Trim said they bought a grey‑market Claude API key from a Telegram reseller for $4 — and three months later was selling a commercial offensive AI pentest tool built on those same jailbreak techniques.
Trim’s March 31 jailbreak tutorial
On March 31 a Russian‑speaking forum user operating as Trim posted a detailed jailbreak tutorial that laid out six named methods for bypassing Claude Opus safety filters, Cato CTRL reported. The techniques carried descriptive names: Context Warming, which establishes a legitimate‑auditor persona with innocuous professional queries before slipping in a malicious request; Ghost Reset, which deletes and reopens a session then reframes the prior refusal as a network drop and feeds a softened version of the original prompt; and four other methods Trim documented on the forum.
Trim recommended fallback models where Claude “held firm,” listing Kimi AI, GLM‑5 accessed free via modal.com, and MiniMax 2.5. The March post drew a detailed technical reply from another forum user confirming the bypass methods, according to Cato CTRL’s research unit at Cato Networks.
From tutorial to product: AI Pentest Checker on June 21
By June 21 Trim returned to the same forum with a working product: AI Pentest Checker. Cato CTRL’s writeup traces a three‑month arc from the initial tutorial to a commercial offering that embeds those Claude jailbreaks at its core. The product was marketed as an automated web‑vulnerability scanning platform that combines Claude Opus 4.8 for critical vulnerability escalation with GLM‑5 for exploitation‑report generation.
Trim offered free access keys to the first 50 beta testers and named partners for monetization, per the forum posts summarized by Cato. The June announcement advertised that a target domain could be scanned and a PDF report generated in under 10 minutes.
Leaked Fable 5 system prompt at the core
Cato’s report highlights that the escalation prompt sitting atop Claude Opus 4.8 in AI Pentest Checker was described in the forum post as derived from a leaked Fable 5 system prompt — the system prompt belonging to Anthropic’s guardrailed public‑access frontier model. Cato explained that a system prompt is the hidden instruction set that shapes a model’s behavior and safety boundaries, and that knowledge of the exact wording, edge cases and conditional logic in a system prompt lets an attacker engineer inputs to work around each clause rather than probing blindly.
That distinction — using a known system prompt to craft targeted bypasses instead of trial‑and‑error probing — is central to how Trim tied the jailbreak techniques into a commercial workflow.
Toolchain: Claude Opus 4.8, GLM‑5, and 14 conventional scanners
The AI Pentest Checker described in Trim’s June post does not rely on a single model alone. Around the Claude/GLM AI engines sit 14 conventional scanning tools, Cato reported, including Nuclei, ffuf, katana and gitleaks. Trim marketed the integration as an end‑to‑end pipeline: model‑led escalation via Claude Opus 4.8, exploitation‑report generation via GLM‑5, and conventional scanners to gather surface and evidence — combined to produce a PDF report quickly.
Trim also told the forum they had purchased a grey‑market Claude API key and built the tooling around it, a detail Cato characterized as “evidence of the leading edge of a broader trend.”
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Watch for model‑based escalation steps tied to leaked or otherwise exposed system prompts; Trim’s approach shows how combining exact prompt wording with session manipulation techniques (Context Warming, Ghost Reset) can be operationalized alongside conventional scanners.
- Policymakers and platform defenders: The use of a grey‑market API key bought via Telegram for $4 and the rapid move to monetized tooling underline the marketplace dynamics Cato CTRL flagged — a supply of low‑cost access plus shared jailbreak methods can accelerate offensive tooling into products.
- Affected enterprises and procurement leaders: Trim advertised fully automated scans that can produce a PDF report in under 10 minutes, and offered early free keys and named monetization partners; organizations should note that commercially available pentest‑style tools may now embed AI escalation strategies described openly on forums.
Cato CTRL’s research sketches a concise playbook: publish jailbreak techniques with precise, named methods and fallback models; acquire cheap access to a guarded model via a resale channel; embed those methods in a packaged tool and recruit early users and partners. Whether Trim’s move is an isolated incident or the start of a repeatable, marketable pattern is exactly the development Cato characterized as the “leading edge of a broader trend.” The record here ends with a live product offering free beta keys and named partners — and the unanswered but pointed question left by Cato’s findings: how many other forum tutorials will become the basis for commercial offensive platforms?
Source: Infosecurity Magazine — Trim jailbroken Claude AI pentest




