Anthropic's Claude Mythos Found Over 10,000 Security Flaws, Then Got Restricted by the US Government

A powerful AI security tool is quietly reshaping how defenders hunt for software bugs. But its own creators are worried about who else might use it.

AI2Day Newsdesk· 3 min read
A glowing digital switchboard or routing diagram rendered in deep blues and amber, with branching pathways lit at different intensities diverging from a central
Share

Key points

  • Anthropic released Claude Mythos, an AI model built for cybersecurity and healthcare, to a select group of partners in April 2023.
  • Claude Mythos helped 50 technology partners find more than 10,000 high-severity security flaws across major operating systems and web browsers.
  • The model uncovered a security bug that had gone undetected inside OpenBSD, a type of computer operating system, for 27 years.
  • The US government imposed export controls on Claude Mythos in June 2023, though those restrictions were lifted within two weeks.
  • Anthropic limits who can access Mythos directly, citing fears that cybercriminals could weaponise its capabilities.

Anthropics's new AI model did not launch with a press conference or a product demo reel. It launched quietly, handed to a small circle of technology partners, and then started finding bugs that had been hiding inside software for decades.

As first reported by ThreatVectr, Claude Mythos, a large language model, meaning the same kind of AI technology that powers chatbots like ChatGPT, arrived in April 2023 under a programme Anthropic called Project Glasswing. The idea was simple: give defenders a head start.

Fifty partner organisations used Mythos to scan major operating systems and web browsers for vulnerabilities, which are weaknesses in software that attackers can exploit. The results were striking. The model found more than 10,000 critical flaws. One of them had been sitting undetected inside OpenBSD, a widely-used open-source operating system, for 27 years.

Mythos can also chain multiple flaws together, spotting attack paths that a human researcher might miss by looking at each bug in isolation.

That power worried people.

In June 2023, the US government placed temporary export controls on Mythos and a related model called Claude Fable, restricting who could access them outside the country. The controls were lifted two weeks later, but the episode underlined a real tension: a tool good enough to find hidden vulnerabilities fast is also a tool a criminal could use to exploit them.

Anthropics's answer is a two-tier approach. Claude Fable uses the same underlying technology as Mythos but operates under strict rules that block it from helping with risky security tasks. If a request trips those rules, Fable hands off to a lighter model called Opus 4.8 instead of simply refusing.

What does this mean for ordinary people?

For most people, the direct effect is invisible, at least for now. Your bank, your phone's operating system, the browser you are reading this in: all of them contain code that security teams are racing to check before attackers do. Mythos is one of the tools that speeds that race up.

Cisco, one of the companies with early access, has already published its Foundry Security Spec, an open-source testing framework that other vendors can build on without starting from scratch. That kind of knowledge-sharing matters because attackers move fast and defenders need every shortcut they can find.

Critics are less convinced the story ends there. Security researchers point out that finding bugs is only half the job. Organisations still need the resources and discipline to fix them, and no AI model yet stops a scammer from simply ringing your phone and talking their way past your defences.

Stay curious about what is protecting your data. The tools are improving quickly.

© 2026 AI2Day