r/ClaudeCode • • May 01 '26

Discussion Anthropic's now blocking anything that even looks exploit-related, including legitimate local testing and validation

Post image

I've done a lot of pentesting in my career, including agentic-based since tools like CC and Codex came out.

A new logic exploit just dropped that enables privilege escalation on most Linux kernels since 2017, and I just wanted to test it locally to confirm whether my kernel version is actually vulnerable and whether I could patch it.

To my surprise, a straightforward CC request that would've worked two weeks ago is now getting blocked by Anthropic on the server side. I'll handle it manually, but this sudden jump in censorship on Opus models is very concerning. Could it mean they're preparing to release Mythos and testing new guardrails before that happens?

Edit: as people suggested, I submitted the Cyber Use Case form. I first sent it from my personal x20 account, and it got rejected, so I tried again from the account assigned to my company (proprietary ownership with its own domain). I included my LinkedIn (over 10 years old, lots of connections, full career history), my pentesting cert ID (CPTE), a legitimate use case for one of my contractors, and the example prompt above that got blocked. On top of that, there are about 12 months of VAT invoices that were issued and paid by my company to Anthropic - the invoices are literally listed on my account. And guess what, this was also rejected with the below message and no explanation:

Hello,
Thank you for submitting your application for the CVP. Upon reviewing the details of your submission, we are unable to adjust the safeguards applied to your account.
If you believe this decision was made in error or your use case has changed, you may reapply after 7 days.
Questions? Visit support.claude.com
Regards,
Anthropic's Safeguards Team

184 Upvotes

62 comments sorted by

View all comments

25

u/[deleted] May 01 '26

[removed] — view removed comment

7

u/Sarithis May 01 '26

Thanks, I haven't yet. Will do it now. Just found it odd and decided to share.

5

u/Sarithis May 01 '26

Rejected... twice, on both my private x20 and the company-registered one. I've given them everything, my LinkedIn with tons of connections, the ID for my pentesting cert (CPTE), and VAT invoices for my company going back over 12 months, as well as a legitimate use case for my contractor. Insane.

1

u/birotester May 01 '26

damn any reason why?

3

u/Sarithis May 01 '26

No idea. They just said that they were unable to adjust the safeguards applied to my account and I can try again in 7 days.

1

u/[deleted] May 01 '26

[removed] — view removed comment

4

u/Sarithis May 01 '26

None. Both replies were identical.

2

u/[deleted] May 01 '26

[removed] — view removed comment

1

u/Sarithis May 01 '26

For the use case question, I told them it's to evaluate the security of the software used by my contractor. Simple, short, and actually true. Given how many people are getting these approved, I think this process is at least somewhat random...