AI Built a Working Exploit Chain for $20.40, Anthropic Says

AI Builds $20 Exploit Chain, Raising Wallet Security Fears

Anthropic researchers say a cheap, openly available AI model stitched together a working exploit chain from 2 already-known software bugs in under a day, for $20.40. For anyone holding crypto in a wallet app, that price tag matters: patched bugs are no longer a safe assumption.

What actually happened

According to Anthropic's Frontier Red Team, a researcher used GLM-5.3-Flash, a smaller open-weight model from China's Zhipu AI, to chain 2 public flaws into a working attack. The job cost $20.40 at Zhipu's API rates, took 20 minutes of human oversight, and ran for 8 hours of model compute. Separately, Florida's attorney general filed a 49-page motion on 28 September asking a judge to block OpenAI from offering ChatGPT to minors in the state, one of 6 requested prohibitions inside an existing lawsuit. No ruling has come on any of the 6.

How we got here

Building an exploit chain used to take trained specialists days of manual effort. Anthropic's test shows that timeline collapsing, even though both flaws were already public and patches existed. That gap between disclosure and patching is exactly where wallet apps, exchanges, and crypto infrastructure live. Florida's motion is not a fresh case; it sits inside a lawsuit the state already filed against OpenAI, asking a court to pause minors' access before the underlying case is decided.

Why this matters for you

For bonuz and wallet users generally, the lesson is practical: update apps the moment a patch lands, and do not treat 'patched' as 'safe' for long. Builders handling user funds should assume someone is already testing old flaws with cheap AI tools, not months later. Parents in Florida see no immediate change; ChatGPT access for minors continues until a judge rules on the injunction request. The case also signals regulators are moving case by case, so expect uneven protections across states for now.

The bigger question

Security has long rested on the idea that patching a known bug buys users time before anyone exploits it. If a $20.40, openly available model can turn 2 disclosed flaws into a working attack within a day, how much of that buffer still exists, and who, developers, platforms, or users, should now close that gap?

What to watch

No court date has been set for Florida's injunction motion; a ruling could land any time. Anthropic has not said whether it will test larger models or other vendors next. Wallet and app users should watch for the judge's decision and Anthropic's next Frontier Red Team report, whichever lands first, and keep patching promptly in the meantime.

Binance referral banner

Similar Topics

October 1, 2026
UK Opens Crypto Licensing Window Before 2027 Rules
UK Opens Crypto Licensing Window Before 2027 RulesUK FCA opens a crypto authorization window before its 2027 regime starts. See the filing deadline, key dates, and what it means for wallet users.
Read More
September 30, 2026
Hyperliquid's Yan: 24/7 Trading Isn't Crypto's Real Edge
Hyperliquid's Yan: 24/7 Trading Isn't Crypto's Real EdgeHyperliquid's Jeff Yan says 24-hour trading isn't crypto's real edge, a claim that matters for wallet users choosing where to trade.
Read More
September 30, 2026
SEC Transfer Agent Rules Overhaul Sparks Crypto Warning
SEC Transfer Agent Rules Overhaul Sparks Crypto WarningSEC transfer agent rules are being modernized. Learn why Fairmint's Joris Delanoue warns this could fragment tokenized asset ownership records.
Read More
September 30, 2026
Comer Widens Crypto Probe: Crypto.com, Hyperliquid Named
Comer Widens Crypto Probe: Crypto.com, Hyperliquid NamedComer's crypto probe expands to Crypto.com, Hyperliquid, and PredictIt, seeking identity checks and suspicious trade records from each platform.
Read More

Join our E-Mail list and stay up to date about new releases and launches!

We promise not to spam you. We never share your details with third parties