
Tech • IA • Crypto
Anthropic’s Mythos 1 AI model is demonstrating unprecedented cyber offense and defense capabilities, raising urgency around safety, patching capacity, and transparency as signs point to an accelerated rollout.
Mythos 1 has identified over 10,000 high or critical vulnerabilities across roughly 50 major technology organizations, including Cloudflare, Mozilla, and OpenBSD. In one case, Cloudflare reported 2,000 vulnerabilities in core systems, with 400 classified as severe, while maintaining a lower false positive rate than top human testers.
The model demonstrated capabilities described as nation-state level cyber offense, including autonomously constructing full exploit chains. It also became the first AI to defeat the UK AI Safety Institute’s dual network challenge end-to-end, signaling a leap in real-world exploit capability.
In a banking deployment, Mythos prevented a $1.5 million wire fraud attempt by detecting anomalies across compromised email accounts and AI-generated voice calls. The system intervened moments before funds were transferred, showcasing defensive applications alongside offensive potential.
Across 1,000+ core open-source projects, Mythos identified 2,319 vulnerabilities, with 1,094 confirmed as high severity after review. A notable case involved WolfSSL, where the model generated attack code enabling certificate forgery, potentially affecting billions of devices if exploited.
The speed of AI discovery has created a bottleneck: developers cannot fix issues fast enough. Of 1,129 reported vulnerabilities, only 75 critical flaws have been patched so far, with human teams averaging two weeks per fix, prompting maintainers to request slower disclosure.
Anthropic launched Claude Security, which not only detects vulnerabilities but generates fixes. Enterprise users have reportedly resolved 2,100+ issues in three weeks, signaling a shift toward AI-driven remediation and competition with platforms like Snyk and Veracode.
Although Anthropic publicly stated Mythos would remain restricted, references to “Mythos 1 Preview” briefly appeared in developer tools, suggesting a faster rollout. This raises questions about whether safety safeguards have been sufficiently addressed.
Reports of a projected $559 million operating profit and revenue growth from $4.8 billion to $10.9 billion in one quarter have been challenged. Critics point to discounted compute deals and possible front-loaded revenue accounting, casting doubt on sustainability.
While developer events emphasized productivity and “magic,” leadership warnings painted a starkly different picture. Anthropic executives cautioned that AI could reach recursive self-improvement by 2028 or sooner, with potentially catastrophic consequences if safeguards lag.
The recruitment of Andrej Karpathy, alongside former Tesla and xAI engineers, underscores intensified competition in frontier AI development and preparation for large-scale deployment.
Mythos 1 represents a major inflection point in AI-driven cybersecurity, combining unprecedented capability with systemic risks that existing infrastructure and governance may not be ready to handle.