A penetration test at a financial services firm managing billions of dollars in client assets has found a critical flaw in AI-generated code. The interesting part is what the code got right.
Sygnia, the incident response firm, assessed a customer onboarding application built substantially with Claude. It handled government-issued identification, identity verification data, payment details and Social Security numbers.
The flaw let one applicant reach another applicant’s record.
What actually broke
The application solved a real problem. People start an application, leave, and return before they have an account, so the system must restore their progress without a password.








