An AI agent based on Claude analysed the firmware and update mechanisms of five devices in less than 13 hours, revealing several vulnerabilities.

Cybersecurity researcher Chaz Schlarp detailed, on 23 August 2026, a reverse-engineering experiment involving several connected devices, conducted using an AI agent based on Claude Opus 5. He provided it with the firmware and update tools for five devices on his desk: a webcam, a monitor, a microphone, a video capture card and a Wi-Fi lamp.

He then asked it to examine these elements, particularly their security mechanisms, in order to identify hidden functions, debugging interfaces and attack surfaces, and, where possible, to interact directly with the devices. The AI agent succeeded in manipulating the firmware of all five devices, highlighting particularly weak protection mechanisms. “In total, analysing the five devices represented around 13 hours of work for the agent and 98 messages from me,” Chaz Schlarp said.

The experiment shows that AI could significantly accelerate vulnerability research affecting consumer connected devices. “I would now assume that any peripheral connected to a computer can be infected with malware. Previously, such an operation would have required considerable resources and would have seemed limited to state actors,” the researcher said.

He is now wondering “what an AI-powered computer worm capable of autonomously carrying out reverse-engineering operations could accomplish today.”

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.