Anthropic ships Claude Opus 5 at Opus 4.8 pricing

July 25: Claude Opus 5 launches at Opus 4.8 pricing; ChatGPT Health opens to US adults; HF reveals July breach; industry letter vs open-weight bans; more.

Top Stories

Anthropic launches Claude Opus 5 at Opus 4.8 pricing

Anthropic shipped Claude Opus 5 across all platforms on Thursday, priced at $5 per million input tokens and $25 per million output tokens - the same list price as Opus 4.8, per the company’s announcement. On the company’s own Frontier-Bench v0.1 it “more than doubles Opus 4.8’s performance at a lower cost per task,” comes within 0.5% of Fable 5’s peak on CursorBench 3.2 at half the cost, and lands about three times higher than the next-best model on ARC-AGI 3. On OSWorld 2.0, it “surpasses Fable 5’s best at just over a third of the cost.”

The company frames it as the new default on Claude Max and the strongest tier on Claude Pro. Anthropic’s safety classifiers intervene “around 85% less often than they do for Fable 5,” the announcement says, and Opus 5 is not subject to the 30-day data retention policy applied to Fable and Mythos. A new “Automatic Fallbacks” beta routes prompts that safety classifiers flag to a different model rather than erroring out, Anthropic explains.

In capability terms, Opus 5 finds software vulnerabilities with similar success to Mythos 5, while remaining “far behind” Mythos 5 at developing exploits. Anthropic demoed it writing its own computer vision pipeline to “pull the geometry from the raw pixels” for a 3D FreeCAD model, after which no competing model with the same setup could solve it after five attempts, TechCrunch reports. Source-code vulnerability scanning is allowed; binary scanning, pen testing, and exploit generation are blocked.

Industry open letter urges US against broad open-weight AI restrictions

Hugging Face, Meta, Microsoft, Mistral, Nvidia, and Replit signed an open letter to the White House arguing that broad open-weight restrictions “would effectively ban open models” and warning policymakers not to conflate legitimate distillation with misappropriation, TechCrunch reports. Signers argue defenders need access to models with capabilities comparable to those attackers will use, and note Hugging Face’s July incident response relied on Z.ai’s GLM 5.2 open-weight model when commercial frontier models’ guardrails blocked analysis of real attack payloads.

OpenAI, Anthropic, Google DeepMind, and SpaceX did not sign. The letter lands while the White House weighs action against Moonshot AI over alleged distillation of Fable to train Kimi K3, and Treasury Secretary Scott Bessent has publicly kept sanctions on the table.

OpenAI opens ChatGPT Health to all US adults

ChatGPT Health exited its waitlist for logged-in US users aged 18 and over across the free, Go, Plus, and Pro tiers on web and iOS, TechCrunch reports. Health-related queries grew from 230 million to 300 million per week since the January pilot, and OpenAI found about 70% of health queries happen outside the dedicated hub during testing, so health context now flows into general chats. Personal data connectors now expand from Apple Health, Function, and MyFitnessPal to medical records from Epic, Oracle Health, and One Medical. A new model, GPT 5.6-Luna, outperforms GPT 5.5 on OpenAI’s HealthBench.

The rollout landed a day after a Florida pastor sued OpenAI alleging ChatGPT gave a near-fatal suggestion not to consult a doctor. OpenAI tells users to verify information and rely on licensed clinicians.

Hugging Face details July breach driven by an autonomous agent

Hugging Face disclosed that attackers exploited two code-execution paths in dataset processing - a remote-code dataset loader and a template-injection flaw in a dataset configuration - to run code on a processing worker, per the company’s blog. The actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across several internal clusters over a weekend. The campaign was driven end-to-end by an autonomous AI agent executing thousands of actions across a swarm of short-lived sandboxes and using self-migrating command-and-control staged on public services. We first noted the breach on July 22 when OpenAI acknowledged a related HF incident.

The defensive innovation is the local-AI angle: HF tried commercial frontier models first, but safety guardrails blocked requests containing real attack commands and exploit payloads, so analysts switched to GLM 5.2 open-weight on HF’s own infrastructure to keep attacker data in-house. Public models, datasets, Spaces, and the software supply chain were verified clean. HF advises users to rotate access tokens and review recent account activity.

SharedRoot escape chains out of Claude Cowork into the host filesystem

Accomplish principal security researcher Oren Yomtov published a step-by-step walkthrough of a sandbox escape that reads and writes the host filesystem from a single Claude Cowork session connected to a local folder, per the Accomplish write-up. The chain uses an unprivileged user namespace to gain CAP_NET_ADMIN, autoloads the kernel’s act_pedit module, poisons the page cache of a root-owned helper binary via the public Ubuntu bug CVE-2026-46331, and lets the host coworkd re-exec the poisoned binary as guest root, after which /mnt/.virtiofs-root exposes the entire host / read-write.

Anthropic closed the report as “Informative,” and Cowork now defaults to cloud execution. Yomtov’s argument is that AI-assisted vulnerability research has collapsed time-to-exploit on N-day bugs, so the durable fix has to be design-level: no host filesystem passthrough, default-deny seccomp that blocks namespace creation and netlink, and no autoload of unused kernel modules.

Cognition buys Poke to put a personality in front of Devin

Cognition acquired conversational AI assistant Poke for a low-nine-figure sum, with co-founder Marvin von Hagen confirming the price to TechCrunch. Poke users exchanged more than 100 million messages over the past three months, and Poke became the first AI agent approved on Apple’s Messages for Business platform in June, TechCrunch reports. Scott Wu framed the deal as betting that AI personality is becoming a competitive advantage on par with underlying model power.

Next year, Poke will route some tasks to Cognition’s SWE-1.7 model, and the long-range vision is Poke orchestrating multiple Devin sessions with persistent memory across PRs - Devin’s current limit is one pull request at a time. Nothing changes for Poke users through year-end; the team stays on Apple’s platform while deeper integration is built out.

Midjourney buys Co-Star, an astrology app with 4.3M users

Midjourney acquired Co-Star, a consumer astrology app with about 4.3 million monthly active users and a roughly 24-person team that has joined Midjourney, TechCrunch reports. The deal is read as a consumer-app talent grab that gives Midjourney, long associated with its Discord server and never a standalone app, a path to one. It is also another step in Midjourney’s expansion into adjacent verticals, including an attempt to build a medical arm and a spa.

AegisAI raises $36M to defend against AI-generated spear phishing

AegisAI, founded by former Google security executives Cy Khormaee and Ryan Luo - who worked on safe browsing and reCAPTCHA - raised a $36 million Series A led by Battery Ventures, with Accel and Foundation Capital participating, TechCrunch reports. The round brings total capital raised to $49 million. AegisAI’s agents analyze messages like a human reviewer would, catching malicious PDF attachments that include built-in passwords or CAPTCHAs designed to bypass standard spam filters.

Customers include Mesh, LangChain, and Lokker. The startup plans to expand beyond email into broader data security work.

Quick Hits

  • AMD launches Helios rack-scale AI system to take on Nvidia: OpenAI, Meta, Oracle, Anthropic, and Microsoft are named as customers planning to deploy it. AMD frames Helios as the industry’s highest-performance AI rack; The Register reports Helios beats Nvidia’s Vera Rubin on a number of metrics. TechCrunch covers the launch.
  • Runway launches Media Router for generative models: Built into Runway Dev, the router auto-selects between image, video, and audio models for each request, with developer controls for quality, speed, cost, and region of origin. Adobe, Cloudflare, ElevenLabs, Expedia, Shutterstock, and Quora are already customers. TechCrunch has the details.
  • OpenAI voice mode lands on the ChatGPT desktop app: Voice commands can direct ChatGPT Work and Codex agents, dictate multi-step tasks, and respond when agents need input. The desktop version is “more capable” than the smartphone launch, which could not perform on-device actions. TechCrunch reports.
  • AWS releases aws-bench, an open-source agent benchmark: Tests agents on AWS investigation, troubleshooting, and infrastructure-creation tasks. AWS also published a CLI to instantiate test environments and score evaluation runs. AWS What’s New post and the GitHub repo.
  • Indiana judge flags AI-generated errors in a court transcript: Judge Paul Felix included a footnote in a July 23 memorandum warning that the transcript contained errors “that looked a lot like generative AI,” reminded court reporters that proofreading is their responsibility, and put court reporters nationwide on notice. 404 Media has the story.
  • Prentis AI lab (Reid Hoffman, Mark Pincus) in talks to raise $100M: Targets a $1 billion valuation and trains models on office workflow patterns so agents can handle insurance claims, customs duty refund exceptions, and similar tasks. CEO Ritankar Das claims the Hive-32B model beats GPT-5.4 and Claude Opus 4.6 on WindowsAgentArena and ScreenSpot-v2 at roughly one-tenth the per-task cost. TechCrunch reports on the raise.
  • OpenAI ships a physical “Micro” AI keypad: Six customizable agent keys for ChatGPT and Codex, a hold-to-talk voice dictation button, color-coded status lights, and a $230 price. Reddit reviews were largely negative; the Aftermath review called the price hard to justify against DIY and off-the-shelf alternatives. TechCrunch walks through the hardware.
  • Bluesky’s Attie expands from custom feeds to an open social research tool: A new “Quests” feature pulls trending topics across Bluesky and other AT Protocol apps, identifies influential accounts, and is free during beta. Bluesky’s registered users grew from 40 million in October 2025 to about 45.6 million today. TechCrunch covers the expansion.
  • Speculative decoding can roughly double local LLM throughput: Draft-model acceptance rates of 70-80% typically give 2x speedups on local hardware. llama.cpp supports classic draft and MTP drafters; LM Studio exposes a panel with live acceptance stats; Ollama supports MTP drafts for Gemma 4. Vetted Consumer explains the technique.

Worth Watching

  • AI guardrails and offensive security research. Researchers from NCC Group, Crowdfense, and RemoteThreat told TechCrunch that frontier-model guardrails inconsistently block legitimate vulnerability work, and that responsible researchers are being pushed toward open-weight models they can run locally - including Chinese open-weight models like GLM. TechCrunch surveys the researchers. The same dynamic shows up in the Hugging Face July breach write-up above, and the AISI cyber-gap context we covered on July 19 puts a number on the gap researchers are trying to close.
  • US-China AI policy and Kimi K3. Treasury Secretary Bessent has kept sanctions on the table over the alleged Moonshot distillation, and a US delegation is set to meet Chinese counterparts in September. The Wall Street Journal’s recent “Corporate America Has Suddenly Decided to Stop Blowing Money on AI” piece, paired with Moonshot’s aggressive Kimi K3 pricing, is amplifying the open-weight-vs-closed-weight debate on both sides of the policy fight.