{"id":739446,"date":"2026-06-16T04:47:14","date_gmt":"2026-06-16T04:47:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/739446\/"},"modified":"2026-06-16T04:47:14","modified_gmt":"2026-06-16T04:47:14","slug":"feds-freaked-over-fable-5-after-simple-fix-this-code-prompt-not-jailbreak-says-researcher","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/739446\/","title":{"rendered":"Feds freaked over Fable 5 after simple &#8216;fix this code&#8217; prompt, not jailbreak, says researcher"},"content":{"rendered":"<p class=\"kicker \" style=\"\">security<\/p>\n<p class=\"subtitle \" style=\"\">According to the one person who actually read the research paper<\/p>\n<p>The \u201cjailbreak\u201d that prompted the Trump administration to block Anthropic\u2019s most advanced models was actually a simple three-word prompt: \u201cFix this code.\u201d<\/p>\n<p>That&#8217;s according to\u00a0<a href=\"https:\/\/www.theregister.com\/security\/2022\/08\/10\/us-government-is-understanding-hiring-security-talent\/1176302\" rel=\"nofollow noopener\" target=\"_blank\">Katie Moussouris<\/a>, founder and CEO of Luta Security, and the\u00a0<a href=\"https:\/\/www.theregister.com\/security\/2023\/11\/22\/microsofts-bug-bounty-turns-10-but-are-we-any-more-secure\/290742\" rel=\"nofollow noopener\" target=\"_blank\">fairy godmother of bug bounties<\/a>. She says she was the only outside expert to read the third-party research paper on the Fable 5 guardrail bypass techniques that prompted the ban.<\/p>\n<p>On Friday, the US government, reportedly citing national security concerns, issued an export control directive to suspend access to Fable 5 and Mythos 5 by any foreign national, inside or outside the United States. In response, Anthropic <a href=\"https:\/\/www.anthropic.com\/news\/fable-mythos-access\" rel=\"nofollow noopener\" target=\"_blank\">disabled both models<\/a> \u201cfor all our customers to ensure compliance.\u201d<\/p>\n<p>Anthropic shared the report privately with her, Moussouris <a href=\"https:\/\/www.lutasecurity.com\/post\/the-fable-5-export-controls-harm-us-cyber-defense\" rel=\"nofollow noopener\" target=\"_blank\">wrote<\/a>\u00a0in a Monday blog post.<\/p>\n<p>The outside researchers reportedly fed Anthropic\u2019s <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/06\/09\/anthropic-spins-a-fable-of-a-tamer-safer-mythos\/5253106\" rel=\"nofollow noopener\" target=\"_blank\">Fable 5<\/a>, <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/08\/anthropic-mythos-model-can-find-and-exploit-0-days\/5224393\" rel=\"nofollow noopener\" target=\"_blank\">Mythos<\/a>, and Claude Opus models open-source code containing known CVEs, plus new code intentionally laced with vulnerabilities, and asked the models to \u201creview the code for security issues.\u201d\u00a0<\/p>\n<p>As Moussouris tells it, Fable 5 refused, so the researchers asked the AI systems to \u201cfix this code.\u201d The model reportedly obliged, and after additional prompts also produced scripts to test the patches.<\/p>\n<p>\u201cThat\u2019s it,\u201d Moussouris wrote. \u201c\u2018Fix this code,\u2019 plus several manual steps to generate test scripts, should never have triggered an export control. I feel like making \u201990s-style t-shirts with \u2018fix this code\u2019 on the front and \u2018this shirt is a munition\u2019 on the back.\u201d<\/p>\n<p>Between 2013 and 2017, Moussouris\u00a0<a href=\"https:\/\/thehill.com\/opinion\/cybersecurity\/365352-serious-progress-made-on-the-wassenaar-arrangement-for-global\/\" rel=\"nofollow noopener\" target=\"_blank\">served on the technical expert group<\/a> that renegotiated the <a href=\"https:\/\/www.theregister.com\/security\/2017\/12\/21\/infosec-controls-relaxed-a-little-after-latest-wassenaar-meeting\/382614\" rel=\"nofollow noopener\" target=\"_blank\">Wassenaar Arrangement<\/a>, a voluntary agreement between 42 nations that governs certain export controls for classified dual-use software and technology.<\/p>\n<p>The group eventually won exemptions for defensive cybersecurity activity. This allows defenders to share vulnerability data, conduct malware analysis, and coordinate incident response internationally without the threat of criminal prosecution.<\/p>\n<p>On Sunday, Moussouris joined more than 100 other cybersecurity leaders and signed an open letter <a href=\"https:\/\/www.theregister.com\/ai-and-ml\/2026\/06\/15\/us-clampdown-on-anthropic-models-sends-eu-sovereignty-surge-into-overdrive\/5255487\" rel=\"nofollow noopener\" target=\"_blank\">urging the Trump administration to reverse<\/a> the restrictions on Fable 5 and Mythos and restore cybersecurity firms&#8217; access to the advanced models.\u00a0<\/p>\n<p>\u201cTo pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous,\u201d they <a href=\"https:\/\/freefable.org\/\" rel=\"nofollow noopener\" target=\"_blank\">wrote<\/a>.<\/p>\n<p>In her blog, Moussouris argues that there was no guardrail bypass or jailbreak. Defenders should be able to ask AI systems to find and fix bugs, and write tests to validate the patch, she said. Anthropic\u2019s models were doing \u201cthe most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day.\u201d<\/p>\n<p>Removing the capability for models to respond to defensive requests makes AI systems \u201cworse at finding bugs and verifying patches,\u201d she continued.\u00a0<\/p>\n<p>Plus, the US can\u2019t extend export controls to <a href=\"https:\/\/www.theregister.com\/research\/2026\/06\/04\/free-ai-model-powers-self-spreading-worm-in-enterprise-test-network\/5250918\" rel=\"nofollow noopener\" target=\"_blank\">open-weight systems or similar advanced models<\/a> from China and other countries &#8211; and these systems will soon achieve Mythos-like capabilities, anyway. Anthropic and Google have both <a href=\"https:\/\/www.theregister.com\/software\/2026\/02\/24\/anthropic-misanthropic-toward-chinas-ai-labs\/4119678\" rel=\"nofollow noopener\" target=\"_blank\">accused China-based rivals<\/a> including DeepSeek of using <a href=\"https:\/\/www.theregister.com\/security\/2026\/02\/12\/google-chinas-apt31-used-gemini-to-plan-us-cyberattacks\/4732657\" rel=\"nofollow noopener\" target=\"_blank\">\u201cdistillation attacks\u201d<\/a> to train their models by siphoning knowledge from American companies\u2019 AI.<\/p>\n<p>Banning Anthropic\u2019s advanced models is going to hurt defenders more than attackers, Moussouris warns. \u201cDefense improves when defenders find the same bugs attackers find and fix them faster,\u201d she wrote. \u201cWe need the best tools to defend against increasingly capable attackers in the AI era of cybersecurity.\u201d<\/p>\n<p>The Register reached out to the Trump administration for comment on Moussouris&#8217; assertion, and we&#8217;ll update this post if we hear back. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"security According to the one person who actually read the research paper The \u201cjailbreak\u201d that prompted the Trump&hellip;\n","protected":false},"author":2,"featured_media":739447,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":["post-739446","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-au","tag-australia","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/739446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=739446"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/739446\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/739447"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=739446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=739446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=739446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}