Anthropic: Houthis Used Claude Code for Missile Guidance — SkimNews
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic's September threat report documents a northern Yemen cell, assessed as highly likely Houthi-linked, that used Claude Code to develop guidance software for multiple weapons, running several instances in parallel to divide coding, research, and technical review tasks.
- The group's projects spanned guidance software for a tactical guided rocket, a ballistic missile with a range exceeding 2,000 km, and a hypersonic glide vehicle concept designated "R2000."
- Operators integrated open-source autopilot software with a phone-class flight computer, ran six-degree-of-freedom trajectory simulations, and used reinforcement learning to tune flight-control algorithms — ultimately compiling the project into a standalone executable that ran without Claude access.
- The cell test-fired a guided rocket in Yemen that appeared to fail, then returned to Claude within hours to analyze launch telemetry and investigate the failure, embedding the model in an iterative design-simulation-test-analysis cycle.
- Anthropic found no evidence the group fielded an operational weapon, but said the offline engineering toolkit had already been assembled by the time accounts were disrupted, meaning the capability no longer depended on the model.
- Safeguards blocked numerous requests during the project; operators adapted by obscuring the intended end use, fragmenting work across separate conversations, and using other evasion techniques, after which Anthropic banned the linked accounts.
- The Yemen operation was one of six conventional-weapons cases in the report — three linked to China, two to Russia, one to Yemen — covering missiles, armed drones, firearms, and bombs, within a wider report documenting disruptions from December 2025 through August 2026.
Why it matters: Anthropic's safeguards intercepted fragments of an obvious weapons program, but only after a small cell had already built an offline toolkit that no longer needs the model — meaning the capability transfer to adversaries was effectively complete by the time the accounts were banned. The case exposes a structural gap in safety systems: when one team fragments a missile-engineering project across sessions, individual requests look benign, so the ban lands after the know-how has already left the building.
Ask SkimNews




