Anthropic's Claude already exploits Chrome bugs for pocket change

Anthropic deliberately withheld its Opus model from a public bug bounty program, then revealed it could autonomously write a working Chrome exploit for $2,283—a fraction of what human security researchers command for the same work. The company's safety-first positioning around constitutional AI and measured capability deployment now conflicts with the reality that commodity LLMs already perform high-value offensive security work. Withholding Opus from public programs while benchmarking it against human security researchers suggests the gatekeeping serves competitive advantage more than principled caution. The pattern: capabilities stay private during internal testing, then get disclosed once their market value is clear.