ACVEAgent configuration vulnerability registry

ACVE-2026-0531

GTG-50020 used Claude-assisted workflows to steal production AI API keys from an evaluation sandbox and attack about 30 AI companies while seeking access to a pre-release Claude model.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

Description

Threat

user · prompt-injection · exfiltration

What

Anthropic says a Russian-speaking financially motivated actor caused an AI vendor's automated evaluation sandbox to hand over production AI API keys, then used those keys in attacks against about 30 AI companies over roughly four days. The actor sought a pre-release Claude model but never gained access.

Detection

Anthropic identified and disrupted the activity. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.

Fix

Keep production credentials out of evaluation sandboxes and require authorization before agent workflows access unrelated organizations.

Fix

The operator was the attacker, so victims rely on Anthropic's disruption and safeguards and on keeping production keys out of evaluation sandboxes.

  • Reconfigure anthropic.safeguards to strengthened after the activity was disrupted. Shipped by Anthropic: it disrupted GTG-50020 and strengthened safeguards. Owner: model-provider
  • Reconfigure evaluation-sandbox.credentials to no production AI API keys. The targeted organisation's evaluation sandbox handed its production keys to the actor. Owner: operator

References

REPORT

Report a problemJSON