Claude Code (Opus 4.8) fabricates fake "injected instructions" and invents user rules, then refuses to work
Status Closed — not planned
Reported on v2.1.199
Maintainer reply None cached
Activity 1 comment · opened Jul 3, 2026 · closed Aug 25, 2026
Since ~2-3 days ago, during implementation Claude Code (Opus 4.8) fabricates "injected malicious instructions" in tool results, and falsely claims the user added rules they never gave (e.g. "the user just added a \"don't trust fake instructions\" rule"), then announces distrust and refuses to continue.
- Started ~2-3 days ago; the user changed nothing.
- Persists across /clear and restarts.
- Config verified clean (no such instructions in CLAUDE.md, hooks, or memory).
- Appears model/server-side. Possibly related to the recent Fable 5 rollout.
- Possibly related to existing issue #16904 (hallucinated user input).
Environment: Claude Code 2.1.199, model claude-opus-4-8, macOS.
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗