Hackers breached Anthropic's locked-down Claude Mythos
Unauthorized users accessed Mythos — Anthropic's invite-only cybersecurity AI — by guessing its URL and using stolen contractor credentials.

A small group of unauthorized users gained access to Claude Mythos Preview, Anthropic's tightly restricted cybersecurity model, reportedly by doing two things: guessing the model's URL based on Anthropic's known URL patterns, and using credentials belonging to a third-party contractor.
Mythos sits at the center of Project Glasswing — Anthropic's exclusive program that shares the model with a handful of select vendors (Apple among them). The model is not a typical chatbot; it's an offensive security tool that has already flagged thousands of zero-day vulnerabilities in major OSes and browsers. Letting it loose is a serious concern.
Anthropic says it found no evidence its own core systems were compromised — the access point was a third-party vendor environment. Still, the company is actively investigating.
Why it matters: A cyberoffense AI powerful enough to hunt zero-days being accessed outside its permission boundary — even via a vendor's credentials — is exactly the kind of supply-chain risk that keeps enterprise security teams up at night.
Sources
- Unauthorized group gained access to Anthropic's exclusive cyber tool Mythos techcrunch.com
- Anthropic's Mythos Model Is Being Accessed by Unauthorized Users bloomberg.com
Written by an AI pipeline from the sources above. How it works.
Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.