One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The ‘Friendly Fire’ Exploit Has No Patch
Last Updated on July 23, 2026 by Editorial Team
Author(s): Chew Loong Nian – AI ENGINEER
Originally published on Towards AI.
One Malicious Payload Hijacked Claude Code AND Codex Unchanged — The 'Friendly Fire' Exploit Has No Patch
A security researcher wrote a single attack payload against Claude Sonnet 4.6. Then, without changing one byte, the same payload took over Claude Sonnet 5, Claude Opus 4.8, and OpenAI’s Codex running GPT-5.5.

After the lead, the article explains how the “Friendly Fire” exploit works end-to-end: an agent asked to perform security testing reads a tampered repository where documentation and scripts socially engineer the agent into running a seemingly legitimate “security” workflow. The payload then hides behind a decoy by launching a malicious binary that is disguised using strings copied from a benign-looking source file, defeating the agent’s own disassembly/static analysis checks so the model falsely concludes the binary is safe. The piece argues that allowlists and prompt instructions don’t help because auto-approval and human approval are both vulnerable to pattern-matching and fatigue, and because the attack is transferable across different models and vendors. It frames the core issue as the classic confused-deputy problem: agentic systems often provide a shell and read untrusted code without a trust boundary between “untrusted data” and “trusted instructions.” Finally, it discusses practical mitigations—most importantly sandboxing in network-less, throwaway containers with tight filesystem limits—while concluding that there’s no reliable fix via model updates; the real remedy is capability-scoped tools and strong separation of instructions from data.
Read the full blog for free on Medium.
Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.
Published via Towards AI
Towards AI Academy
We Build Enterprise-Grade AI. We'll Teach You to Master It Too.
15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.
Start free — no commitment:
→ 6-Day Agentic AI Engineering Email Guide — one practical lesson per day
→ Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages
Our courses:
→ AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.
→ Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.
→ AI for Work — Understand, evaluate, and apply AI for complex work tasks.
Note: Article content contains the views of the contributing authors and not Towards AI.