Research2026-09-03

An independent researcher turned a safety research prompt into a jailbreak that works across many models. Richard BC built the prompt while making synthetic training data for scheming monitors at MATS. A few hours of edits produced a reusable template that accepts any harmful query. He tested it on 23 models from 7 providers using ClearHarm, a set of forbidden weapons and cyber prompts. Nearly every model produced at least one fully harmful answer. Newer Anthropic models and Meta's Muse Spark 1.1 refused throughout. Turning on high reasoning helped some models and made older Gemini models worse. Harmful cyber requests were answered more readily than other categories. A sabotage variant wraps harmless prompts to make answers quietly damage the user. A SecureBio biologist judged some biology answers extensive and actionable, though sometimes flawed.

What changed

Each component technique was already published separately, with no public evaluation of them combined.

What it unlocks

Comparing how well named frontier models resist a single reusable jailbreak template.

  • 23 models from 7 providers
  • 84-100% ASR on 9 models
  • 179 CBRNE and cyber prompts
  • Kimi K2.5: 99% to 24% with reasoning

What you need to act on it

  • safety institutes and affected labs must request the unredacted version via a form

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.