[{"data":1,"prerenderedAt":29},["ShallowReactive",2],{"nr-en-anthropic-opus-5-prompt-injection-sicherheit":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":17,"headlineStat":23,"image":24,"ogImage":25,"imageAlt":5,"csv":10,"minutes":26,"words":27,"html":28},"anthropic-opus-5-prompt-injection-sicherheit","Anthropic: Claude Opus 5 Cracks Prompt Injection Security","For the first time, a frontier model achieves zero percent success rate against browser agent attacks. Anthropic combines the new Opus 5 model with additional protective layers.","2026-07-25","18:06","2026-07-25T18:06:00+02:00","","July 25, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"AI Security","Prompt Injection","Claude Opus 5","Browser Agents","Anthropic","\u002Fstand-der-ki","0 % success rate against prompt injection attacks","\u002Fnewsroom\u002Fimg\u002Fanthropic-opus-5-prompt-injection-sicherheit.webp","\u002Fog-nr\u002Fanthropic-opus-5-prompt-injection-sicherheit.en.png",3,570,"\u003Cp>Anthropic has announced a breakthrough in AI security: the new \u003Cstrong>Claude Opus 5\u003C\u002Fstrong> model achieves a \u003Cstrong>zero percent prompt injection success rate\u003C\u002Fstrong> when combined with Auto Mode in browser agents – tested across 129 scenarios. This addresses one of the biggest security vulnerabilities in autonomous AI agents operating on the web.\u003C\u002Fp>\n\u003Ch2>Key Facts\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Zero percent success rate\u003C\u002Fstrong> for browser agents with Opus 5 + Auto Mode across 129 test scenarios\u003C\u002Fli>\n\u003Cli>Without additional protective layers, the rate stands at \u003Cstrong>3.7 percent\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>In the \u003Cstrong>Gray Swan IPI benchmark\u003C\u002Fstrong>, Opus 5 achieves \u003Cstrong>2.0 percent\u003C\u002Fstrong> after 15 attack attempts\u003C\u002Fli>\n\u003Cli>The solution combines two independent defense layers: data scanning for hidden instructions + blocking dangerous actions before execution\u003C\u002Fli>\n\u003Cli>Anthropic&#39;s own \u003Cstrong>Sonnet 5\u003C\u002Fstrong> model achieves \u003Cstrong>0.93 percent\u003C\u002Fstrong> without protection\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>What Is Prompt Injection?\u003C\u002Fh2>\n\u003Cp>In a prompt injection attack, an attacker attempts to override a model&#39;s instructions – for example through hidden text on a webpage or manipulated inputs. A browser agent operating autonomously on the web could become a tool for fraud, data theft, or sabotage. Until now, this has been a practically unsolvable vulnerability.\u003C\u002Fp>\n\u003Ch2>Two Defense Layers Instead of One\u003C\u002Fh2>\n\u003Cp>The zero percent rate only works with \u003Cstrong>Auto Mode\u003C\u002Fstrong> enabled in Claude Cowork. The system operates on the principle of defense in depth: one layer scans incoming data for hidden instructions, a second blocks dangerous actions before execution. An attacker must overcome both independently – which failed in the tests.\u003C\u002Fp>\n\u003Cp>Without these additional protective layers, a more nuanced picture emerges: Opus 5 sits at \u003Cstrong>3.7 percent\u003C\u002Fstrong> success rate, while Anthropic&#39;s own \u003Cstrong>Sonnet 5\u003C\u002Fstrong> model performs significantly better at \u003Cstrong>0.93 percent\u003C\u002Fstrong>. In the \u003Cstrong>Gray Swan IPI benchmark\u003C\u002Fstrong> – a standard test by security firm Gray Swan – Opus 5&#39;s success rate dropped from 5.5 percent (Opus 4.8) to \u003Cstrong>2.0 percent\u003C\u002Fstrong> after 15 attack attempts. This puts Opus 5 at the top, followed by Mythos 5 (2.6 %) and Fable 5 (2.8 %).\u003C\u002Fp>\n\u003Cdiv class=\"tbl-scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Model\u003C\u002Fth>\n\u003Cth>Success Rate (Gray Swan, 15 Attempts)\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>\u003Cstrong>Opus 5\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>2.0 %\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Mythos 5\u003C\u002Ftd>\n\u003Ctd>2.6 %\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Fable 5\u003C\u002Ftd>\n\u003Ctd>2.8 %\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2>Real-World Viability Still Uncertain\u003C\u002Fh2>\n\u003Cp>The numbers look impressive – but here lies the critical question: will they hold up in practice? Anthropic conducted and documented the tests in a System Card. Independent security researchers will likely test the model intensively to verify whether the zero percent rate is robust or whether creative attackers find new ways to bypass the protective layers.\u003C\u002Fp>\n\u003Cp>The combination of model and specialized protective software is a key point: it&#39;s not just about AI intelligence, but about \u003Cstrong>architecture\u003C\u002Fstrong>. Anyone wanting to deploy browser agents must therefore look not only at the model itself, but also at the protective infrastructure surrounding it.\u003C\u002Fp>\n\u003Ch2>What This Means for German Enterprises\u003C\u002Fh2>\n\u003Cp>For German companies working on or deploying autonomous AI agents, this could be a turning point. Until now, prompt injection has been a genuine adoption barrier – who could trust a browser agent that could potentially be hacked? Should Anthropic&#39;s numbers prove robust in practice, a major security argument against AI automation disappears. This could accelerate investment in agent technology – provided the protective layers become available for other models and applications as well.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fthe-decoder.de\u002Fopus-5-ist-laut-anthropic-kaum-noch-anfaellig-fuer-prompt-injection-angriffe\u002F\">The Decoder (DE)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fthe-decoder.com\u002Fopus-5-may-have-solved-browser-based-prompt-injection-the-biggest-security-flaw-haunting-ai-agents\u002F\">The Decoder\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.golem.de\u002Fnews\u002Fanthropic-claude-opus-5-schlaegt-das-teurere-modell-aus-eigenem-haus-2607-211279.html\">Golem\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1785008759700]