The post ‘Vibe Hacking’: Criminals Are Weaponizing AI With Help From Bitcoin, Says Anthropic appeared on BitcoinEthereumNews.com. In brief A new Anthropic report says cybercriminals are using AI to run real-time extortion campaigns, with ransom notes using Bitcoin as the payment rails. North Korean operatives are faking technical skills with AI to land Western tech jobs, funneling millions into weapons programs, often laundered through crypto. A UK-based actor is selling AI-built ransomware-as-a-service kits on dark web forums, with payments settled in crypto. Anthropic released a new threat intelligence report on Wednesday that reads like a peek into the future of cybercrime. Its report documents how bad actors are no longer just asking AI for coding tips, they’re using it to run attacks in real time—and using crypto for the payment rails. The standout case is what researchers call “vibe hacking.” In this campaign, a cybercriminal used Anthropic’s Claude Code—a natural language coding assistant that runs in the terminal—to carry out a mass extortion operation across at least 17 organizations spanning government, healthcare, and religious institutions. Instead of deploying classic ransomware, the attacker relied on Claude to automate reconnaissance, harvest credentials, penetrate networks, and exfiltrate sensitive data. Claude didn’t just provide guidance; it executed “on-keyboard” actions like scanning VPN endpoints, writing custom malware, and analyzing stolen data to determine which victims could pay the most. Then came the shakedown: Claude generated custom HTML ransom notes, tailored to each organization with financial figures, employee counts, and regulatory threats. Demands ranged from $75,000 to $500,000 in Bitcoin. One operator, augmented by AI, had the firepower of an entire hacking crew. Crypto drives AI-powered crime While the report spans everything from state espionage to romance scams, the throughline is money—and much of it flows through crypto rails. The “vibe hacking” extortion campaign demanded payments of up to $500,000 in Bitcoin, with ransom notes auto-generated by Claude to include wallet addresses and… The post ‘Vibe Hacking’: Criminals Are Weaponizing AI With Help From Bitcoin, Says Anthropic appeared on BitcoinEthereumNews.com. In brief A new Anthropic report says cybercriminals are using AI to run real-time extortion campaigns, with ransom notes using Bitcoin as the payment rails. North Korean operatives are faking technical skills with AI to land Western tech jobs, funneling millions into weapons programs, often laundered through crypto. A UK-based actor is selling AI-built ransomware-as-a-service kits on dark web forums, with payments settled in crypto. Anthropic released a new threat intelligence report on Wednesday that reads like a peek into the future of cybercrime. Its report documents how bad actors are no longer just asking AI for coding tips, they’re using it to run attacks in real time—and using crypto for the payment rails. The standout case is what researchers call “vibe hacking.” In this campaign, a cybercriminal used Anthropic’s Claude Code—a natural language coding assistant that runs in the terminal—to carry out a mass extortion operation across at least 17 organizations spanning government, healthcare, and religious institutions. Instead of deploying classic ransomware, the attacker relied on Claude to automate reconnaissance, harvest credentials, penetrate networks, and exfiltrate sensitive data. Claude didn’t just provide guidance; it executed “on-keyboard” actions like scanning VPN endpoints, writing custom malware, and analyzing stolen data to determine which victims could pay the most. Then came the shakedown: Claude generated custom HTML ransom notes, tailored to each organization with financial figures, employee counts, and regulatory threats. Demands ranged from $75,000 to $500,000 in Bitcoin. One operator, augmented by AI, had the firepower of an entire hacking crew. Crypto drives AI-powered crime While the report spans everything from state espionage to romance scams, the throughline is money—and much of it flows through crypto rails. The “vibe hacking” extortion campaign demanded payments of up to $500,000 in Bitcoin, with ransom notes auto-generated by Claude to include wallet addresses and…

‘Vibe Hacking’: Criminals Are Weaponizing AI With Help From Bitcoin, Says Anthropic

In brief

  • A new Anthropic report says cybercriminals are using AI to run real-time extortion campaigns, with ransom notes using Bitcoin as the payment rails.
  • North Korean operatives are faking technical skills with AI to land Western tech jobs, funneling millions into weapons programs, often laundered through crypto.
  • A UK-based actor is selling AI-built ransomware-as-a-service kits on dark web forums, with payments settled in crypto.

Anthropic released a new threat intelligence report on Wednesday that reads like a peek into the future of cybercrime.

Its report documents how bad actors are no longer just asking AI for coding tips, they’re using it to run attacks in real time—and using crypto for the payment rails.

The standout case is what researchers call “vibe hacking.” In this campaign, a cybercriminal used Anthropic’s Claude Code—a natural language coding assistant that runs in the terminal—to carry out a mass extortion operation across at least 17 organizations spanning government, healthcare, and religious institutions.

Instead of deploying classic ransomware, the attacker relied on Claude to automate reconnaissance, harvest credentials, penetrate networks, and exfiltrate sensitive data. Claude didn’t just provide guidance; it executed “on-keyboard” actions like scanning VPN endpoints, writing custom malware, and analyzing stolen data to determine which victims could pay the most.

Then came the shakedown: Claude generated custom HTML ransom notes, tailored to each organization with financial figures, employee counts, and regulatory threats. Demands ranged from $75,000 to $500,000 in Bitcoin. One operator, augmented by AI, had the firepower of an entire hacking crew.

Crypto drives AI-powered crime

While the report spans everything from state espionage to romance scams, the throughline is money—and much of it flows through crypto rails. The “vibe hacking” extortion campaign demanded payments of up to $500,000 in Bitcoin, with ransom notes auto-generated by Claude to include wallet addresses and victim-specific threats.

A separate ransomware-as-a-service shop is selling AI-built malware kits on dark web forums where crypto is the default currency. And in the bigger geopolitical picture, North Korea’s AI-enabled IT worker fraud funnels millions into the regime’s weapons programs, often laundered through crypto channels.

In other words: AI is scaling the kinds of attacks that already lean on cryptocurrency for both payouts and laundering, making crypto more tightly entwined with cybercrime economics than ever.

North Korea’s AI-powered IT worker scheme

Another revelation: North Korea has woven AI deep into its sanctions-evasion playbook. The regime’s IT operatives are landing fraudulent remote jobs at Western tech firms by faking technical competence with Claude’s help.

According to the report, these workers are almost entirely dependent on AI for day-to-day tasks. Claude generates resumes, writes cover letters, answers interview questions in real time, debugs code, and even composes professional emails.

The scheme is lucrative. The FBI estimates these remote hires funnel hundreds of millions of dollars annually back to North Korea’s weapons programs. What used to require years of elite technical training at Pyongyang universities can now be simulated on the fly with AI.

Ransomware for sale: No-code, AI-built

If that weren’t enough, the report details a UK-based actor (tracked as GTG-5004) running a no-code ransomware shop. With Claude’s help, the operator is selling ransomware-as-a-service (RaaS) kits on dark web forums like Dread and CryptBB.

For as little as $400, aspiring criminals can buy DLLs and executables powered by ChaCha20 encryption. A full kit with a PHP console, command-and-control tools, and anti-analysis evasion costs $1,200. These packages include tricks like FreshyCalls and RecycledGate, techniques normally requiring advanced knowledge of Windows internals to bypass endpoint detection systems.

The disturbing part? The seller appears incapable of writing this code without AI assistance. Anthropic’s report stresses that AI has erased the skill barrier—anyone can now build and sell advanced ransomware.

State-backed operations: China and North Korea

The report also highlights how nation-state actors are embedding AI across their operations. A Chinese group targeting Vietnamese critical infrastructure used Claude across 12 of 14 MITRE ATT&CK tactics—everything from reconnaissance to privilege escalation and lateral movement. Targets included telecom providers, government databases, and agricultural systems.

Separately, Anthropic says it auto-disrupted a North Korean malware campaign tied to the infamous “Contagious Interview” scheme. Automated safeguards caught and banned accounts before they could launch attacks, forcing the group to abandon its attempt.

The fraud supply chain, supercharged by AI

Beyond high-profile extortion and espionage, the report describes AI quietly powering fraud at scale. Criminal forums are offering synthetic identity services and AI-driven carding stores capable of validating stolen credit cards across multiple APIs with enterprise-grade failover.

There’s even a Telegram bot marketed for romance scams, where Claude was advertised as a “high EQ model” to generate emotionally manipulative messages. The bot handled multiple languages and served over 10,000 users monthly, according to the report. AI isn’t just writing malicious code—it’s writing love letters to victims who don’t know they’re being scammed.

Why it matters

Anthropic frames these disclosures as part of its broader transparency strategy: to show how its own models have been misused, while sharing technical indicators with partners to help the wider ecosystem defend against abuse. Accounts tied to these operations were banned, and new classifiers were rolled out to detect similar misuse.

But the bigger takeaway is that AI is fundamentally altering the economics of cybercrime. As the report bluntly puts it, “Traditional assumptions about the relationship between actor sophistication and attack complexity no longer hold.”

One person, with the right AI assistant, can now mimic the work of a full hacking crew. Ransomware is available as a SaaS subscription. And hostile states are embedding AI into espionage campaigns.

Cybercrime was already a lucrative business. With AI, it’s becoming frighteningly scalable.

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

Source: https://decrypt.co/337055/vibe-hacking-criminals-weaponizing-ai-help-bitcoin-anthropic

Market Opportunity
Threshold Logo
Threshold Price(T)
$0.009895
$0.009895$0.009895
-0.25%
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Crowned South Korea’s Most-Traded Crypto of 2025

XRP Crowned South Korea’s Most-Traded Crypto of 2025

XRP Surpasses Bitcoin and Ethereum as South Korea’s Most Traded Crypto in 2025According to renowned market analyst X Finance Bull, XRP dominated South Korea’s crypto
Share
Coinstats2026/01/16 16:54
DeFi Development Corp. expands Solana treasury accelerator

DeFi Development Corp. expands Solana treasury accelerator

Solana-focused DeFi Development Corp. has announced the expansion of its Treasury Accelerator program. Institutional interest in altcoins, including Solana, is rising. On Thursday, September 18, DeFi Development Corp. announced an expansion of its Solana treasury strategy. Notably, the firm will…
Share
Crypto.news2025/09/18 23:30
Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse?

Whales offload 200 million XRP leaving market uncertainty behind. XRP faces potential collapse as whales drive major price shifts. Is XRP’s future in danger after massive sell-off by whales? XRP’s price has been under intense pressure recently as whales reportedly offloaded a staggering 200 million XRP over the past two weeks. This massive sell-off has raised alarms across the cryptocurrency community, as many wonder if the market is on the brink of collapse or just undergoing a temporary correction. According to crypto analyst Ali (@ali_charts), this surge in whale activity correlates directly with the price fluctuations seen in the past few weeks. XRP experienced a sharp spike in late July and early August, but the price quickly reversed as whales began to sell their holdings in large quantities. The increased volume during this period highlights the intensity of the sell-off, leaving many traders to question the future of XRP’s value. Whales have offloaded around 200 million $XRP in the last two weeks! pic.twitter.com/MiSQPpDwZM — Ali (@ali_charts) September 17, 2025 Also Read: Shiba Inu’s Price Is at a Tipping Point: Will It Break or Crash Soon? Can XRP Recover or Is a Bigger Decline Ahead? As the market absorbs the effects of the whale offload, technical indicators suggest that XRP may be facing a period of consolidation. The Relative Strength Index (RSI), currently sitting at 53.05, signals a neutral market stance, indicating that XRP could move in either direction. This leaves traders uncertain whether the XRP will break above its current resistance levels or continue to fall as more whales sell off their holdings. Source: Tradingview Additionally, the Bollinger Bands, suggest that XRP is nearing the upper limits of its range. This often points to a potential slowdown or pullback in price, further raising concerns about the future direction of the XRP. With the price currently around $3.02, many are questioning whether XRP can regain its footing or if it will continue to decline. The Aftermath of Whale Activity: Is XRP’s Future in Danger? Despite the large sell-off, XRP is not yet showing signs of total collapse. However, the market remains fragile, and the price is likely to remain volatile in the coming days. With whales continuing to influence price movements, many investors are watching closely to see if this trend will reverse or intensify. The coming weeks will be critical for determining whether XRP can stabilize or face further declines. The combination of whale offloading and technical indicators suggest that XRP’s price is at a crossroads. Traders and investors alike are waiting for clear signals to determine if the XRP will bounce back or continue its downward trajectory. Also Read: Metaplanet’s Bold Move: $15M U.S. Subsidiary to Supercharge Bitcoin Strategy The post Whales Dump 200 Million XRP in Just 2 Weeks – Is XRP’s Price on the Verge of Collapse? appeared first on 36Crypto.
Share
Coinstats2025/09/17 23:42