product updateAnthropic

Anthropic's Claude Mythos cybersecurity model accessed by unauthorized users for two weeks

TL;DR

Anthropic's Claude Mythos Preview, a cybersecurity AI model restricted to select companies including Nvidia, Google, and Microsoft, was accessed by unauthorized users starting April 7, 2025. The group obtained access through a third-party contractor and internet sleuthing techniques, according to Bloomberg.

2 min read
0

Anthropic's Claude Mythos cybersecurity model accessed by unauthorized users for two weeks

Anthropic's Claude Mythos Preview, a restricted AI model designed to identify and exploit security vulnerabilities, has been accessed by unauthorized users for approximately two weeks, according to Bloomberg. The company is investigating the breach, which occurred through a third-party vendor environment.

How the breach occurred

The unauthorized access began on April 7, 2025—the same day Anthropic announced Mythos would be released to a limited number of companies for testing. Members of a private Discord forum obtained access through a combination of tactics, including leveraging a third-party contractor's credentials and using publicly available information.

The group used data from a recent Mercor breach to make "an educated guess" about the model's online location based on knowledge of Anthropic's other model formats. Bloomberg reports that members provided screenshots and a live demonstration of the working model.

About Claude Mythos Preview

Claude Mythos Preview is described by Anthropic as a general-purpose model capable of identifying and exploiting vulnerabilities "in every major operating system and every major web browser when directed by a user to do so." Official access is limited to select companies through the Project Glasswing initiative, including Nvidia, Google, Amazon Web Services, Apple, and Microsoft. Multiple governments are also evaluating the technology.

Anthropic has stated it has no plans to release the model publicly due to concerns about weaponization.

Company response

"We're investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments," an Anthropic spokesperson told Bloomberg. The company claims it currently has no evidence that the breach extends beyond the third-party vendor's environment or is impacting Anthropic's own systems.

According to Bloomberg, the unauthorized users have been using Mythos regularly since gaining access, though reportedly avoiding cybersecurity-related queries to evade detection. The group has also accessed other unreleased Anthropic models.

What this means

This breach highlights the persistent challenge of restricting access to powerful AI models, even when companies implement strict access controls. The incident occurred through a third-party contractor—a common vulnerability in enterprise security—and demonstrates that determined actors can exploit indirect access points to restricted systems. The fact that the group avoided using the model's core cybersecurity capabilities suggests they understood detection risks, but their ability to maintain access for two weeks raises questions about monitoring and access controls at AI companies deploying high-risk models. This incident may influence how Anthropic and other AI labs structure access to sensitive models going forward.

Related Articles

product update

1Password launches Claude integration that injects credentials without exposing passwords to AI

1Password has released a Mac integration that allows Claude to complete browser-based login tasks without accessing user passwords. The system injects approved credentials directly into web pages while keeping secrets out of Claude's context, memory, and Anthropic's systems entirely.

product update

Anthropic launches Reflect dashboard for Claude with usage tracking and break reminders

Anthropic released Reflect, a new dashboard inside Claude's settings that tracks usage patterns and helps users set limits on their chatbot interactions. The tool offers break reminders at 15, 30, or 45-minute intervals and allows users to block access during custom quiet hours on specific days.

changelog

Anthropic reverses course, makes Claude Fable 5 permanent on subscription plans

Anthropic announced July 18 that Claude Fable 5 will remain available on subscription plans, reversing its previous decision to make the model API-only. Max and Team Premium subscribers will receive access at 50% of standard limits starting July 20, while Pro and Team Standard users get a one-time $100 credit.

product update

Adobe Tests AI Photo Editing in Project Indigo App Using Google's Nano Banana Model

Adobe is testing AI-powered photo editing features in its experimental Project Indigo camera app for iPhone. The AI Playground, available to a small percentage of users for a limited time, includes object removal, style transfers, photo critiques, and custom prompt-based editing powered by Google's Nano Banana model.

Comments

Loading...