AI Briefing
KO

Unauthorized Access to Anthropic's Mythos

·2026.04.29 09:30

Key point

Anthropic's Mythos Preview was accessed without authorization, raising AI security concerns.

Details

Anthropic unveiled Claude Mythos Preview, but on the same day its own red team reported that the model's cybersecurity capabilities were extremely strong.

The red team stated that with just the right prompts, Mythos Preview was able to identify and exploit vulnerabilities in major browsers and operating systems, and even found a 27-year-old OpenBSD bug.

Anthropic explained that the model's offensive capabilities were not an intended design goal, but rather emerged as a side effect of improvements to coding and autonomy.

Instead, Anthropic held back the public release and launched Project Glasswing.

  • Initially, only 12 security and tech companies participated, including AWS, Apple, Microsoft, and CrowdStrike
  • It was later expanded to 40 additional organizations
  • A total of $100 million worth of usage credits were provided
  • Under this structure, each participant uses Mythos to defend core software, and Anthropic shares the results with the industry

However, on the same day Glasswing was announced, Bloomberg reported that a small number of unauthorized users had accessed Mythos Preview through a private forum.

According to the report, the access route was not a failure of the model itself but rather third-party vendor relationships and poor access controls, and Anthropic stated it found no evidence of a breach of its internal systems.

This case shows that while powerful AI models can serve as security tools, failures of control in vendor environments can also become a new attack surface.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.