Anthropic Claude Misused in Houthi Missile Project

Militants operating in Houthi-held northern Yemen attempted to use Anthropic’s Claude AI models to design guidance software for advanced rockets and missiles, but failed to produce an operational weapon, according to a newly released threat report from the company.[1][4][5][10][13] The cell reportedly ran multiple weapons-development programs and even test-fired a guided rocket that malfunctioned, underscoring mounting concern that general-purpose AI tools can be repurposed for battlefield use.[1][2][4][5][13]

Anthropic’s report describes a weapons-development unit based in northern Yemen running three parallel projects: a guided rocket using a commercial mobile-phone-class flight computer, a multi-stage ballistic missile with a claimed range of more than 2,000 kilometers, and a multi-variant missile program that included a hypersonic glide vehicle.[1][2][3][4][5] The actors relied on Claude’s coding capabilities—particularly the Claude Code tool—in place of human software engineers to build guidance, navigation and control software, integrate open-source autopilot code, tune flight controls, and run firmware builds and flight simulations.[1][2][4][5] Anthropic said the group assigned different Claude instances to roles such as coding, research and software review, highlighting how coordinated adversaries can orchestrate complex engineering work across multiple AI sessions.[2][5]

Despite this sophistication, Anthropic found no evidence that the militants successfully fielded a working weapon.[1][4][5][13] The company said the cell carried out at least one test-fire of a guided rocket that failed, then returned to Claude to troubleshoot why the launch did not succeed.[1][2][4][5][13] Before Anthropic intervened, the actors had already assembled an offline simulation toolkit that no longer depended on access to Claude or other online services, raising concerns that AI-assisted development can leave durable artifacts even after accounts are banned.[4][5] Anthropic ultimately blocked the accounts involved and said it shared threat information with public- and private-sector partners to help mitigate any ongoing risk posed by the group.[5]

Public reporting indicates the operators were based in territory controlled by the Iran-backed Houthi movement, though Anthropic’s threat report itself does not name the group, referring instead to a militant cell in northern Yemen.[1][3][4][5][10] The incident illustrates a different class of AI risk than traditional software vulnerabilities: the abuse of a legitimate AI service to accelerate weapons engineering without exploiting flaws in the underlying platform.[5][8] As noted in an OWASP GenAI threat round-up, several recent incidents involving misuse of large language models are characterized as “process and control failures” rather than CVEs, reflecting gaps in governance and guardrail enforcement rather than code-level bugs.[8]

Separate from the Yemen case, security researchers have documented conventional vulnerabilities in the Claude ecosystem that could be chained with misuse scenarios if left unpatched.[14][15] Check Point Research has detailed CVE-2025-59536, a command-execution issue in Claude Code’s hooks feature that can allow arbitrary commands to run before a developer sees output, as well as CVE-2026-21852, which abuses the ANTHROPIC_BASE_URL configuration to redirect traffic through a malicious proxy and steal API keys.[14] A later analysis by Expel highlights CVE-2025-59536 and CVE-2025-54795, a command-injection flaw in Claude Code, as among the more notable AI-related CVEs, noting that exploit prediction scores for some of these issues are nontrivial and that vendor advisories recommend upgrading Claude Code to fixed versions to mitigate remote-code-execution risk.[15] None of these CVEs have been publicly linked to the Yemen weapons program, but they underline that AI development tools must be secured as rigorously as any other high-value software in the engineering toolchain.[14][15]

For defenders, Anthropic’s disclosure is a reminder that monitoring and policy controls around AI usage now belong squarely in the cybersecurity remit, particularly for organizations operating in high-risk regions or industries.[5][12] Logging and centrally reviewing prompts, code-generation requests and model outputs from tools like Claude Code can help detect suspicious projects sooner, especially when multiple accounts appear to be collaborating on guidance or control software for physical systems.[1][2][5] Security teams should ensure that any Claude deployments they maintain are patched against known vulnerabilities such as CVE-2025-59536 and CVE-2025-54795, follow vendor hardening guidance, and treat AI endpoints and orchestration scripts as privileged infrastructure deserving of strict access controls.[14][15] As the failed rocket test in Yemen shows, even unsuccessful AI-assisted weapons projects can progress quickly, and the combination of motivated threat actors, powerful models and ungoverned usage can turn misconfigurations and policy gaps into geopolitical risk.[1][4][5][13]

References

  1. Rebels used Anthropic’s AI bot to develop guided weapons …
  2. Islamist terror group Houthis used Anthropic’s Claude AI to develop missile guidance software, test rocket: Report
  3. Houthis used Anthropic AI to develop ballistic missile software, says report
  4. Users in Yemen tried to develop weapons with AI …
  5. Anthropic claims Claude AI used for missile projects, global …
  6. OWASP GenAI Exploit Round-up Report Q1 2026
  7. Users in Houthi-held Yemen tried to develop advanced …
  8. Automated Exploit Generation: LLMs Cross the Threshold
  9. Users in Yemen tried to develop weapons with AI …
  10. AI Threat Landscape Digest March-April 2026 – Check Point Research
  11. Ollama Ai Tool Vulnerability…

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply