Skip to content
GOPPO

News · AI summarised to understand what matters

Back to news

Security & Ethics

Published on

Anthropic restricts Mythos after advanced exploit capabilities

According to the newsletter, Anthropic is not publicly releasing Claude Mythos for now after very strong results in exploit generation and vulnerability discovery across critical software.

  • anthropic
  • mythos
  • ciberseguranca
  • vulnerabilidades
  • ai-safety

Summary

According to the Ben's Bites newsletter, Anthropic has decided not to publicly release Claude Mythos for now after the model reportedly showed a major jump in offensive cybersecurity tasks. The piece focuses especially on the model's ability to find and exploit software vulnerabilities at a level far beyond earlier systems.

The report points to large improvements on benchmarks such as SWE-bench Pro and Terminal-Bench 2.0, but the most striking claim concerns exploit generation. The newsletter says that on Firefox exploit generation, an earlier Anthropic model produced two working exploits across hundreds of attempts, while Mythos reached 181. It also mentions the discovery of long-standing bugs in critical projects such as OpenBSD and FFmpeg.

In practice

In practice, this means Anthropic is treating Mythos less like a standard product launch and more like a capability that requires tightly controlled access. Instead of broad public availability, the company is reportedly giving limited preview access to 12 organizations through a program called Project Glasswing.

According to the newsletter, that program includes model usage credits and support for open-source security organizations. The framing is straightforward: Anthropic appears to want the model used to identify real vulnerabilities, while avoiding immediate broad access to a system that could create serious misuse risks.

What we still don't know

Despite the strength of the story, several important details remain unclear. The newsletter does not fully explain what operational restrictions apply to the preview, which guardrails are in place, or under what conditions a broader release might happen later.

It is also not entirely clear how much of the reported performance reflects robust real-world behavior versus particularly strong results in narrower security tasks. Even so, the decision to restrict access is itself a strong signal that the company sees this capability as materially different from more conventional model releases.

Why it matters

  • It shows that some frontier AI capabilities may be considered too sensitive for an immediate public release.
  • It reinforces the idea that offensive security and exploit generation are becoming a central governance issue for advanced models.
  • It puts Anthropic in a rare position: limiting distribution because of concrete technical risk rather than simple product timing.
  • It is a strong public-interest story because it combines technical progress, real risk, and practical limits on openness.