Canada’s banking regulator OSFI warned major banks and insurers that Anthropic’s Claude Mythos could heighten cyber threats by shrinking the window to detect and fix vulnerabilities, an April email revealed and OSFI later issued a public bulletin; Reuters obtained the information via an access-to-information request.
The Washington Post reports the White House had an export-control directive prepared to crack down on Anthropic’s Claude Mythos well before Claude Fable 5 went offline, after Anthropic expanded Project Glasswing access to about 111 entities (with roughly 50 already granted) including a South Korean telecom linked to China. An Amazon tip from Andy Jassy about jailbreak capabilities appears to have pushed policymakers toward action, and Anthropic later revoked access to the sensitive organization, contributing to Fable 5’s shutdown and underscoring a tense clash between frontier AI access and export controls.
Anthropic released Fable 5, the public, safety-focused version of Claude Mythos, for broad use with safeguards, while Mythos 5 remains gated for select organizations via Project Glasswing due to cybersecurity concerns; sensitive queries go to the lower-tier Opus 4.8. About 200 organizations in 15+ countries have access, with extensive red-teaming and bug-bounty work, and collaboration with the U.S. government on testing. The model carries a price of $10 per million input tokens and $50 per million output tokens, and compute capacity includes SpaceX/xAI arrangements.
Anthropic is expanding access to Claude Mythos via Project Glasswing, inviting about 150 more organizations—from utilities to healthcare—to test the frontier model that can identify software vulnerabilities. Access requires stringent security vetting, and the company says Mythos won’t be widely released until highly robust safeguards are in place.
Anthropic’s Project Glasswing, using Claude Mythos Preview, has identified more than 10,000 high- or critical-severity software vulnerabilities since launch, including 6,202 affecting over 1,000 open-source projects; 1,726 confirmed true positives and 1,094 high/critical. The effort has yielded 97 upstream patches and 88 advisories, with examples like WolfSSL CVE-2026-5194 (CVSS 9.1). The work underscores the gap between discovery and remediation, while defenders credit the tool for preventing fraud (a partner bank blocked a $1.5M wire transfer). Anthropic also launched a Cyber Verification Program for legitimate testing; public, unrestricted access to Mythos-like models remains unlikely amid safeguards. The episode amplifies calls to shorten patch cycles and harden defenses across software supply chains.
Prediction-market traders now rate OpenAI as the likely first AI company to IPO, about 83% odds after reports it may confidentially file soon, beating Anthropic. Investors weigh OpenAI’s spending and leadership questions against Anthropic’s rapid enterprise growth and updates to Claude Mythos, with a fast debut potentially setting valuations and shifting sentiment.
OpenAI has launched Daybreak, a cybersecurity initiative that embeds defense into software from the start, using GPT-5.5 and Codex Security to triage, patch, and validate vulnerabilities with audit-ready evidence; aimed at rivaling Anthropic's Claude Mythos, it teams with partners like Cloudflare, Cisco, CloudStrike, Palo Alto Networks, Oracle and Akamai, and builds on Mythos' earlier patching success.
Anthropic’s Claude Mythos, pitched as a security milestone, was accessed by a small group of unauthorized users from day one, in what Bloomberg describes as an embarrassingly unsophisticated breach that leveraged insider knowledge and data exposed in the Mercor breach. Anthropic says it’s investigating and could have logged or stopped unauthorized use, but experts note that educated guessing is a common tactic in hacking and that the company should have monitored access more closely. The episode has been described as a humiliation for Anthropic, undermining its safety-first branding and highlighting broader risks around supply-chain security and the handling of powerful AI models.
Anthropic says it is investigating reports of unauthorized access to its Claude Mythos cybersecurity model, allegedly gained via a third-party vendor portal and online sleuthing; the group reportedly targeted testing rather than malicious use, and Mythos Preview was limited to trusted partners and praised for identifying vulnerabilities, prompting ongoing debate about AI-enabled cyber threats as DoD risk designations and demand from banks and government agencies persist.
Anthropic is investigating a Bloomberg-reported claim that a small group gained unauthorised access to its Claude Mythos AI via a third-party vendor environment; Anthropic says there’s no evidence its systems were compromised and the access likely stems from misused permissions rather than a hack, highlighting the ongoing challenge of controlling access to frontier AI tools as UK officials urge robust cyber security practices.
Mozilla says Claude Mythos helped identify and patch 271 Firefox vulnerabilities, but the model didn’t find bugs beyond what human researchers would, and the feature can be turned off by users.
Anthropic says an unknown group accessed Claude Mythos—an unreleased, highly restricted model—via a third‑party vendor environment. Bloomberg reports, citing a live demo and screenshots, that the group used data from a Mercor breach and other intel to pinpoint Mythos and has been experimenting with it since April 7. The group claims no malicious intent, but Anthropic is investigating the breach and the security hole remains a concern.
OpenMythos is an open-source PyTorch reconstruction of Claude Mythos proposing a Recurrent-Depth Transformer (RDT) that uses a fixed set of weights looped up to 16 times, with a Mixture-of-Experts FFN and Multi-Latent Attention to enable deep reasoning with far fewer parameters. The design re-injects input at each loop, employs stability techniques like Linear Time-Invariant constraints and Adaptive Computation Time, and adds depth-wise LoRA adapters to differentiate loop steps. The project argues that 770M parameters can match a 1.3B transformer when trained on identical data, reframing depth as inference-time computation rather than parameter count. It releases four artifacts: a configurable PyTorch implementation, LTI stability primitives, depth-wise LoRA adapters, and a reproducible loop-dynamics baseline.
Federal agencies and lawmakers are quietly pursuing access to Anthropic's Claude Mythos despite Trump's ban, with the Commerce Department's CAISI testing its hacking capabilities and congressional briefings planned to assess its cyber-scanning power, underscoring a tension between cybersecurity ambitions and political restrictions as officials weigh Mythos' national-security implications.
UK regulators and the Bank of England are holding urgent discussions with the National Cyber Security Centre after Anthropic’s Claude Mythos Preview allegedly demonstrated the ability to identify and exploit zero-day vulnerabilities, triggering fears of AI-driven cybersecurity risks and prompting resilience-planning in the UK’s financial sector.