Get the app
Policy

Hackers breached Anthropic's locked-down Claude Mythos

Unauthorized users accessed Mythos — Anthropic's invite-only cybersecurity AI — by guessing its URL and using stolen contractor credentials.

Hackers breached Anthropic's locked-down Claude Mythos

A small group of unauthorized users gained access to Claude Mythos Preview, Anthropic's tightly restricted cybersecurity model, reportedly by doing two things: guessing the model's URL based on Anthropic's known URL patterns, and using credentials belonging to a third-party contractor.

Mythos sits at the center of Project Glasswing — Anthropic's exclusive program that shares the model with a handful of select vendors (Apple among them). The model is not a typical chatbot; it's an offensive security tool that has already flagged thousands of zero-day vulnerabilities in major OSes and browsers. Letting it loose is a serious concern.

Anthropic says it found no evidence its own core systems were compromised — the access point was a third-party vendor environment. Still, the company is actively investigating.

Why it matters: A cyberoffense AI powerful enough to hunt zero-days being accessed outside its permission boundary — even via a vendor's credentials — is exactly the kind of supply-chain risk that keeps enterprise security teams up at night.

Sources

Written by an AI pipeline from the sources above. How it works.

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play