Never let a Good Sputnik Moment go to Waste
Anthropic reported the first AI automated cyberattack. Will we ignore it?
On November 13th, Anthropic reported something truly remarkable: they disrupted an almost entirely AI-orchestrated cyber operation. A Chinese state-sponsored group had jury-rigged a framework allowing Claude to orchestrate a battery of agents and off-the-shelf attack tools against up to thirty high-profile targets including “large tech companies, financial institutions, chemical manufacturing companies, and government agencies.” Data theft was the goal and a small number of attacks, it seems, succeeded. The kicker: humans were relegated to an approval role, authorizing attacks and selecting targets, while AI drove 80-90% of actual execution.
It’s hard to overstate how significant this is. In Washington, ‘Sputnik Moment’ gets tossed around so liberally it’s lost almost all meaning. This time, however, the moniker fits. This is something special.
Just like Sputnik, this was unanticipated. Even Anthropic’s own engineers admitted surprise at how quickly AI cyber capabilities evolved at scale. Just like Sputnik, this demonstrates a powerful new military-relevant capability. Intelligent machines, uncapped by human fatigue, knowledge burdens, or labor constraints, are now truly stepping into the cyber battlefield. The result could be a massive step change in attack volume, speed, and effectiveness that many defenders are unequipped to manage.
Finally, just like Sputnik, this is an as-yet crude capability that will only improve. When Sputnik-1 launched, functions were limited to simple radio transmission while battery powered operational life was just three weeks. Anthropic suggests these AI capabilities were likewise limited. Only a small few attacks succeeded while persistent hallucinations undermined success. As was the case for satellite technology, however, this first version is the worst these capabilities will ever be. This is a floor, not a ceiling.
Yet unlike the original Sputnik Moment, urgency is strangely absent. The attack made headlines on November 13th, but a month later it feels as though nothing sunk in and the conversation has moved on. Worryingly, decisions made in the weeks since fail to reflect that something fundamental in global security has shifted.
Just weeks after the attacks, the Trump Administration authorized the sale of Nvidia’s H200 chip to China—the very nation backing the campaign. The H200 is superior to all Chinese AI chips and can be produced at unparalleled scale. With the H200, Chinese actors will be positioned to train potent new cyber models and run automated attacks at scales and speeds otherwise impossible. For anyone with doubts that this may be the plan, note that the very day the H200 decision was issued the Chinese military aligned School of Cyberspace Security at Beihang University issued a tender to rent H200 compute. It’s not hard to imagine the value these researchers see in these chips.
Immediately after China demonstrated it can, and will, automate cyber attacks the United States willingly handed them the exact tool needed to jump from their current capability floor right through the ceiling of possibility. After Sputnik, it would have been absurd to suggest handing rockets to the reds. This demonstrates a critical need for narrative correction. If we don’t take this moment seriously - and embrace it as the cyber Sputnik it is - we will not only fail to prepare for a world of autonomous cyber attacks but risk making decisions that will actively make this problem worse.
On Wednesday, the House of Representatives held what appears to be the most substantial official recognition of the challenge: Anthropic and others were called to discuss the attack. With congressional ears perked, this is a great moment to reset the conversation. To that end, I want to renew stress on the stakes and illustrate just a few of the critical near term risks we face if we fail to treat this moment with appropriate urgency.
The Cyber Scaling Problem
Concern boils down to one word: scale. While automation is certainly no stranger to hackers, today’s cyber risk remains fundamentally constrained by human bottlenecks. Throughout the cyber kill chain, humans write and customize attack code, conduct social engineering, engineer lateral movement, and serve as the brainy interface that unites disparate steps into one effective whole.
With humans in the loop, cyber risk has operated at human scale. Only so many hackers possess the requisite skills, only so many targets can be attacked, and attacks can only proceed so fast. With AI now removing humans from the equation, such scaling limits could fall. The impact could be felt across three major dimensions.
Scale of Attack Volume
Nestled in Anthropic’s attack report is a brief, yet significant passage:
“Under the threat actor’s direction, Claude conducted nearly autonomous reconnaissance, using multiple tools including browser automation via MCP to systematically catalog target infrastructure, analyze authentication mechanisms, and identify potential vulnerabilities.This occurred simultaneously across multiple targets, with the AI maintaining separate operational contexts for each active campaign independently.”
Not only can Claud automate cyber attacks end-to-end, but can apparently do so against multiple targets simultaneously.1 As this capability improves, and it will, the result could be a massive increase in total attack volumes.
While it’s impossible to predict exactly how this might scale, AI’s impact on phishing provides an instructive parallel. Before LLMs, crafting phishing emails was a fiddly process. They had to be typed by human hands and written without all-too common linguistic errors. ChatGPT removed those constraints overnight. Since 2022, phishing volumes have dramatically surged, with some reports indicating increases over 4,151%. Meanwhile LLM-improved prose and language translation have supercharged phishing success rates from a paltry 12% to a staggering 54%.
What makes such AI-driven multi-target attacks particularly concerning is that computational resources, not human attention, skill or time, may become the primary bottleneck to attack volumes. If an AI can maintain “separate operational contexts” for multiple campaigns, the logical endpoint are attacks that scale horizontally without meaningful constraint. Why target just Citibank when you can simultaneously attack JPMorgan, Wells Fargo, and Bank of America? Why compromise just the UK embassy when you can target every embassy in Europe?
Anthropic’s report suggests such everything, everywhere, all at once-style attacks may already be possible.
Scale of Participation
What’s striking about the Anthropic attack is how accessible the approach sounds. Rather than novel AI developments or elite malware, the attackers leaned on off-the-shelf tools that, when combined correctly, yielded capabilities greater than the sum of their parts. This was scaffolding, not breakthrough innovation. While Anthropic has called the method “highly sophisticated,” and no doubt it is, given state backing, reliance on readily available tools suggests technical barriers to advanced cyber operations are rapidly declining.
Complex operations once requiring significant expertise could soon be launched by far less capable actors with the right setup and motivation. Small or medium states may gain greater capacity to punch up at global powers. More concerning still: moderately skilled groups could attempt strikes on under-defended critical infrastructure when political grievances arise. If barriers to entry fall further, even unskilled individuals might have the tools to attack who they please.
This campaign isn’t the only sign of rapid cyber democratization. Grey Swan AI’s ARTEMIS framework recently enabled AI to outperform 9 out of 10 professional penetration testers at discovering and exploiting vulnerabilities in a live network. Like the Anthropic attacks, ARTEMIS succeeded through clever scaffolding rather than frontier model innovation. While no end-to-end hacking tool, ARTEMIS also automated core hacking skills including “reconnaissance, targeting, probing, and exploitation.” This tool is now open-sourced, demonstrating the impressive capabilities already free for anyone to build on and wield.
Meanwhile, January research from Carnegie Mellon and Anthropic found that even small LLMs, given appropriate scaffolding, can successfully execute multi-stage attacks in realistic simulations about 50% of the time. Claude Haiku 3.5, for instance, succeeded in small simulations of critical infrastructure attacks including the Equifax breach and Colonial Pipeline attack. Such small models matter deeply for cyber democratization because they are often free, cheap, unrestricted and - critically - unmonitored.2 If small models from one year ago can achieve such impressive success, today’s versions are almost certainly more capable.
Attack frameworks are increasingly available. Required models are getting smaller. Barriers to entry are rapidly declining. Given AI’s pace of progress, we may have only months until we enter a truly democratized cyber world.
Scale of Speed
AI-driven attacks will move at machine speed, striking faster and responding in near real-time with minimal defensive delay.
An immediate concern is a potential collapse in time-to-exploit: the critical window between discovering a vulnerability and deploying malicious code. In the Anthropic attacks, the system autonomously discovered known vulnerabilities, then wrote and tested exploits on the fly. What traditionally takes skilled human attackers hours or days happened in minutes.3
The time-to-exploit window matters profoundly for defense. It’s the quiet before the storm when developers can write patches, distribute updates, and shore up defenses before attacks materialize. Yet it’s already shrinking. In the first half of 2025, 32% of exploits appeared within 24 hours of their target vulnerabilities being disclosed—a staggering development. Still, in a 68% supermajority of cases defenders retained a window of days, weeks, months or even years to act. When AI can write exploits at machine speed, these statistics could flip, and the time-to-exploit defensive buffer could all but close.
The downstream effects would be severe. Modern security teams operate through triage: not every vulnerability can be patched immediately, if at all, given finite resources, personnel, and system uptime constraints. Thankfully, defenders can tread water because not every bug needs immediate patching, if at all. If AI collapses time-to-exploit, that calculus breaks. Defenders could be overloaded by constant, immediate, critical threats and be unable to prioritize or cope.
AI-driven machine speed could also accelerate attack execution. During one of the Anthropic attacks, Claude was able to “independently query databases and systems, extract data, parse results to identify proprietary information, and categorize findings by intelligence value.” For human attackers, combing through and exfiltrating data is exceptionally slow and labor intensive. Huntress’ 2025 Cyber Threat Report, for instance, found that during ransomware attacks, over 70% of an attacker’s time was spent on data analysis and extraction.4 This attack shows how AI could compress this timeline, rapidly identifying and extracting high-value information so attacks can conclude before detection.
This is just one early example of machine speed potential. While speed in cyber isn’t always paramount, many of the most impactful campaigns often instead prioritize persistent stealth- when speed matters, it matters. The NotPetya worm’s devastating impact, costing an estimated 10 billion dollars in damages, was largely a function of its incredible speed. As Cisco’s Craig Williams noted after the attack: “By the second you saw it, your data center was already gone.” That’s just a taste of machine speed’s cyber potency. As AI removes humans from the attack chain, such digital agility will become commonplace, making attacks increasingly difficult to avert if defenders cannot match the pace.
Embracing the Moment
These scaling possibilities are just a slice of the cyber risks on our immediate doorstep. As AI advances, more exotic capabilities will emerge. Malware may soon mutate attack code in real time to evade traditional defenses. In fact, there’s evidence this may be already happening. A few steps further into the future and we might see the rise of highly autonomous cyber agents that can persistently burrow into networks and operate independent of direct human command and control.
To reemphasize, the capabilities used in this attack are a floor, not a ceiling. As Anthropic notes “The attack relied on several features of AI models that did not exist, or were in much more nascent form, just a year ago.” The question: If AI performance is doubling every 7 months, as METR research shows, just how advanced will AI’s cyber potential be just one year from now?
This cyber challenge is admittedly a big challenge and solving it lacks easy answers. However, as I illustrated in my last post, there are indeed tangible steps that can be taken to mitigate and manage risks before the shoe drops.Rather than go through an exhaustive list of potential next steps, however, the big point is this: nothing will be solved without urgency. The first step is recognizing this as the cyber Sputnik moment it is.
To that end I want to put a final punctuation on the stakes. What made the original Sputnik, Sputnik was not just the innovation itself, but who innovated. It was the Soviet Union, our greatest geopolitical adversary.
In this case, the alleged culprit is again our geopolitical foe, China. What should be particularly worrying is that this incident suggests China is ahead in its understanding of AI cyber capabilities. They figured out how to launch cyber attacks with our own models before we did. 5 If they’ve stretched Claude’s capabilities this far, it’s not a jump of imagination to assume they have an even deeper understanding of what their domestic models can do.
There is a clear AI cyber understanding gap. China is ahead. We are behind. If the United States doesn’t take this seriously and invest in understanding what models can do and how to defend against them, that gap will only grow. After Sputnik, we didn’t sit idly by. When the rocket went up, checks were written. Programs were started. Security fixes were made. While not everything worked, policymakers knew urgency demanded immediate action. If we want a secure future, we should take a page out of that book. To paraphrase Winston Churchill: never let a good Sputnik Moment go to waste.
The report is unclear if it was able to maintain these operational contexts throughout the entire attack chain. Regardless, we can expect this capability to only advance.
Haiku 3.5 is small, yet an Anthropic-monitored model. Still, it demonstrates what other unmonitored in its size class could do.
Complexity matters here, and unfortunately the attack report doesn’t provide enough details to help us understand just how advanced these exploits were or how much time they may have required on the part of a human hacker. It’s relatively safe to assume the vulnerabilities targeted were common, and the exploits low-complexity. That said, this actor did something unprecedented. Our public understanding might not be sufficient to judge what may have been done in this case.
Huntress doesn’t desegregate the total time here. It’s likely a significant portion is simply data transmission. Still, if the data analysis and discovery time can be minimized this could accelerate the total process.
The Model Card for Anthropic’s Sonnet 4.5 states “qualitative feedback from red teamers suggested that the model was unable to conduct mostly-autonomous or advanced cyber operations.” Clearly understanding is limited.

