A Decades-Old Flaw Let Researchers Rewrite DNA Evidence Files Using Claude

A long-standing vulnerability in widely used Thermo Fisher forensic DNA software let researchers add or remove profiles from evidence files, exposing the fragility of digital chain of custody.

Portrait of Declan Moss 8 min read
A gloved hand holding a sealed evidence sample tube under laboratory light
Thirty years of digital DNA evidence rests on file formats that were never designed to resist tampering.

A vulnerability that has existed for decades in DNA analysis equipment made by Thermo Fisher, and used widely in crime laboratories, allowed researchers to add or remove DNA profiles from evidence files, according to reporting by The Verge and the Wall Street Journal on 2 August 2026. The researchers reportedly used Claude, Anthropic's AI model, to help identify and exploit the flaw. Thermo Fisher has issued a patch, and there is no evidence the vulnerability was ever exploited maliciously. The significance of the finding lies less in any single case and more in what it reveals about how much forensic infrastructure has quietly depended on file integrity nobody was actively testing.

What the flaw actually allowed

DNA analysis in modern crime labs runs largely through digital files: genetic profiles generated by sequencing equipment, stored and compared electronically rather than read directly off a physical sample by eye. The vulnerability reportedly let someone with local access to the relevant systems modify those files, inserting a DNA profile that was never present in a sample or deleting one that was, without the kind of alteration being obviously detectable through the software's normal interface.

Why local access is the key caveat, and why it still matters

Exploiting the flaw requires local access to the equipment or the systems handling its output, not a remote internet-based attack. That significantly narrows the realistic threat model: this is not something an outside attacker could do to a random crime lab over the internet. But 'local access' in a forensic context is not a high bar. Lab technicians, contractors, cleaning and maintenance staff, and anyone with physical proximity to the equipment across the roughly thirty years this class of system has been in use represents a large population, and chain-of-custody protocols in forensic science exist precisely because insider access has always been the harder problem to rule out.

Chain of custody was built to answer who touched a physical sample and when. It was never built to answer who touched the file after the sample became data.

Why using Claude to find it is notable

  • The vulnerability had reportedly existed for decades without being identified, suggesting standard security auditing had not been applied to specialised forensic equipment at the same intensity as mainstream enterprise software.
  • AI-assisted vulnerability research lowers the cost of finding this class of flaw, meaning similarly overlooked forensic and medical equipment may harbour comparable issues nobody has looked for yet.
  • Thermo Fisher's equipment is used broadly enough across crime labs that a single flaw touches an unusually large share of stored forensic evidence nationally.
  • The finding arrives amid the same week's broader concerns about AI-assisted security research being used offensively, giving this instance an unusually direct defensive counter-example.

The stakes for the justice system

DNA evidence has been treated in courtrooms for three decades as close to unimpeachable, a status that rests on the assumption that the chain from sample to file to courtroom exhibit is tamper-evident. A flaw that allows silent modification of the file layer, even one requiring local access and even one with no known malicious use, weakens that assumption in every case where the underlying equipment was in use, not just future ones. Defence attorneys in cases involving contested DNA evidence are likely to raise the vulnerability regardless of whether it was ever exploited in their specific case.

What to watch

Watch how quickly crime labs using the affected Thermo Fisher equipment apply the patch, and watch whether defence lawyers begin citing the vulnerability in ongoing cases involving DNA evidence processed on unpatched systems. Longer term, watch whether forensic equipment manufacturers face pressure, regulatory or otherwise, to submit to the kind of independent security auditing that mainstream software vendors have accepted as routine for years.

Share:

Was this helpful?

Portrait of Declan Moss

Security Editor, Lonic

Declan spent a decade in security operations, including four years running incident response for a multinational bank, before writing about the field full time.

  • Cybersecurity
  • Incident response
  • Threat intelligence

Read our editorial standards or send a correction.