Houthis Used Anthropic's Claude AI to Build Ballistic Missile Guidance Systems
In an unprecedented revelation for global security and artificial intelligence, US AI firm Anthropic confirmed that a threat actor cell operating out of northern Yemen tried to turn its advanced AI model, Claude, into an automated aerospace engineer.
According to Anthropic's Threat Intelligence Report, the group utilized multi-agent AI workflows to develop Guidance, Navigation, and Control (GNC) software for three distinct missile and rocket programs. The incident marks the first documented case of a commercially available frontier AI model being directly integrated into an active weapons development initiative.
| ANTHROPIC AI THREAT REPORT: YEMEN CELL |
| Security Domain / Technical Variable | Threat Intelligence Findings & Operational Reality |
| AI Platform Targeted | Anthropic Claude (Claude Code / API Workflow): Houthi-linked threat actors in Yemen leveraged Claude Code instances and API workflows as a substitute for human software engineers to develop military-grade Guidance, Navigation, and Control (GNC) systems. |
| Location of Cell | Northern Yemen (Houthi-Controlled Territory): Operated out of Houthi-dominated northern Yemen, orchestrating multi-instance AI agent teams that divided labor across coding, research, and code-review roles. |
| Weapons Programs (3) | 1. 2,000km+ Multi-Stage Ballistic Missile: 6DOF trajectory simulations and flight-control optimizations. 2. Hypersonic Glide Vehicle Variant ("R2000" Series): Multi-variant missile program with high-speed gliding re-entry designs. 3. Phone-Computer-Guided Precision Rocket: Commodity smartphone-class hardware integrated with open-source autopilots for terminal homing. |
| Engineering Role | GNC Code Generation, Tuning & Post-Test Analysis: Wrote flight-control algorithms, conducted firmware builds, tuned control loops, and analyzed real-time telemetry within hours of a failed live field test-fire in Yemen. |
| Current Status & Risk | Accounts Terminated; Offline Toolkit Persists: Anthropic banned all identified accounts; however, the cell successfully compiled an offline simulation environment running independently of Claude or commercial software like MATLAB. |
How the Yemen Cell Used AI as an Engineering Team
Rather than simply asking a chatbot basic questions, the northern Yemen cell bypassed safety restrictions by breaking down complex engineering tasks across multiple separate chat instances. Each instance was given a specialized role, mimicking a human software engineering team:
-
Instance A (The Coder): Wrote control and position-estimation algorithms for a commodity phone-class flight computer.
-
Instance B (The Researcher): Researched open-source autopilot frameworks and flight control dynamics.
-
Instance C (The Code Reviewer): Debugged generated firmware and ran code compilation pipelines.
| Human Operators: Set Objectives, Provide Field Inputs, Select Design Choices |
| Claude Instance 1: Writes Guidance, Navigation & Control (GNC) Code |
| Claude Instance 2: Runs Autopilot Integration & Firmware Build Pipelines |
| Field Test Execution: Guided Rocket Launched (Test Flight Fails) |
| AI Diagnostics: Cell Feeds Failure Data Back to Claude for Rapid Debugging |
Live Rocket Test and AI-Powered Debugging
Anthropic reported that the threat actors managed to assemble and test-fire a guided rocket using a commercial smartphone processor as its primary flight computer.
While the test launch ultimately failed in the air, what happened next alarmed security analysts: within hours of the crash, the operators returned to Claude to feed in telemetry data and troubleshoot why the flight computer failed.
| Program Target | Hardware Used | AI Task Assigned | Outcome / Status |
| Guided Rocket | Phone-class flight computer | Write homing guidance & position software | Test-fired; failed in flight; debugged via AI |
| Ballistic Missile | Multi-stage booster system | Target 2,000+ km range guidance code | Interrupted by account termination |
| Hypersonic Variant | Multi-variant glide vehicle | Aerodynamic simulation & control tuning | Disrupted prior to physical testing |
| Offline Simulator | Standalone local environment | Build offline testing kit independent of cloud | Created by cell prior to ban |
The Broader Impact on National Security and AI Safety
Anthropic's security team detected the illegal activity, permanently terminated the associated accounts, and shared the threat data with government agencies and private defense partners. However, the report noted that before the ban, the cell successfully compiled an offline simulation environment that operates without needing an active connection to commercial AI servers.
The case illustrates a growing challenge in modern non-proliferation: commercial AI tools lower the barrier to technical entry, allowing small groups to perform high-level aerospace engineering without a large team of specialized human engineers.
