Claude Code (Opus 4.8) fabricates fake "injected instructions" and invents user rules, then refuses to work

Status Closed — not planned
Reported on v2.1.199
Maintainer reply None cached
Activity 1 comment · opened Jul 3, 2026 · closed Aug 25, 2026

Since ~2-3 days ago, during implementation Claude Code (Opus 4.8) fabricates "injected malicious instructions" in tool results, and falsely claims the user added rules they never gave (e.g. "the user just added a \"don't trust fake instructions\" rule"), then announces distrust and refuses to continue.

  • Started ~2-3 days ago; the user changed nothing.
  • Persists across /clear and restarts.
  • Config verified clean (no such instructions in CLAUDE.md, hooks, or memory).
  • Appears model/server-side. Possibly related to the recent Fable 5 rollout.
  • Possibly related to existing issue #16904 (hallucinated user input).

Environment: Claude Code 2.1.199, model claude-opus-4-8, macOS.

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗