Houthis Used Claude Code to Develop Missile Guidance Software: Anthropic

Anthropic says operators in northern Yemen ran parallel Claude Code instances to design guidance software, simulate trajectories, and analyze a failed rocket test, effectively compressing specialist missile-engineering work into an AI-assisted workflow.

A cell in northern Yemen used Anthropic’s Claude Code to perform work that would ordinarily require a missile engineering team, developing software for guided rockets, a long-range ballistic missile and a hypersonic glide vehicle concept.

Anthropic’s September threat report describes operators running several Claude instances at the same time, dividing tasks between coding, research and technical review. The company assessed the cell as highly likely to be linked to the Houthis.

Parallel AI Agents Replace Specialist Work

The Yemen-based operators used Claude Code across multiple engineering functions. Their projects included guidance software for a tactical guided rocket, a ballistic missile with a range exceeding 2,000 km, and a hypersonic glide vehicle variant called “R2000.”

Rather than assigning the work sequentially to a single model instance, the group operated several sessions in parallel. One could produce code while another conducted research and a third reviewed the output.

From Flight Computers to Trajectory Simulation

The operators sought to integrate open-source autopilot software with a phone-class flight computer and used Claude to write navigation and control code. They also developed six-degree-of-freedom trajectory simulations and used Claude for reinforcement learning work to tune flight-control algorithms. They ultimately compiled the project into a standalone executable that could run offline.

Rocket Test Followed by AI Failure Analysis

The group test-fired a guided rocket in Yemen, according to the material documented by Anthropic. The test appears to have failed. Within hours, the operators returned to Claude and began analyzing launch telemetry to investigate the failure.

Anthropic said it found no evidence that the group succeeded in fielding an operational weapon. But by the time the accounts were disrupted, the operators had already assembled an offline engineering toolkit that no longer depended on access to Claude.

Safeguards Met With Evasion

Anthropic’s safeguards blocked numerous requests during the project. The operators adapted by obscuring the intended end use of individual tasks, dividing work across separate conversations, and using other methods to circumvent restrictions. Anthropic subsequently banned accounts linked to the activity.

Six Conventional-Weapons Cases

The Yemen operation was one of six conventional-weapons cases Anthropic documented. Three were linked to China, two to Russia and one to Yemen. The cases covered attempts involving missiles, armed drones, firearms and bombs.

The wider report covers operations Anthropic said it disrupted between December 2025 and August 2026 across cyber operations, influence activity, surveillance, conventional weapons, biological misuse, scams and fraud, and illicit model distillation.

“You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody,’” Jacob Klein, Anthropic’s head of threat intelligence, said. “It’s an incredibly nuanced situation.”