Users on a Discord chat are playing with Mythos, an AI deemed too dangerous for the public
AI developer Anthropic deemed its new model too dangerous to release to the public. Now, however, it seems its secrets may already be in the hands of unauthorized third parties.
Dubbed “Mythos,” the artificial intelligence platform was trained to find vulnerabilities in IT networks that no one else could detect, in an effort to improve cybersecurity. Anthropic released the platform to a handful of companies for exactly that purpose, including the nonprofit Mozilla, the maker of the Firefox web browser.
In a blog post, Mozilla said it was able to find 271 bugs with the help of Mythos, which was able to find potential backdoors through Firefox’s security at a rate that surpasses any other tool.
For comparison, previous scans using an older Anthropic model, Opus, only revealed 22 potential vulnerabilities in an earlier Firefox build.
Mozilla said it’s struggling to keep up with Mythos, as its engineers look to plug holes as soon as they’re revealed.
“As these capabilities reach the hands of more defenders, many other teams are now experiencing the same vertigo we did when the findings first came into focus,” the organization wrote. “For a hardened target, just one such bug would have been red alert in 2025, and so many at once makes you stop to wonder whether it’s even possible to keep up.”
That fear is related to why Anthropic felt the AI was too dangerous to release. If it can find these vulnerabilities, the company reasoned, then hackers can use the tool to find them too, releasing a deluge of ransomware attacks and conducting data breaches in ways the world has never seen before.
In theory, no institutions would be safe—from governments to hospitals—if Mythos was turned into a weapon. Now that fear may soon be realized, if media reports are to be believed.
Unauthorized users gather on chat app
Earlier this week, Bloomberg was the first to report that a group using Discord, a popular chat program often associated with video games, was openly using Mythos, having gained access because a member of the group is a contractor working for Anthropic.
While there is no sign of foul play or intentions to perform cyberattacks, the existence of such a group is a wake-up call—once released in any form, new technologies have a way of getting out.
The users had reportedly been using the program since its release, and still had access at the time Bloomberg wrote its report on April 21.
Anthropic said in a response that it’s “investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments.”
Whether or not this means that the secrets of Mythos are already out of the bag and onto the web for the bad guys to find, that’s still unknown.
As for how cybersecurity groups will respond and develop defenses for critical institutions, that too is a developing piece of the puzzle.
