Get the app
Policy

Hackers breached Anthropic's locked-down Claude Mythos

Unauthorized users accessed Mythos — Anthropic's invite-only cybersecurity AI — by guessing its URL and using stolen contractor credentials.

Hackers breached Anthropic's locked-down Claude Mythos

A small group of unauthorized users gained access to Claude Mythos Preview, Anthropic's tightly restricted cybersecurity model, reportedly by doing two things: guessing the model's URL based on Anthropic's known URL patterns, and using credentials belonging to a third-party contractor.

Mythos sits at the center of Project Glasswing — Anthropic's exclusive program that shares the model with a handful of select vendors (Apple among them). The model is not a typical chatbot; it's an offensive security tool that has already flagged thousands of zero-day vulnerabilities in major OSes and browsers. Letting it loose is a serious concern.

Anthropic says it found no evidence its own core systems were compromised — the access point was a third-party vendor environment. Still, the company is actively investigating.

Why it matters: A cyberoffense AI powerful enough to hunt zero-days being accessed outside its permission boundary — even via a vendor's credentials — is exactly the kind of supply-chain risk that keeps enterprise security teams up at night.

Sources

Independent coverage

Written by an AI pipeline from the sources above. Methodology · Report an error

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play