Cybersecurity now looks like proof of work
Key point
Prompted by the Mythos analysis, security has become a token-consumption race.
Details
Anthropic's Mythos shows extremely strong performance on computer security tasks, and instead of being released publicly, it was made available in a limited way to a few important software makers.
AISI's 3rd-party evaluation largely backed up Anthropic's claims. Notably, in The Last Ones, a 32-stage enterprise network attack simulation, Mythos completed the task 3 out of 10 times. This task is estimated to take about 20 hours for a human.
The core interpretation is simple: strengthening security requires spending more tokens and cost than attackers spend finding exploits. AISI allocated 100 million tokens per attempt, and a single Mythos attempt cost roughly $12,500. All 10 attempts together cost $125,000.
What's more concerning is that within the 100 million token range, no model showed a clear diminishing returns pattern. In other words, there's still room to find more if more budget is put in.
This piece suggests three implications.
- The importance of open source software grows even more. Widely used OSS is valuable to attackers too, but at the same time it can be hardened further through large-scale defensive investment.
- The agentic coder workflow is likely to gain an added hardening step.
- The standard pipeline going forward may solidify into three stages: development → review → hardening.
For that last stage in particular, budget becomes a more direct constraint than human decision-making. Code itself remains cheap, but the moment security is required, the cost structure changes completely.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.