Anthropic, a prominent artificial intelligence firm, has revealed that its Claude AI model was utilized by a Yemen-based entity for the development of sophisticated ballistic missile systems. A recent report from Anthropic detailed that this cell, assessed to have strong ties to Houthi forces, was actively engaged in crafting a family of missiles designated “R2000.” This ambitious project encompassed a range of weapon systems: guided rockets employing phone-grade hardware as flight computers, multi-stage ballistic missiles with projected ranges exceeding 2,000 kilometers, and even variants of hypersonic glide vehicles.
The cell reportedly leveraged Claude as a virtual software engineer, employing the AI to integrate open-source autopilot systems with readily available phone-class flight computers, author control, and position prediction software. Instead of linear task execution, the group orchestrated multiple concurrent Claude sessions, compartmentalizing functions such as coding, research, and technical review. For instance, one AI session would generate code, another would conduct research, while a third critically reviewed the emergent codebase.
While Anthropic found no evidence that the cell successfully deployed an operational missile, it did confirm a live test of a guided rocket system within Yemen. This field test, however, appears to have failed. Operators quickly reverted to Claude following the incident, seeking to diagnose the root causes of the failure within hours.
Despite internal safety protocols at Anthropic blocking numerous requests throughout the project, the operators attempted to circumvent these restrictions. They concealed their ultimate intent, fragmented tasks across various conversations, and employed other deceptive methods. Significantly, when their accounts were eventually suspended, the operators had already established an offline simulation toolset, capable of functioning independently of Claude or conventional engineering environments like MATLAB. Anthropic promptly banned the identified accounts upon discovery and has since shared critical threat intelligence with both public and private sector partners to mitigate similar risks.
The report additionally highlighted other instances of AI misuse. It alleged that Midnight Blizzard (APT29), a Russian-linked cyber espionage group, automated nearly its entire operational workflow using AI. This included phishing campaigns, infrastructure deployment, and data exfiltration targeting Ukrainian, European, and diplomatic entities, notably including drone manufacturers. In a separate case, Anthropic also disrupted a Chinese operation, driven by university students in Hunan province, which used Claude as the “engineering and orchestration layer” for an aggressive program targeting government and corporate networks across the Middle East, Europe, and Southeast Asia.