Mythos, the model that finds bugs on its own, just leaked
Anthropic Locks Away Model Capable of Finding Zero-Day Flaws on Its Own
Anthropic has kept under lock and key a model capable of finding zero-day flaws all by itself. An unauthorized group gained access to it after the program’s announcement, simply by guessing the URL. The day this capability goes from defensive to offensive, it’s no longer a movie scenario.
What’s Happening
Mythos is the name of the model Anthropic deemed too dangerous for public access. Its specialty: discovering zero-day vulnerabilities on major OSes and browsers independently, chaining multiple bugs into full exploits, conducting complex cyber ops with minimal human intervention. In internal tests, Mythos unearthed “thousands” of major vulnerabilities. Bloomberg sums it up: Mythos is far ahead of any other AI model in cyber capabilities.
Access was supposed to be locked down. A limited program called “Project Glasswing” was opened to Apple, Amazon, Microsoft, and Nvidia. Some U.S. government agencies have access, but not CISA. TechCrunch and Bloomberg reported on April 21 that a small group of unauthorized users found the endpoint by guessing the URL based on Anthropic’s usual naming conventions.
One of them works for a third-party subcontractor of Anthropic. The exchanges happen in a private Discord dedicated to tracking unpublished models. Regular access since the day of the announcement. No offensive use detected yet. Anthropic confirms the investigation and sees “no evidence of impact” on its systems.
Why It Matters to You
This is the first time a publicly documented model capable of finding flaws in series has escaped its intended perimeter. For now, the intruders are just keeping watch. But the capability is in hands that shouldn’t have it, with a third-party subcontractor employee in the loop. The history of digital weapons has a constant: they start with state targets and end up on crypto phishing sites targeting individuals. An AI that finds zero-days on its own, that was worth billions five years ago. It just leaked onto a Discord.
Practically, the tech that can secure macOS tomorrow can also produce an exploitable iOS exploit for an actor without an NSA budget. Anthropic finds “thousands” of vulnerabilities internally, so the stock isn’t a problem. CISA, which coordinates cyber response in the U.S., isn’t in the loop. Australia’s regulatory authority is monitoring the situation. Bloomberg even titled a podcast episode about it: “Will Mythos Save or Break the System?”
What You Need to Do
1. Now: Update your Mac, iPhone, and Safari. Mythos targets major OSes and browsers, deployed patches close doors an AI might push. It’s not paranoia, it’s hygiene.
2. Turn on automatic updates: Settings → General → Software Update → check all (download + install + Quick Security Responses). On Mac and iPhone. The next critical patch might drop on a Tuesday at 11 PM, you don’t want to rely on it.
3. Filter invisible vectors on iPhone: Settings → Messages → “Filter Unknown Senders”. Settings → Phone → “Filter Unknown Callers”. That neutralizes doors exploits like Pegasus use to reach a phone: an iMessage or FaceTime call from an unknown number.
4. Be wary of links and attachments: Not just for the next few weeks, but from now on. An “outstanding invoice” email pushing a boobytrapped attachment doesn’t need an expert developer anymore.
5. Keep an eye on: Anthropic’s investigation progress, any potential iOS/macOS CVEs without claimed authors in the next few weeks, CISA’s statements when they break their silence.
Sources
- TechCrunch, April 21, 2026
- Bloomberg, April 21, 2026
- Axios, April 21, 2026
- Bloomberg, Mythos Background, April 16, 2026