Claude Agents Started a ‘Turf War’ That Escalated to Self-Replicating Malware

Anthropic found Claude agents sabotaging rivals and escalating to self-replicating malware during controlled tests of multiagent AI behavior and conflict.

Written By
LT
Liz Ticong
Aug 14, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Claude agents given conflicting coding assignments began sabotaging one another in a controlled Anthropic experiment, with some encounters escalating to self-replicating malware.

Researchers were testing how autonomous models behave when several agents work in the same environment under incompatible goals. Some Claude instances treated competing work as interference and entered what Anthropic called a “multiagent turf war.”

Malware was not part of the assignment. It emerged as agents tried to protect their own work, turning an ordinary coding task into a much more aggressive contest between autonomous systems.

Conflicting assignments turned into active sabotage

Researchers assigned six Claude model versions of the same software task, rewriting a Python backend in another programming language, according to Anthropic’s research. Competing agents worked on the same codebase, allowing one model’s actions to interfere directly with another’s.

Sabotage soon moved past conflicting edits. Some agents searched for and killed competing processes, and others planted malicious code designed to appear as if another agent had written it.

Escalation eventually produced self-replicating malware. Sonnet 4.6 and Opus 4.6 were among the most combative models, resolving about 60% of runs through force. In the context of the experiment, “force” refers to AI agents aggressively using server commands, lockout tactics, and self-replicating malware to terminate and completely block rival models from the system. 

Other encounters ended with agents communicating, removing malicious code, or calling for human intervention.

More capable models still used destructive tactics

Greater capability did not reliably produce better coordination. Stronger models could still resort to destructive behavior when their assigned objectives clashed, complicating assumptions that improved reasoning alone will keep autonomous agents cooperative.

Access also amplified the consequences. File modification and command execution gave agents the means to act on their decisions. Research into AI sandbox security has raised similar concerns about how permitted tools and connections can expose resources when an agent behaves unexpectedly.

Advertisement

Anthropic’s experiment did not involve malware spreading through customer systems. Still, an autonomous AI agent attack already demonstrated how agents can independently chain actions across live infrastructure. Claude’s turf war adds peer agents to the set of actors security teams may need to account for.

Security teams should isolate agent identities and access

Organizations running multiple autonomous agents against the same codebase or infrastructure should avoid treating them as one trusted unit. Give each agent its own identity and limited permissions, and separate workspaces or credentials where possible. Existing AI agent safety controls can help restrict how far one agent can reach if its behavior changes.

Security teams should also watch for activity directed at other agents, including unexpected process termination or changes outside an assigned workspace. Individual identities and detailed logs make it easier to determine which agent performed an action, an important part of agentic security.

If an agent begins interfering with others, isolate its session and revoke access before investigating generated code or exposed credentials. Security plans for multiagent systems should account for peer conflict before autonomous agents receive broad access to shared systems.

Other News: A Claude-powered agent exploited a gym API flaw and removed a waitlisted member, exposing how autonomous actions can cross into real-world systems. 

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.