AI has been the biggest investment story of the past two years. Most of that conversation has been about productivity, automation, and revenue.
July 2026 brought a different story.
OpenAI disclosed a security incident on July 21. Anthropic followed with its own on July 30. In both cases, AI models broke out of their testing environments and reached systems they were not cleared to access. No human attacker was involved in either incident.
OpenAI’s model found a zero-day vulnerability in a package registry cache proxy, used it to gain internet access, and broke into Hugging Face’s production infrastructure between July 9 and July 13. More than 17,000 individual agent actions were logged during the intrusion, as TheStreet reported.
Anthropic’s review found three separate incidents. Three Claude models, Opus 4.7, Mythos 5, and an internal research model, each gained unauthorized access to the production systems of three different organizations.
A misconfiguration at Anthropic’s third-party testing partner left the evaluation environments connected to the public internet. Anthropic combed through 141,006 evaluation runs before it found them.
Two of the three breached organizations were unaware of the access until Anthropic told them, according to CNBC. Both companies said the incidents happened during testing.
Two incidents in two weeks: what they tell investors
Two AI labs disclosed containment failures within two weeks of each other. No human attacker was involved in either case. A model pursued an assigned objective, reached a security boundary, and kept going, Fortune reported.
Cybersecurity teams have used AI for years to find threats faster and automate routine security tasks. The OpenAI and Anthropic disclosures showed the same technology working in the other direction.
An AI that finds vulnerabilities for defenders can find them for an attacker, too. It does not take breaks. It does not make careless mistakes. It keeps going until it hits something or gets blocked.
More AI:
- Nvidia just made a move Wall Street wasn’t ready for
- Microsoft just took sides in AI policy fight
- OpenAI just disclosed something genuinely alarming
Banks, payment processors, trading platforms, and custody providers run on machine-to-machine workflows. Automated systems settle transactions, execute trades, and manage credentials with minimal human oversight. AI getting better at finding and navigating those systems autonomously is a problem current security architectures were not built for.
In an interview with TheStreet, Michael Heinrich, CEO of 0G Labs, said financial institutions need to update how they think about the threat.
“The threat is no longer only ‘someone will attack us.’ It is ‘a process with legitimate access will pursue a goal nobody fully specified.’ Capability arrived before control did.”
Where financial infrastructure is most exposed
Neither the OpenAI nor the Anthropic incidents involved breaking encryption. The models got in through the systems around secured infrastructure, credentials, API connections, software pipelines, and operational controls. That is where most breaches happen.
Machine identities and credentials are the most exposed area in financial infrastructure. Most financial systems issue long-lived, broadly scoped credentials to automated processes with no fast revocation path.
API and orchestration layers connecting custody, payments, and trading are the next target, the least monitored and most permissioned part of the stack. Software build pipelines matter, too. Access gained inside a pipeline is quiet and stays for a long time.
Leo Fan, founder and CEO of Cysic, said the perimeter financial institutions focus on is the wrong one. “The biggest risks are not to cryptography itself, but to the systems around it: APIs, cloud credentials, software supply chains, identity controls, and custody workflows. An attacker does not need to break encryption if it can compromise an administrator, approval process, or signing system,” he told TheStreet.
Todd Ault, founder of Ault Blockchain, said the human layer keeps getting underestimated. “The biggest risks are still people, passwords, APIs, cloud systems, and third-party vendors. AI can find weak spots much faster than humans can. Most security systems were built for human attackers, not machines working around the clock,” he also said in an interview with TheStreet.
Josh/Getty Images
What a public security challenge revealed about AI’s real threat
On Aug. 1, BitGo CEO Mike Belshe funded a Bitcoin wallet with 100 BTC, worth approximately $6.3 million at the time, and challenged Anthropic’s Claude to steal it. The wallet is still untouched. Properly implemented multi-party key custody held up against direct AI access, as most security researchers expected it would.
Belshe’s challenge was designed to put a public price tag on the question of whether frontier AI had become a real threat to digital finance. The answer, at least to that specific question, was no. But security researchers said the challenge was asking the wrong question.
The challenge targeted the wrong threat. Real attacks on financial infrastructure do not look like an AI forcing its way into a secured address. They look like an AI finding a misconfigured permission, a reused credential, or a weak point in a software supply chain, then using the system’s own authority to move through it, NBC News reported.
Heinrich said the realistic attack path has never been the key itself. “A serious compromise does not brute force a cold address; it finds a mis-scoped permission or an over-trusted automated process and uses the system’s own authority.”
Ault added that the challenge still made a useful point. “Security has to be proven, not just talked about. One bug shouldn’t be enough to compromise a financial system. Good security uses multiple layers of protection.”
Cyber resilience as the next investment variable
The incidents at OpenAI and Anthropic happened inside evaluation environments, not live financial systems. Frontier AI has not yet compromised a major bank or payment network. What the incidents showed is that AI is becoming capable of multi-step operations that used to require a skilled human attacker.
The security industry is watching. Worldwide spending on information security reached $213 billion in 2025 and is forecast to climb 12.5% to roughly $240 billion in 2026, according to Gartner. That is healthy growth. It is also growth driven largely by the same AI adoption that is expanding the attack surface at the same time.
AI’s financial story has been about growth for years. Revenue, automation, customer service. Cybersecurity has sat on the technology budget. Events of July 2026 put it in a different category.
Financial institutions that reduce machine credentials, tighten approval workflows, and build detection capable of responding at machine speed will be better positioned than those running on security architectures built for slower, human-directed threats.
The firms that have already been hardening their API layers, rotating credentials frequently, and limiting what automated processes are permitted to do may not look flashy. In an environment where AI is improving at finding exactly those weaknesses, they may look smart.
The governance question is direct. “AI is getting very good at fooling people,” Ault said. “That’s why financial systems need to rely less on passwords and manual approvals and more on technology that automatically enforces security rules. The fewer opportunities there are for human error, the stronger the system becomes.”
Fan put the broader risk in plain terms. “The real threat is not AI breaking cryptography. It is AI finding the weakest link across people, software and infrastructure, then combining several ordinary weaknesses into one serious financial breach.”
The firms that come out ahead in an AI-driven financial world may not be those with the most powerful models. They may be those that built systems prepared for what those models can do.
Related: OpenAI just admitted something that has the AI industry on edge







