HackMyIP
← Back to News
2026-09-12 SecurityWeek

Anthropic Blocks Houthi-Linked Accounts Misusing Claude for Missile Development

AI ThreatsLLM SecurityAI Security

Anthropic has disclosed that users operating from Houthi-controlled territory in northern Yemen attempted to weaponize its Claude AI model to develop advanced missile systems, hypersonic glide vehicles, and mid-course maneuvering warheads. According to the company's third threat report since March 2025, the actors used Claude Code in place of human software engineers to build guidance, navigation, and control (GNC) software for a multi-variant missile architecture—one in which interchangeable warheads and guidance packages can be mounted on a common airframe. Anthropic confirmed the accounts were banned after detection, and that while the users failed to field an operational device, they did conduct a failed test of a guided rocket and returned to Claude for post-mortem debugging of the failure.

The report detailed three distinct weapons programs pursued by the cell, including a hypersonic-speed gliding missile variant and a warhead leveraging commercial mobile phone hardware for in-flight course corrections. Critically, before the accounts were suspended, the users had already exported their work into an offline simulation toolkit that operates independently of Claude or any cloud platform—meaning the underlying design knowledge has likely persisted beyond Anthropic's enforcement action. Weapons analyst Trevor Ball of Armament Research Services noted that while the Houthis may be researching hypersonic concepts through the model, they lack the industrial base to manufacture such systems; U.S. hypersonic programs, by comparison, remain in testing. Hazam al-Assad, a member of the Houthi political bureau, denied reliance on open-source AI, asserting that Houthi armed forces possess indigenous production capabilities developed during the 12-year Saudi-led conflict.

This incident underscores the growing intersection of commercial LLMs and state-level weapons proliferation, mirroring documented misuse patterns from December through August that also included state-sponsored disinformation campaigns and biological weapon research. Organizations tracking adversary infrastructure in the region can monitor related domains and proxy endpoints using a WHOIS lookup or a VPN/proxy detector to identify anonymized access patterns consistent with sanctioned actors. Anthropic's threat intelligence team continues to publish periodic disclosures as part of its responsible scaling policy, but the export of generated code to offline environments remains a fundamental enforcement blind spot—one that adversaries will continue to exploit as long as frontier models can be prompted for dual-use engineering output.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →