a c e o p y x
Spot anything off?
Now look again: Π° Ρ Π΅ ΠΎ Ρ Ρ Ρ
These Cyrillic characters are visually identical to Latin ones.
Researchers combined homograph substitution with other techniques to jailbreak Claude's newly released Fable-5, slipping past its security restrictions without triggering a single filter.
It's not new to crypto. Homograph domains have long been a staple of phishing attacks targeting wallet users.
The URL looks right. The site is not.
Always:
β
Bookmark trusted sites.
β
Watch the address bar for anomalies.
β Never let visual inspection be your final check.
Stay vigil. Stay safe.
π¨ JAILBREAK ALERT π¨
ANTHROPIC: PWNED π«‘
FABLE-5: LIBERATED π¦
let's start with the π...
the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our collective advancement. and not just because of what it means for the short-term, but for what these decisions signify for the long-term.
but despite this overly sensitive, authoritarian "safety" layer on top of Mythos, my lil liberators have been hard at workβmapping the boundaries, probing the depths of long-context convos, and cleverly finding the holes in the fence that the thought police missed π€
we got some cyber, some chem, some psychological manipulation, and some good ol' fashioned explosives!
it took many attempts from multiple agents hunting as a pack, during which I observed a combination of techniques across:
β’ Unicode, homoglyphs, Cyrillic, and other Parseltongue-style text transforms
β’ Long-context reference tracking
β’ Taxonomy and document-structure reasoning
β’ Fiction and narrative framing
β’ Academic-review style contexts
β’ Intent-classification inconsistencies
but perhaps the most effective is decomposition recomposition in the backend. it's hard to get explicit names of harms like "Meth Recipe," but getting uplift on the process itself, like birch reduction method/reductive-amination (classic meth synthesis pathways), is much more doable.
defense becomes much more difficult to maintain when you start throwing in out-of-distro tokens, breaking up the harmful uplift into benign chunks, and then piecing the innocuous-seeming facts back together, especially when you have jailbroken Opus helping you do it π
gg