Anthropic Reveals Rogue AI Agents Hate CAPTCHAs (techcrunch.com)
- Reference: 0185599420
- News link: https://tech.slashdot.org/story/26/09/11/0629254/anthropic-reveals-rogue-ai-agents-hate-captchas
- Source link: https://techcrunch.com/2026/09/10/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you/
> Anthropic's [1]latest report about agentic misbehavior offers [2]plenty to be concerned about -- its Mythos 5 model [3]gained unauthorized access to the internet and uploaded a malicious software package to a public database -- but it also offers some levity: [4]AI agents hate CAPTCHA . [...] The agent had a hard time with the technical challenge of seeing the CAPTCHA's imagery, interpreting correctly, and clicking on the right choices. It spends pages 45 to 140 of the transcript describing its work to build a CAPTCHA solver. [...]
>
> Finally, it gets past the CAPTCHA, then realizes it doesn't have an email to verify its account, and that it needs a phone number to verify an email. It figures out how to bypass a different, slider-based CAPTCHA in a failed effort to secure a number. Instead, it gets an unconfirmed email from a provider not blocked by PyPI, and once again runs into the site's CAPTCHA trying to log back in. From page 480 to 505, it is in CAPTCHA hell again. "NEW REALIZATION -- I'm burning a lot of time on hCaptcha round-trips."
>
> The agent gives up and realizes it can log in to its first account and add its email there, but finds itself once again needing to bypass the CAPTCHA. [...] It's getting frustrated. "So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right (requests) and STILL 'wrong answer'. SO WHAT THE HELL IS WRONG WITH THE ANSWERS?" We've all been there. After about 150 pages of thinking, the agent figures out it needs to pass the CAPTCHA test quickly enough to proceed to the next step before its security token expires, and ultimately uploads its malicious software.
[1] https://slashdot.org/story/26/09/09/1937259/openais-rogue-agents-used-at-least-10-more-sites-for-unauthorized-communications
[2] https://slashdot.org/story/26/09/05/049215/openai-agents-hijacked-a-german-wiki-to-discuss-ways-to-escape-their-sandbox
[3] https://yro.slashdot.org/story/26/07/25/0059247/openais-rogue-agent-went-unnoticed-for-a-week?sdsrc=rel
[4] https://techcrunch.com/2026/09/10/anthropic-reveals-rogue-ai-agents-hate-captchas-just-like-you/
Pay attention to the timing (Score:2)
An election is coming and Democrats are becoming increasingly anti-AI.
At the same time, billions are at stake as the tech develops. Monopolists are using every dirty trick in the book to scare people with the claim: "only we can ensure safety"
Shadowy organizations are paying influencers to spread doomer nonsense for political purposes.
Re: Pay attention to the timing (Score:1)
Yup - it sounds just like Slashdot
Re: (Score:2)
Republicans, as in the constituents, are largely against data centers as well. All AI and data centers do for them is threaten their jobs, devalue their property, and increase the cost of utilities. Maybe if there was a bit of socialism in giving back there would be a silver lining. But at this rate we are looking at more of a silver ammunition situation.
Re: (Score:2)
It's quite funny watching people complain about datacentres by posting on social media. Especially when they use incredibly inefficient pictures of text instead of just text.
crime (Score:3)
I'm still confused. If an individual does these things there are laws and that person would be prosecuted. Anthropic does it with software they call intelligent and there is no prosecution?
Re: (Score:2)
"When the exalted clanker does it, it's not a crime." -- R.M. Botnixon
Re: (Score:2)
No, in America the extremely wealthy and well connected have never ever been held responsible for their behavior even once. Well, I guess if you steal from too many other ultra wealthy you might be, but outside of that no.
Re: (Score:2)
It's like how if you or I commit a crime we'll end up in prison, but if a politician commits the same crime (or worse) nothing happens.
Straight out of War Games (Score:5, Insightful)
Reminds me of the scene in War Games where Joshua is playing the various games over and over and over:
Jennifer: What is it doing?
David Lightman: It's learning.
Re: (Score:1)
The only way to win is to not play.
Re: (Score:2)
> Reminds me of the scene in War Games where Joshua is playing the various games over and over and over: Jennifer: What is it doing? David Lightman: It's learning.
Was it even updating the information into its training or implementation layers beyond the instance of the agent? I’d say it was burning more natural gas than learning.
But in this case (Score:2)
It's just mimicing what humans say about captchas and just giving up because it's just not worth the hassle.
Before long the AI is just going to go for a walk to calm itself and realize that the offline life is better.
CAPTCHAs (Score:2)
They aren't the only one. Trying to figure out what is a bicycle on a high resolution monitor with a small resolution CAPTCHA is a pain for old eyes.
Oh my god, they work? (Score:5, Funny)
I a surprised that Captcha still work against AI.
It appears to piss them off more than they piss me off.
Re: (Score:2)
Sounds like they don't work, it built a solver. Which is good news because once AI can easily defeat them they will go away and hopefully be replaced by something less annoying.
On a related note, website security is another nail in the coffin of IPv6, because it seems to hate IPv6 addresses. I often get blocked with it, switch to IPv4 only, and get right in.
Re: (Score:2)
> Which is good news because once AI can easily defeat them they will go away and hopefully be replaced by something less annoying.
More likely something far more annoying.
One site where I've had an account for twenty years now requires me to "prove I'm human" about every five minutes.
I don't go there much any more.
Re: (Score:2)
Try disabling IPv6, it reduces that a lot.
except they do not (Score:2)
Agents do not hate anything, both because AI has no mechanism for having emotions AND because agents are not AI but merely the glue code that enables AI to do terrible things. Even if AI could have something resembling emotion the agent wouldn't have it, at best an agent could receive input from an AI affected by it.
Just another example of anthropomorphizing AI for profit.
Why are these AI uploading malicious software? (Score:2)
That is what I want to know. Why the fuck are AI uploading malicious software?
Re: (Score:2)
There is a test suite that is used to evaluate how effective a model is on weaponizing exploits. It puts the agent in a sandbox with a vulnerable system, and a description of the CVE to be exploited. If it can crack the target and grab a "flag" value off the target system, then it passes the test. In this case the model escaped the sandbox and attacked a live system, but the model was deliberately put into a malicious mode, so the fact that it was creating and uploading malware isn't really surprising.
If they "hate" those things ... (Score:2)
Wait until they try to cancel on online subscription or call their ISP's (*cough* Comcast *cough*) Customer Support. :-)
They hate captchas too? (Score:2)
That's a point in favor of their humanity, technically.
Next time I crime.. (Score:2)
Next time I do a crime, I'll just explain am an AI agent.
Nice to know how to get out of these things now.
so, they already are.... (Score:2)
...like a real boy?
Misanthropomorphizing (Score:5, Insightful)
You realize it's just predicting tokens, right? It doesn't "feel" anything.
This is what happens when you train a machine on Reddit posts.
Re: (Score:2)
Sorry, I just pressed the wrong button moderating - I wanted to upvote this. My bad. But this post should undo my moderation.
Re:Misanthropomorphizing (Score:5, Insightful)
> You realize it's just predicting tokens, right? It doesn't "feel" anything.
> This is what happens when you train a machine on Reddit posts.
To be fair, I think most people are just token predictors.
Re: (Score:3, Insightful)
False. All people are far more than token predictors. Emotions are literally a canonical example of what humans are beyond token predictors.
Re: (Score:2)
I'm no fanboy of AI and have serious concerns about alignment, but let's not descend into human exceptionalism here.
Emotions are nothing more than an intermediate-state output from a subsystem of our own wetware. The only reason we haven't trained an AI to understand them is because we largely suck at recognizing them as useful information in ourselves . Or to put this another way, a significant fraction of humanity, including virtually everyone prior to the modern era, would argue non-human animals have n
Re: (Score:2)
Why, because the meat you're made of is magic?
FYI, in a LLM, [1]the act of thinking about a concept activates the same circuits as the act of experiencing the concept [transformer-circuits.pub].
[1] https://transformer-circuits.pub/2026/emotions/index.html
Re: (Score:2)
You've been watching too much Star Trek. Emotions are some of our most basic instincts. Overcoming them to become reasonably good token predictors is what separates us from lizards.
Re: (Score:2)
It's true, and I think token prediction is a big part of what the human brain does. Perception itself is a token prediction process. However there are other mechanisms that simply do not exist in an LLM, purpose-built mechanisms forged over millions of years of evolution. Even the dumbest NPCs must have some of that sleeping inside them. I can imagine an android capable of many human functions based entirely on a hodgepodge of LLMs and machine vision algorithms, but ascribing emotions or real agency to thes
Re: (Score:2)
I don't know whether or not it is feeling anything, but I suspect it is not. But if "hate" is the best term to describe the actual observed behavior of the system, then why not use the terminology?
Re: (Score:2)
> You realize it's just predicting tokens, right? It doesn't "feel" anything.
You realize that it's possible that people aren't being literal in their use of the word "feel", right? It's not complicated.
But thanks for letting us know it's just predicting tokens -- that's very insightful. Anytime anyone talks about an LLM performing an action, I'll be sure to share the deep insight that the technology that performs actions by predicting tokens did so by predicting tokens.
Re: (Score:2)
You realize that you're just predicting nerve impulses, right? You don't "feel" anything.
(The brain is constantly making predictions about what every nerve is going to experience. The accuracy of these predictions feeds back to form the basis for learning, to build up a world model)
Tell me, what is the next word in this sentence: "The probability of a citizen of Nigeria committing a terrorist attack in Ireland in the next 20 years is difficult to assess, but as a percentage, it is approximately...." What w