The Specialty News
Tech

Chaz Schlarp Unleashes Claude 5 to Hijack Five Desktop Peripherals

Prompted by an annoying monitor popup, one researcher spent 13 hours and 98 prompts turning everyday desk gadgets into a massive hardware security wake-up call.

By Marcus Vance4 min read
Chaz Schlarp Unleashes Claude 5 to Hijack Five Desktop Peripherals
Photo: Linus Mimietz / Unsplash

On August 23, security researcher Chaz Schlarp stared at an ASUS monitor demanding he run a "pixel cleaning" cycle for the hundredth time. Instead of clicking 'yes', he enlisted Anthropic's Claude Opus 5 to tear the firmware apart and kill the popup forever. What started as a quest to fix a minor annoyance ended with Schlarp completely compromising five everyday desk accessories, proving that AI has effectively democratized hardware hacking overnight.

The 13-Hour Hardware Heist

Schlarp didn't use a multi-million-dollar lab to pull this off. He simply fed Claude Opus 5 his devices' firmware, original update utilities, and a set of strict reverse-engineering goals. Over the course of two weeks—spending just 13 hours of AI "churn" and 98 human prompts—Claude acted as a tireless junior security analyst. The AI successfully documented the code, enumerated security vulnerabilities, and wrote custom update tools from scratch.

The results were startling. Schlarp discovered a full, plaintext command shell inside his microphone, which he then accessed directly through a web browser using WebHID. He permanently disabled his webcam's active recording LED by patching a firmware table and fixing the integrity hash. He even found that his WiFi-connected key light permitted unauthenticated memory writes over his local network.

"I have never intentionally run pixel cleaning on this monitor, and I never will, I don't care, and I would like for that overlay to go away forever," Schlarp wrote in his viral blog post. But the implications of his success stretch far beyond a clean screen. He had just demonstrated that everyday peripherals are essentially unprotected mini-computers, ripe for the taking by anyone with internet access and a capable language model.

The Metasploit Moment for Hardware

The Metasploit Moment for Hardware
Photo: Agence Olloweb / Unsplash

We are witnessing the birth of Agentic Reverse Engineering. Just as the Metasploit Framework stripped the "black magic" out of network exploitation in 2003, AI is now dragging hardware security out of the dark ages. The technical barrier to entry has evaporated. In the wake of Schlarp's post, tinkerers are already replicating his success, using models like GLM-5.3 to rewrite Linux drivers for old GPUs and reclaim abandoned tablets.

This is a massive victory for the Right to Repair movement. Consumers are no longer bound by vendor restrictions or forced to trash perfectly good hardware just because the manufacturer stopped releasing software updates. AI is handing ownership back to the buyer, allowing anyone to crack open their devices and tailor them to their exact specifications without waiting for corporate permission.

Operating systems aren't really equipped to work with the user to ensure that a microphone stays a microphone,Chaz Schlarp

But the security threat is severe. "Operating systems aren't really equipped to work with the user to ensure that a microphone stays a microphone," Schlarp warned, noting a compromised mic could easily spoof a keyboard, hitting Win+R and injecting a payload to steal data. Hardware manufacturers can no longer treat desktop accessories as dumb plastic husks; they must rapidly adopt secure boot and strict signature validation for everything they build. The era of the unprotected peripheral is officially over.

The Metasploit Moment for Hardware

A visual summary of this story

More stories

Keep reading

The Brief

Stay curious

Your 5-minute daily summary of the stories that matter.
No noise. Just signal.

Free forever. Unsubscribe anytime.