Anthropic's Claude Mythos preview identified thousands of zero-day vulnerabilities in major operating systems and browsers, prompting the Fed chairman and Treasury secretary to convene bank CEOs. The company warns of a six- to 12-month window before adversaries replicate the capability.
See also: Anthropic Mythos pushes White House to consider pre-publications for high-risk AI models

Anthropic has developed an AI model that has identified thousands of zero-day vulnerabilities in every major operating system and web browser. The Federal Reserve chairman and the Treasury secretary have called bank CEOs to discuss it. The company says there is a six- to 12-month window to fix the vulnerabilities before adversaries create models that can do the same thing.
Claude Mythos Preview has not yet been publicly released. In controlled tests, it outperformed all but the most skilled people at finding and exploiting software vulnerabilities, identifying weaknesses that had been undetected for decades, including a 27-year-old bug in OpenBSD and a 17-year-old remote code execution vulnerability in FreeBSD. Anthropic CEO Dario Amodeidescribed the current period as a “moment of danger” and warned of “a huge increase in vulnerabilities, breaches, financial damage caused by ransomware in schools, hospitals, not to mention banks.”
Mozilla released Firefox 150 with fixes for 271 security vulnerabilities found by Mythos in a single scan. The number is impressive not because Firefox is unusually insecure, but because no human team had found them. The vulnerabilities had accumulated over years of development, each of which is a potential entry point for an attacker with the right tools. Mythos found all 271 in a single run.
See also: Anthropic and Wall Street create $1.5 billion pipeline to private capital markets

The model's ability raises a question that the cybersecurity industry has been theorizing for years and now needs to answer practically: what happens when the cost of finding vulnerabilities drops to almost zero? The traditional economics of cybersecurity depend on the asymmetry between attackers, who must find one weakness, and defenders, who must secure them all.
Mythos breaks down the costs on both sides. Defenders can now scan their entire code for vulnerabilities they didn't know existed. Attackers, once they create or obtain equivalent models, can do the same.
Anthropic has opted for a controlled release, which it calls Project Glasswing. About 40 tech companies and institutions have early access to Mythos to enhance their systems. The list does not include most central banks and governments. The asymmetry is intentional: to give defenders a head start before the capability becomes widely available.
The reaction from financial regulators was immediate. Federal Reserve Chairman Jerome Powell and Treasury Secretary Scott Bessent convened a meeting with the CEOs of major US banks to discuss the cyber risks arising from Mythos. The IMF highlighted the cybersecurity threats posed by artificial intelligence to the global banking system.
See also: White House opposes expansion of Anthropic Mythos

The concern is not that Mythos itself will be used to attack banks. It is that the capability Mythos demonstrates, automated vulnerability discovery at superhuman speed, will be replicated by adversaries who are not bound by Anthropic's responsible disclosure practices.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
