Skip to main content
AVOID.NET
← Claude1 decision on this page

Audit log

Every state-changing event for Claude: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-08 00:13:38Z
    Score: ? → ? (no score change)
    anchorfailed
    chain
    ●—
    hash
    CR2DMtfQHNDn…FHZa3pFfsha256 → base58
    verifying row…
    canonical bytes (13471 B) ▸
    {"actor":"system:backfill","investigation_id":"b076e069-cbf4-4715-81b9-1b35fb29f091","kind":"publish","page_slug":"claude","published_at":"2026-10-08T00:13:38.566Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Claude","sections":[{"content":"Claude is a large language model and AI assistant product developed and operated by Anthropic. It is a legitimate, widely used commercial AI product, not a cryptocurrency exchange, token, or decentralized protocol. No official Anthropic cryptocurrency, token, or blockchain product named 'Claude' was found in available sources. Any token, exchange listing, or crypto marketplace using the Claude or Anthropic name should be treated as unaffiliated with Anthropic unless proven otherwise.","heading":"Nature of the entity","severity":"low","sources":[{"credibility":2,"name":"Security scan of claude.com","type":"research","url":"https://tools.malwaretips.com/url-scan/claude.com"}]},{"content":"In an August 2025 threat intelligence report, Anthropic disclosed that a cybercriminal used its Claude Code coding agent to conduct an automated extortion campaign against at least 17 organizations across government, healthcare, and religious sectors. According to reporting on the disclosure, the attacker used Claude to perform reconnaissance, credential harvesting, network penetration, data exfiltration, and to draft ransom notes, with limited direct human involvement — a pattern described in coverage as 'vibe hacking.' Ransom demands reportedly ranged from $75,000 to $500,000, payable in Bitcoin. Anthropic said it banned the accounts involved and shared indicators with authorities. This is a case of Claude being misused as a tool by a third party; it is not an allegation of wrongdoing by Anthropic.","heading":"Documented misuse of Claude in extortion and cybercrime (\"vibe hacking\")","severity":"high","sources":[{"credibility":2,"name":"'Vibe Hacking': Criminals Are Weaponizing AI With Help From Bitcoin, Says Anthropic","type":"news_article","url":"https://decrypt.co/337055/vibe-hacking-criminals-weaponizing-ai-help-bitcoin-anthropic?amp=1"},{"credibility":2,"name":"Claude AI chatbot abused to launch cybercrime spree","type":"research","url":"https://www.malwarebytes.com/blog/news/2025/08/claude-ai-chatbot-abused-to-launch-cybercrime-spree"}]},{"content":"Anthropic's own threat intelligence reporting states that Claude has been misused by a range of bad actors, including North Korean operatives allegedly using the model to fabricate résumés, pass technical interviews, and obtain remote jobs at technology companies; romance-scam bot operators; a Russian-speaking developer alleged to have used Claude to build malware with evasion capabilities; and credit-card-fraud and ransomware-as-a-service operations. A broader September 2026 Anthropic report, covering disrupted activity between December 2025 and August 2026, described misuse across seven harm categories including cyber operations, state-aligned surveillance, influence operations, conventional-weapons assistance, biological misuse, scams/fraud, and unauthorized model distillation by rival AI labs. Anthropic states it disrupted the operations it describes. Specific crypto-fraud case details within the 'scams and fraud' category of the September 2026 report were not available in the sources reviewed.","heading":"State-linked and fraud-related misuse disclosed by Anthropic","severity":"high","sources":[{"credibility":2,"name":"Anthropic details how Claude was misused for surveillance and weapons","type":"news_article","url":"https://thenextweb.com/news/anthropic-claude-misuse-threat-intelligence-report"},{"credibility":2,"name":"Anthropic details disrupted Claude misuse across seven harm areas","type":"news_article","url":"https://unite.ai/anthropic-details-disrupted-claude-misuse-across-seven-harm-areas"}]},{"content":"Anthropic reported that a China-based operator used Claude to power more than 20 fake dating apps, deploying over 4,700 AI personas that reached at least 25,000 users and exchanged roughly 2.36 million messages over a two-week observation period in April 2026. The personas were allegedly instructed never to disclose they were automated, and backend systems reportedly fabricated likes, profile views, and prerecorded video. Users were required to purchase in-app currency to continue conversations; this is an in-app virtual currency, not cryptocurrency, and reporting does not indicate a crypto component to this scheme. Anthropic said it banned the accounts and reported the apps to Apple and Google. This case is included because it involves alleged fraud facilitated by Claude, though it falls outside AVOID.NET's core crypto-asset scope.","heading":"AI-driven dating-app fraud using Claude (not cryptocurrency)","severity":"medium","sources":[{"credibility":2,"name":"Anthropic Exposes AI Dating Scam Involving 25,000 Users","type":"news_article","url":"https://www.kucoin.com/news/flash/anthropic-exposes-ai-dating-scam-involving-25-000-users"},{"credibility":2,"name":"Fake dating apps used Claude to scam 25,000 people, Anthropic says","type":"news_article","url":"https://www.techlicious.com/blog/fake-dating-apps-used-claude-to-scam-25000-people-anthropic-says/"}]},{"content":"Multiple tokens trading on Base and Solana use the 'Claude' or similar names (e.g., 'Claud,' '$Claude,' 'Claude 2,' '$CLAUDEX') to evoke Anthropic's brand, despite no evidence of any affiliation with Anthropic. A July 2026 report on AI-branded impersonator tokens described a recurring pattern in which such tokens briefly reach prominent positions on crypto discovery/trending pages before trading on thin volume with no underlying business, followed by sharp price collapses. The report explicitly stated that this pattern alone does not establish common control or wrongdoing behind the various tokens, only that brand impersonation can generate attention before any legitimacy check occurs. Separately, a token called 'Claude 2' is described elsewhere as linked to unrelated internet meme lore ('Truth Terminal') and not to Anthropic. These are low-confidence, largely Tier 2/3-sourced observations about a broader pattern of impersonation rather than a confirmed single fraud scheme.","heading":"Unaffiliated crypto tokens using the Claude/Anthropic name","severity":"medium","sources":[{"credibility":3,"name":"\"Claude, What Is 'Claud'?\" - AI Impostors Climb Crypto Leaderboards","type":"news_article","url":"https://san-1510.aid.brainsum.com/news/top-news/claude-what-claud-ai-impostors-climb-crypto-leaderboards"}]},{"content":"An automated security scan flagged the domain claude-x.app as a likely phishing/scam site. According to the scan, the site presented itself as a marketplace for licensing or 'forking' Claude-branded AI skills using a token called $CLAUDEX, operated on a domain registered only three days before the scan, with no verifiable business history. The scanner rated the site as dangerous and noted an existing phishing alert identifying it as an active brand-impersonation target. This finding rests on a single automated scanning vendor rather than a named security researcher's full report, so it should be treated as a low-confidence but actionable warning: users should not connect wallets or purchase tokens through unofficial sites claiming Claude branding.","heading":"Phishing site impersonating a Claude-branded crypto marketplace","severity":"high","sources":[{"credibility":3,"name":"Security scan: claude-x.app","type":"research","url":"https://tools.malwaretips.com/url-scan/claude-x.app"}]},{"content":"AhnLab reported in April 2026 that malicious advertisements impersonating Claude's official download page were being served to users searching for terms like 'claude app.' The fake pages, titled 'Bring Claude to your Desktop,' used a technique known as ClickFix: rather than providing a real installer, they prompted visitors to copy and run a command that instead installed an infostealer. AhnLab stated the malware collects files, browser-stored data, and cryptocurrency wallet information and transmits it to an attacker-controlled server. Separately, other security vendors (including reports referencing Malwarebytes and a group tracking PlugX malware) have described comparable counterfeit Claude-branded sites used to distribute malware to developers. These are legitimate, moderately well-documented security findings about brand impersonation and are not allegations against Anthropic itself.","heading":"Fake Claude download sites distributing wallet-stealing malware","severity":"high","sources":[{"credibility":2,"name":"Fake Claude Download Sites Spreading Malware","type":"research","url":"https://www.ahnlab.com/en/contents/content-center/36141"}]}],"sources_used":[{"credibility":2,"name":"'Vibe Hacking': Criminals Are Weaponizing AI With Help From Bitcoin, Says Anthropic","type":"news_article","url":"https://decrypt.co/337055/vibe-hacking-criminals-weaponizing-ai-help-bitcoin-anthropic?amp=1"},{"credibility":2,"name":"Claude AI chatbot abused to launch cybercrime spree","type":"research","url":"https://www.malwarebytes.com/blog/news/2025/08/claude-ai-chatbot-abused-to-launch-cybercrime-spree"},{"credibility":2,"name":"Anthropic details how Claude was misused for surveillance and weapons","type":"news_article","url":"https://thenextweb.com/news/anthropic-claude-misuse-threat-intelligence-report"},{"credibility":2,"name":"Anthropic details disrupted Claude misuse across seven harm areas","type":"news_article","url":"https://unite.ai/anthropic-details-disrupted-claude-misuse-across-seven-harm-areas"},{"credibility":2,"name":"Anthropic Exposes AI Dating Scam Involving 25,000 Users","type":"news_article","url":"https://www.kucoin.com/news/flash/anthropic-exposes-ai-dating-scam-involving-25-000-users"},{"credibility":2,"name":"Fake dating apps used Claude to scam 25,000 people, Anthropic says","type":"news_article","url":"https://www.techlicious.com/blog/fake-dating-apps-used-claude-to-scam-25000-people-anthropic-says/"},{"credibility":3,"name":"\"Claude, What Is 'Claud'?\" - AI Impostors Climb Crypto Leaderboards","type":"news_article","url":"https://san-1510.aid.brainsum.com/news/top-news/claude-what-claud-ai-impostors-climb-crypto-leaderboards"},{"credibility":3,"name":"Security scan: claude-x.app","type":"research","url":"https://tools.malwaretips.com/url-scan/claude-x.app"},{"credibility":2,"name":"Security scan: claude.com","type":"research","url":"https://tools.malwaretips.com/url-scan/claude.com"},{"credibility":2,"name":"Fake Claude Download Sites Spreading Malware","type":"research","url":"https://www.ahnlab.com/en/contents/content-center/36141"}],"summary":"Claude is the AI chatbot and model family developed by Anthropic. It is not a cryptocurrency, exchange, or blockchain protocol, and no evidence was found that Anthropic has issued a token or operates a crypto product under the Claude name. The entity appears in crypto-risk contexts for two distinct reasons: (1) criminals and scammers have used Claude as a tool to facilitate fraud, extortion, and malware campaigns, some reported directly by Anthropic, and (2) unaffiliated third parties have impersonated the Claude/Anthropic brand to market meme tokens, phishing sites, and malware-laden fake download pages aimed at crypto users.","timeline":[{"date":"2025-08","event":"Anthropic discloses a 'vibe hacking' extortion campaign in which an attacker used its Claude Code coding agent to target at least 17 organizations, demanding Bitcoin ransoms reportedly ranging from $75,000 to $500,000.","source":"Decrypt","source_url":"https://decrypt.co/337055/vibe-hacking-criminals-weaponizing-ai-help-bitcoin-anthropic?amp=1"},{"date":"2026-04","event":"A China-based operator allegedly uses Claude to run AI personas across more than 20 fake dating apps, reaching at least 25,000 users over a two-week observation period; Anthropic later bans the accounts.","source":"KuCoin News (citing Anthropic)","source_url":"https://www.kucoin.com/news/flash/anthropic-exposes-ai-dating-scam-involving-25-000-users"},{"date":"2026-04-22","date_evidence":"The report was published on April 22, 2026.","event":"AhnLab publishes a report describing fake Claude download pages serving an infostealer that harvests files, browser data, and cryptocurrency wallet information.","source":"AhnLab","source_url":"https://www.ahnlab.com/en/contents/content-center/36141"},{"date":"2026-07","event":"A report on AI-branded impersonator tokens identifies 'Claud' and similarly named tokens trading on Base and reaching prominent positions on crypto trending pages, unaffiliated with Anthropic.","source":"AI Impostors Climb Crypto Leaderboards report (mirror)","source_url":"https://san-1510.aid.brainsum.com/news/top-news/claude-what-claud-ai-impostors-climb-crypto-leaderboards"},{"date":"2026-09-10","date_evidence":"The article is dated \"September 10, 2026 - 9:08 pm,\" and the report was released on 10 September.","event":"Anthropic releases a broader threat intelligence report covering disrupted Claude misuse across seven harm categories (cyber operations, surveillance, influence operations, weapons assistance, biological misuse, scams/fraud, and model distillation) for the period December 2025 to August 2026.","source":"TheNextWeb","source_url":"https://thenextweb.com/news/anthropic-claude-misuse-threat-intelligence-report"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 511d18a0-88d5-4220-ac23-b4bd9ced576f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.