Former Anthropic Employee: Black Hats Use Claude and Codex, White Hats Stick to Open-Source Models
According to the BeatPulse Monitoring, employees from OpenAI and Anthropic discussing on X believe that once the open-source models catch up with the strongest closed-source models, the automated attack capability will no longer be platform-controlled. Former Anthropic employee Noah Lebovic, however, stated that the real black hat hackers are mainly using Claude Code and Codex.
He mentioned that some attackers he knows buy discounted subscription Tokens from the gray-black market. After their accounts are banned, they simply create new accounts. The closed-source model has stronger capabilities, lower subscription prices, and security restrictions that are just a threshold to bypass.
On the contrary, legitimate security teams rely more on open-source models. They cannot engage in rule-breaking jailbreaks or constantly switch accounts. Real vulnerabilities, attack commands, and exploit codes are easily detected by the closed-source model. Lebovic reported that he knows of three legitimate penetration testing teams that have adopted GLM 5.2 as their primary model.
Previously, Lebovic used Opus 4.6 to take over a bank account and access medical records in an authorized test. He believes that the current barriers are easier to stop rule-abiding defenders, while those with malicious intent can still find a way around.