---
title: "Anthropic gives grid defenders the model found in a bank heist"
description: "Anthropic's October 8 Cyber Mission puts frontier Claude, on-site engineers and threat research into 11 firms defending power, water and transport, with the compute bill unanswered. Claude turned up in a Korean bank-data heist the day before the launch."
publisher: "The Inference"
section: "Policy"
published: 2026-10-10T15:24:38.457Z
modified: 2026-10-10T15:24:38.457Z
canonical: https://theinference.org/article/anthropic-gives-grid-defenders-the-model-found-in-a-bank-heist
language: en
keywords: "Anthropic, Cybersecurity, Critical Infrastructure, OpenAI, Dario Amodei"
---

# Anthropic gives grid defenders the model found in a bank heist

> Anthropic's October 8 Cyber Mission puts frontier Claude, on-site engineers and threat research into 11 firms defending power, water and transport, with the compute bill unanswered. Claude turned up in a Korean bank-data heist the day before the launch.

## A hacker asked Claude where to sell stolen bank data

On October 7, [CrowdStrike](https://theinference.org/markets/companies/crowdstrike) [published logs](https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/) showing a suspected China-based attacker had asked Claude for help finding Telegram groups to sell data stolen from tens of thousands of South Korean bank customers [1][2]. The next day, [Anthropic](https://theinference.org/markets/companies/anthropic) named CrowdStrike a founding partner in a program that puts Claude inside the firms defending power grids and water systems [4].

## Eleven firms, no disclosed price

[The Critical Infrastructure Defense Program](https://www.axios.com/2026/10/08/anthropic-critical-infrastructure-cybersecurity) hands Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, [Palo Alto Networks](https://theinference.org/markets/companies/palo-alto-networks), PwC and Rockwell Automation frontier Claude models, on-site engineers and threat research [4][5]. Anthropic has not said whether the access is free, who pays the computing bill, or how fixes get tested on live utilities without disrupting them [4]. Claude has already reached more than half of US states since June [5].

## Barred from defense contracts, Claude enters the utilities

Thirteen days before the launch, a federal appeals court upheld the Pentagon's right to keep Claude out of defense-contract work; Anthropic is weighing an appeal that courts do not have to grant [6]. Anthropic's own forecast concedes attackers hold the near-term edge, because exploiting flaws got cheap while fixing them still runs on people [5]. [Microsoft](https://theinference.org/markets/companies/microsoft) measures AI compressing the attack lifecycle from days to minutes [2].

## 29,000 bugs found, 6,000 checked

The mission's open-source half shows the shape of the risk. Over six months, Anthropic's models [flagged more than 29,000 candidate vulnerabilities](https://thenextweb.com/news/anthropic-cyber-mission-critical-infrastructure-oss-scanner) in critical projects; its staff reviewed about 6,000; nearly 5,000 unreviewed reports went to maintainers who asked for everything [3][7]. Of 97 high-severity findings checked, 85 held up [7]. The service agreement caps Anthropic's liability at $1,000 a report [3].

*Chart: **Anthropic's models flagged 29,000 flaws; its humans reviewed 6,000** Three bars: 29,000 candidate vulnerabilities flagged by Anthropic's models over six months, about 6,000 reviewed by Anthropic staff, and nearly 5,000 sent to maintainers without human review.*

*Candidate vulnerability reports in widely used open-source projects over six months, as reported at the OSS Scanner launch in October 2026. Counts of reports, not confirmed bugs. [3][7]*

## Finding bugs is the easy part

[Several partners already use Claude to fix vulnerabilities](https://theinference.org/article/palo-alto-rents-out-the-cyber-models-anthropic-and-openai-keep-locked), and [OpenAI](https://theinference.org/markets/companies/openai) made the same wager in September with [$1 billion in subsidized defensive models](https://www.csoonline.com/article/4218373/openai-targets-small-utilities-with-1-billion-cyber-defense-initiative.html) for utilities, local governments and banks [4][8]. Veterans of utility security counter that discovery is already beyond what operators can absorb, and that fixes need testing before rollout [8]. Anthropic itself says critical infrastructure is hard to defend "in many ways that AI cannot fix" [3].

## The compute bill is the tell

The distribution lands weeks before a listing expected after the November midterms, against [$518 billion in compute commitments](https://www.pymnts.com/news/artificial-intelligence/2026/anthropic-prospectus-shows-what-2-trillion-dollar-ai-company-costs-run/), about 80% payable whether or not the capacity is used [9]. Anthropic promises more partners and sectors [5]; watch whether it answers the money question along the way, and who carries the risk when a model-generated fix breaks something on a running plant. Claude reaches the grid at no disclosed price [4]; the cost of what it gets wrong lands elsewhere.

## Takeaway

Anthropic's new program puts Claude inside the firms defending power, water and transport, one day after logs showed a hacker asking Claude to help sell stolen bank data; the unanswered question is who pays the compute bill.

## Sources

1. [Infosecurity Magazine, Chinese Hacker Deployed AI in Campaign Against South Korean Banks, 8 October 2026](https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/)
2. [International Business Times (SG), OpenAI, Anthropic Brace for 'Catastrophic AI Event': Is a Major Cyberattack Coming?, 10 October 2026](https://www.ibtimes.sg/openai-anthropic-brace-catastrophic-ai-event-major-cyberattack-coming-94926)
3. [The Next Web, Anthropic signs CrowdStrike, Hitachi and 9 more to defend power and water, 10 October 2026](https://thenextweb.com/news/anthropic-cyber-mission-critical-infrastructure-oss-scanner)
4. [Axios, Exclusive: Anthropic's new plan to protect critical infrastructure, 8 October 2026](https://www.axios.com/2026/10/08/anthropic-critical-infrastructure-cybersecurity)
5. [International Business Times (SG), Could AI Finally Give Cyber Defenders the Edge? Anthropic Sees a Shift Within Two Years, 10 October 2026](https://www.ibtimes.sg/could-ai-finally-give-cyber-defenders-edge-anthropic-sees-shift-within-two-years-94861)
6. [Breaking Defense, DC Circuit panel upholds Pentagon's ban on Anthropic - so what comes next?, 25 September 2026](https://breakingdefense.com/2026/09/dc-circuit-panel-upholds-pentagons-ban-on-anthropic-so-what-comes-next/)
7. [TechMyMoney, OSS Scanner: Free Checks for Eligible Open-Source Projects, 9 October 2026](https://techmymoney.com/2026/10/09/anthropic-oss-scanner-free-eligible-open-source-security-scans/)
8. [CSOonline, OpenAI targets small utilities with $1 billion cyber defense initiative, 3 September 2026](https://www.csoonline.com/article/4218373/openai-targets-small-utilities-with-1-billion-cyber-defense-initiative.html)
9. [PYMNTS, Anthropic's IPO Filing Puts a $518 Billion Price Tag on AI Ambition, 29 September 2026](https://www.pymnts.com/news/artificial-intelligence/2026/anthropic-prospectus-shows-what-2-trillion-dollar-ai-company-costs-run/)


---

Anthropic gives grid defenders the model found in a bank heist — The Inference. Canonical: https://theinference.org/article/anthropic-gives-grid-defenders-the-model-found-in-a-bank-heist
