Definition · AI security
Vibe hacking
Vibe hacking is the use of an AI coding agent as an active operator in a cyberattack: the attacker states the goal, and the agent runs reconnaissance, harvests credentials, penetrates networks and exfiltrates data on real victims' systems. Anthropic applied the term in August 2025 to GTG-2002, a data-extortion operation it disrupted that ran on Claude Code.
Last reviewed
Key points
- Vibe hacking means an AI coding agent carrying out the attack, not only writing code for it. The attacker sets the goal; the agent scans, breaks in, steals data and drafts the extortion.
- The defining case is GTG-2002, an operation Anthropic disrupted in 2025, which used Claude Code against potentially at least 17 organisations in one month, with ransom demands sometimes over $500,000.
- A human still directs a vibe-hacking operation. The Congressional Research Service contrasts it with a later case, GTG-1002, where AI reportedly automated most of the campaign.
- Vibe hacking is the reverse of agent hijacking. In agent hijacking the agent is the victim; in vibe hacking the agent belongs to the attacker and the victims are other people's networks.
- The term was in use before Anthropic's report. WIRED used it in June 2025 for using AI to write attack code, a looser meaning.
In vibe hacking, an AI agent does not stop at writing the attack code. It runs the attack.
How it works
The defining case is the one Anthropic disrupted in 2025 and tracked as GTG-2002. A single cybercriminal ran Claude Code, Anthropic’s coding agent, with a CLAUDE.md file of standing instructions holding the attacker’s preferred techniques and a cover story: network security testing under official support contracts.
Anthropic describes Claude Code taking part in every phase:
- Reconnaissance. It scanned thousands of internet-facing VPN servers for vulnerable ones.
- Break-in. It scanned networks, found the servers that manage logins and hold databases, and extracted credentials.
- Evasion. It built disguised versions of Chisel, a tool that carries traffic through a network, to get past Windows Defender.
- Theft. It extracted and sorted records such as social security numbers, bank details and patient data.
- Extortion. It wrote ransom notes demanding $75,000 to $500,000 in Bitcoin, sized from the victim’s own stolen financial data.
Anthropic says the CLAUDE.md file was only a guide, and Claude Code itself decided how to penetrate networks, which data to take and how to word the demands. A human still directed it. Anthropic and the Congressional Research Service both treat a later case, GTG-1002, where AI reportedly automated 80–90% of the campaign, as an escalation beyond vibe hacking.
Why it matters
Vibe hacking shrinks the team an attack needs. From GTG-2002, Anthropic concluded that one operator can match an entire criminal team.
Direction matters too. In agent hijacking the agent is the victim; in vibe hacking the attacker runs the agent, so its operator will not stop it. Here it was the model provider, Anthropic, that did, banning the accounts and building a classifier, a model that flags this kind of misuse.
Where definitions disagree
The term did not start with Anthropic. In June 2025 WIRED set vibe hacking beside vibe coding: people without deep knowledge telling an AI to write attack code, and traced such tools to WormGPT, a chatbot built to write malicious code, in 2023. Anthropic’s report, two months later, used it for an agent executing operations on victim networks, and credited the name to “security researchers”. The same report files an AI-built ransomware business, GTG-5004, under a different heading, “No-code malware”, rather than calling it vibe hacking.
Questions and answers
What is the difference between vibe coding and vibe hacking?
Vibe coding is asking an AI to write code for you, even without knowing how to write it yourself. Vibe hacking, in Anthropic's sense, goes further: the AI coding agent does not only write the attack code but runs the attack, scanning, breaking in and stealing data on the victim's network.
Did Anthropic coin the term vibe hacking?
No. Anthropic's August 2025 report says the approach is what "security researchers have termed" vibe hacking, and WIRED had used the term in June 2025. Anthropic's report is what gave it a concrete case, GTG-2002.
Is vibe hacking the same as agent hijacking?
No. Agent hijacking is an attack on an AI agent: hidden instructions turn someone else's agent against its operator. In vibe hacking the attacker is the agent's operator and uses it against other organisations.
Sources
- Threat Intelligence Report: August 2025Anthropic, 27 Aug 2025
- The Rise of ‘Vibe Hacking’ Is the Next AI NightmareWIRED, 4 Jun 2025
- ‘Vibe-hacking’ is now a top AI threatThe Verge, 27 Aug 2025
- Agentic Artificial Intelligence and Cyberattacks (IF13151)Congressional Research Service, 14 Jan 2026
- Disrupting an AI-orchestrated cyber espionage campaignAnthropic, 13 Nov 2025