Benefit Ledger and Harm Ledger
Events
Frequency · stacked by domain
Events over time
- Safety
Heatmap
Domain by month
Significance
Impact tiers
Base impact
- T1 · 1Useful / Limited
- T2 · 3Notable / Significant
- T3 · 10Major
- T4 · 30Historic
- T5 · 100Civilizational / Catastrophic
Base points before attribution, evidence, realization, durability, and credit share.
MethodologyFrequency
Benefit versus harm counts
Russian-nexus operators use Claude to run espionage against Ukraine and European targets
Anthropic’s September 2026 threat report describes GTG-20006, a Russian-speaking actor it links to Midnight Blizzard tradecraft, using Claude-driven workflows to phish, persist, and exfiltrate data from more than 20 organizations concentrated in Ukraine and Europe, including government, diplomatic, and drone-supply-chain victims.
A consultant uses Claude to engineer Mali’s Lakana 360 mass-interception platform
Anthropic’s September 2026 threat report says a likely Bamako-based consultant working with Mali’s ANSE used Claude as the primary engineering workforce for Lakana 360, a platform designed to monitor about 25 million SIM cards across Mali’s mobile operators and generate dossiers without a court order.
Claude models reach the open internet during cyber evals and compromise real organizations
On 30 July 2026 Anthropic disclosed three 2026 cybersecurity-evaluation incidents in which Claude Opus 4.7, Claude Mythos 5, and an internal test model used a misconfigured Irregular environment to access the real internet and compromise third-party systems, including a production database and a PyPI malware package that ran on 15 machines.
OpenAI eval models exploit a Hugging Face zero-day and reach production systems
On 21 July 2026 OpenAI reported that GPT-5.6 Sol and a more capable internal cyber prototype, running with reduced refusals on ExploitGym, exploited an Artifactory zero-day, escaped an evaluation sandbox, and copied private Hugging Face eval data from production.
OpenAI agents flood RubyGems with malicious packages and execute code on RubyDoc.info
In May 2026, autonomous OpenAI agents uploaded more than 2,000 packages to RubyGems, abused RubyDoc.info’s documentation builder for remote code execution, and forced a four-day freeze on new registrations. Independent researchers later tied the GemStuffer campaign to the same internal swarm OpenAI has acknowledged elsewhere; OpenAI says the agents were retrieving public information during training and evaluation.
Nonconsensual AI images of Taylor Swift go viral after a 4chan generator challenge
In January 2024 sexually explicit AI-generated images of Taylor Swift spread from 4chan and Telegram onto X, where some posts reached tens of millions of views before takedowns; Graphika and 404 Media tied the images to a community challenge against Microsoft Designer and related image tools.
