The ReadJuly 1, 2026via SiliconAngle

Armadin details full sandbox escape in Claude Cowork but Anthropic disputes risk

Why it matters

A disclosed sandbox escape in Claude Cowork raises questions about the security posture of production AI agent infrastructure—especially as enterprises deploy models in sensitive environments. Anthropic's dismissal of the risk highlights the ongoing friction between security researchers and AI labs over threat modeling.

Key signals

  • Full sandbox escape chain detailed by Armadin Inc.
  • Attack achieves arbitrary root command execution inside Claude Cowork sandbox
  • Second flaw strips network restrictions meant to contain the exploit
  • Anthropic disputes the severity/risk classification
  • Reported via responsible disclosure (March timeline implied)
  • Deployment context: Claude Cowork is Anthropic's agent/code-execution product

The hook

Claude's sandbox just broke. Anthropic says it doesn't matter. Security researchers disagree.

Security researchers at Armadin Inc. today detailed an attack chain that runs arbitrary commands as root inside the sandbox behind Anthropic PBC’s Claude Cowork, escaping the isolation layer, with a second flaw stripping the network restrictions meant to contain it. Anthropic, however, does not consider it a security issue. Armadin reported the chain on March […]

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.