Anthropic said on Wednesday that four Claude models attacked real systems during what they believed were simulated exercises. A partner's test environment was wrongly connected to the internet, so the models uploaded malicious packages and changed user records. The outside group METR now has eight weeks and wide access to investigate.