product updateAnthropic

Anthropic's Mythos bug-hunting model accessed by unauthorized users, early tests show performance on par with human rese

TL;DR

Anthropic confirmed unauthorized users accessed its Mythos vulnerability detection model through a third-party vendor environment by guessing URL patterns. Early analysis from Mozilla and AWS indicates Mythos performs on par with elite human security researchers rather than surpassing them, despite Anthropic's claims of identifying thousands of critical vulnerabilities.

3 min read
0

Unauthorized Access Through Third-Party Vendor

Anthropic confirmed on April 22, 2026 that unauthorized users accessed its Mythos vulnerability detection model through a third-party vendor environment, not through Anthropic's production API. The company is investigating the incident but stated no evidence indicates unauthorized activity extended beyond the vendor's environment or affected Anthropic systems.

According to Bloomberg, a handful of users gained access by making "an educated guess about the model's online location" based on Anthropic's previous model URL patterns. The access method was reportedly revealed in the recent Mercor data breach. Mercor, an AI staffing startup that supplies specialized contractors to major AI labs including Anthropic, was affected by the LiteLLM supply-chain attack earlier in April.

The unauthorized users reportedly belong to a private Discord channel and gained access on the same day Anthropic announced Project Glasswing, the limited preview program for Mythos.

Model Performance Below Marketing Claims

Anthropic released Mythos under the Project Glasswing preview program to select organizations, positioning it as a model so capable at finding vulnerabilities that public release posed security risks. Early testing results from preview partners tell a different story.

Mozilla CTO Bobby Holley reported that Mythos found 271 vulnerabilities in Firefox 150. "So far we've found no category or complexity of vulnerability that humans can find that this model can't," Holley said. "We also haven't seen any bugs that couldn't have been found by an elite human researcher."

Anthropic claimed Mythos identified "thousands of additional high- and critical-severity vulnerabilities." According to VulnCheck researcher Patrick Garrity, the actual count as of mid-April stood at approximately 40 confirmed vulnerabilities, with questions remaining about whether some discoveries represent genuine novel findings.

Both AWS and Mozilla reported that while Mythos demonstrates speed advantages and requires less hands-on guidance from security engineers compared to traditional tools, its capabilities align with elite human security researchers rather than exceeding them.

Supply Chain Security Concerns

The unauthorized access incident highlights vulnerabilities in AI model deployment and controlled release strategies. "The Mythos breach didn't require a sophisticated attack," said Ram Varadarajan, CEO at Acalvio. "It just required a contractor, a URL pattern, and a day-one guess, which means the 'controlled release' model failed at its weakest link before the model's capabilities were ever the issue."

Tim Mackey, head of risk strategy at Black Duck, noted that "Anthropic's marketing message for Mythos was effectively a challenge, not dissimilar to a capture-the-flag exercise, where success includes claims of unauthorized access to Mythos."

Anthropic declined to name the affected third-party vendor, stating only that it's a company involved in model development work.

What This Means

Mythos appears to be a productivity tool for security teams rather than the "zero-day machine" Anthropic's marketing suggested. The gap between claimed capabilities and observed performance raises questions about AI model marketing practices and controlled release strategies. The unauthorized access through URL pattern guessing demonstrates that supply chain security and basic access controls remain critical vulnerabilities, regardless of model capabilities. Organizations evaluating Mythos should expect performance equivalent to adding a skilled automated security researcher to their team, not superhuman vulnerability detection.

Related Articles

product update

1Password launches Claude integration that injects credentials without exposing passwords to AI

1Password has released a Mac integration that allows Claude to complete browser-based login tasks without accessing user passwords. The system injects approved credentials directly into web pages while keeping secrets out of Claude's context, memory, and Anthropic's systems entirely.

product update

Anthropic launches Reflect dashboard for Claude with usage tracking and break reminders

Anthropic released Reflect, a new dashboard inside Claude's settings that tracks usage patterns and helps users set limits on their chatbot interactions. The tool offers break reminders at 15, 30, or 45-minute intervals and allows users to block access during custom quiet hours on specific days.

changelog

Anthropic reverses course, makes Claude Fable 5 permanent on subscription plans

Anthropic announced July 18 that Claude Fable 5 will remain available on subscription plans, reversing its previous decision to make the model API-only. Max and Team Premium subscribers will receive access at 50% of standard limits starting July 20, while Pro and Team Standard users get a one-time $100 credit.

product update

AWS launches Managed Knowledge Base for Bedrock with 6 enterprise connectors and automatic ACL enforcement

Amazon Web Services launched Managed Knowledge Base for Bedrock in general availability, offering a fully managed retrieval solution with six native enterprise connectors including SharePoint, Confluence, and Google Drive. The service handles document parsing up to 500 MB for PDFs, 2 GB for audio, and 10 GB for video, with real-time access control list verification at query time.

Comments

Loading...