PaPoo
cover

Claude Can Port Exploits, But That Doesn’t Mean It’s Ready for the Job

What jumped out at me isn’t that Claude managed the port. It’s that the whole exercise still looks painfully human-gated. Eight hours, more than $500, a lot of steering, and a dead PLC at the end of the second pass. That is not “AI independently finding and weaponizing an OT weakness.” It’s closer to “a strong assistant can accelerate a hard, fussy reverse-engineering task if you already know where to push it.”

That distinction matters. The interesting part of the report is the failure mode, not the success. Once the researchers had enough context and the right model variant, Claude apparently found the sticking point and generated working payloads quickly. That feels believable. These systems are good at grinding through branching possibilities once the problem is framed well enough. But the early drift into wrong leads is exactly what I would expect when firmware details are murky and the model is forced to infer too much. In OT work, that’s expensive. In OT work with live hardware, that’s dangerous.

The bricked-device part is the real gut check. If you’re trying to use an LLM as a hands-on exploit porter against embedded targets, you are not just paying for tokens. You’re paying for collateral damage, wasted time, and a very real chance the model will confidently write to the wrong place and kill your test box. That’s not a small footnote; it’s the operational tax on this whole idea.

I also think the authors are right to focus on the scaling argument. Right now, a skilled researcher can probably do this faster and safer without AI in a case like this. But if the amount of supervision needed keeps dropping, the economics change fast. The model doesn’t have to replace expert exploit developers to matter. It just has to make the second, third, and tenth target cheaper to hit once the first one is understood.

So I’d read this less as “Claude is now an OT exploit machine” and more as “Claude is already useful enough to shave the boring parts off offensive research, and that should make defenders a little uneasy.” Especially in industrial environments, where one bad write can turn a lab exercise into a hardware replacement order.


Reference: Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

同じ著者の記事