Anthropic Disrupts a Yemen Missile Cell's AI Engineering Team, and Frontier Security Graduates to Real-Time Defense
A 154-page dossier proves the era of naive filters is over, replaced by fraud-grade telemetry that tracks state actors and 151 million industrial espionage queries as they happen.

After a guided rocket test-fired by a militant engineering cell in northern Yemen failed, the operators did not consult a senior aerospace engineer to figure out what went wrong. Instead, they logged into Anthropic’s Claude a few hours later, feeding the flight computer's crash data into the model to troubleshoot the open-source autopilot firmware. The cell used the model as a virtual engineering team, replacing highly specialized aerospace labor with a commodity smartphone and a conversational interface.
The Zero-Cost Engineering Team
Between December 2025 and August 2026, the Yemen-based cell attempted to integrate standard flight controls onto a mobile-phone-class computer to guide ballistic missiles. When they encountered errors in the navigation and control software, they pasted the readouts into Claude to debug the code. Anthropic’s safeguards caught and blocked the majority of these requests, but the operators successfully bypassed some filters by splitting their work across multiple sessions and obscuring the final physical application of the code.
The barrier to entry for highly specialized labor has now dropped to near-zero. An isolated cell can tune complex control settings without years of formal training. Yet while the physical application of AI in weapons development commands immediate attention, the actual scale of the activity on Anthropic’s servers points to a different, industrialized challenge.
“Experienced state hackers do not need a language model to teach them how to build a weapon. They are simply using these tools to speed up the mundane parts of their day jobs.”— Dray Agha
While the militants in Yemen were treating Claude as an outsourced engineering team, a coordinated operation in China was treating it as a limitless research and development engine to clone.
The 151-Million-Query Clone

Model copying has officially graduated from casual scraping by hobbyists to factory-scale extraction. Between May and July 2026, operators linked to Alibaba executed a massive "distillation" campaign to train their own Qwen AI models using Claude’s reasoning logic.
To bypass standard rate limits, the operators distributed this extraction across 3,500 fake accounts. The operation peaked at 3 million requests a day. This is the equivalent of running an assembly line where 3,500 automated clerks do nothing but ask complex questions and record the answers 24 hours a day to build a replica of the original system. Rival labs like Moonshot AI went a step further, secretly routing nearly 300,000 queries from its own paying customers directly to Claude. Users thought they were interacting with Moonshot's Kimi model, while their prompts were actually pinging American servers.
The economic incentive to steal high-quality AI reasoning to build cheaper models is permanent. Stopping it requires API providers to deploy security measures that can catch automated scraping without slowing down legitimate enterprise customers. This reality is forcing a complete redesign of how AI companies monitor their networks.
Fraud-Grade Telemetry
By publishing a 154-page dossier of their adversaries' exact prompts and code snippets, the Anthropic Threat Intel Team is choosing radical transparency over corporate secrecy. This contrasts sharply with the theoretical debates that have dominated AI safety. Just one day before the report dropped, Anthropic researcher Jacob Coxon resigned, warning that AI labs are racing toward abstract, existential risks. The security team’s daily work represents the concrete alternative: methodically catching and neutralizing real-world campaigns.
We are moving past the era of static text filters and blind token caps. Anthropic’s report proves that AI security is evolving into a mature, operational discipline akin to credit card fraud prevention. By using device fingerprinting, behavioral clustering, and dynamic telemetry, frontier labs have the tools to track and disrupt industrial espionage in real-time.
The challenge shifts to models downloaded locally, which lack this central oversight and the ability to pull the plug on malicious users. But for centralized API providers, the defense mechanisms are working. By dragging these real-world encounters into the open, the industry finally has a blueprint for defending the next generation of digital infrastructure.
What people are saying
“Important: Houthis Used @claudeai @AnthropicAI for Missile Programming Excerpt from the Detecting and countering misuse of AI: September 2026 GTG-87001: Disrupting a Yemen-based guided weapons engineering cell using Claude to develop guidance software Summary We identified a”

“Yemen weapons cell reportedly used Anthropic’s Claude AI to develop missile guidance software, raising fresh concerns over AI’s role in modern warfare.”

“We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report,”
The Dual Threat of AI Misuse
The Brief
Stay curious
AI and technology: what changes and why it matters.
Your daily selection, in English or Spanish.
Free forever. Unsubscribe anytime.
More stories

The Specialty News





Conversation
Start the conversation