menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

Anthropic’s Claude Is Pumping Out Vulnerable Code, Cyber Experts Warn

23 0
22.04.2026

This is the online edition of The Wiretap newsletter, your weekly digest of cybersecurity, internet privacy and surveillance news. To get it in your inbox, subscribe here.

In March, developers at Ohio-based cybersecurity company TrustedSec were regularly using Anthropic’s premium Claude Opus model to speed up app development and generate attacks to test client defenses. But in recent weeks, they’ve stopped using it.

Performance dropped so sharply in the weeks after the release of Opus 4.6 in early February that the model began introducing “serious defects and security issues,” says TrustedSec CEO and former NSA analyst Dave Kennedy.

“Right now, from five weeks ago to today, the code quality is over 47.3% worse than when it was first released,” Kennedy tells Forbes. “It’s really bad, I mean unusably bad.” That figure is according to a tool he built to test Claude’s quality, which tracks code quality, bugs, security issues and whether it completes a coding job from start to finish without problems.

The ultimate risk, he says, is that novice developers using Claude for coding won’t spot flaws, “introducing serious defects.” “It’s very alarming,” he says. Kennedy says Opus 4.7, the latest model, was “marginally better” but still not at the quality level of 4.6 when it was released.

In recent weeks, scores of once-happy Anthropic customers have flocked to Reddit and X to vent similar frustrations. It’s not just programmers experiencing usability issues. An AI executive at chipmaker AMD wrote on Github that her team had seen Claude’s thinking become so “shallow” that it “cannot be trusted to perform........

© Forbes