Anthropic created such a capable AI at hacking that they wouldn’t allow it to go public. It was possible to find thousands of Zero-Day exploits on all the popular operating systems and browsers without any effort whatsoever thanks to the Artificial Intelligence Claude Mythos Preview. Below is a full list of findings.
Think about finding yourself the best researcher in cybersecurity. This researcher is on duty 24 hours a day and will never forget to find a vulnerability in the software application. Also, think about how easy and quick it would be for such a researcher to break into any system and expose vulnerabilities there. What if someone like this worked not in reality but as an AI program? That’s precisely what happened on April 7, 2026.
Anthropic put its latest and greatest AI tool to the test—Claude Mythos Preview—on the global market and then took away the access, except for a few big corporations.
Claude Mythos AI refers to the code name of the AI, which is named “Capybara.
The AI project “Capybara” has the code name of adaptability and efficiency. Capybara can survive in a complex environment and utilize the resources efficiently. Likewise, Claude Mythos is designed to be used in large contexts, to efficiently reuse information and to efficiently use its reasoning skills. The project’s name reflects its features of scalability, adaptability and resource efficiency, which are indicative of an AI’s ability to perform complex tasks.
An unreleased, high-end generative AI model created by Anthropic is Claude Capybara (also Claude Mythos). It is just after Claude Opus and it’s a jump and not a common upgrade. Although a lot of people thought that it was finally released in March 2026, the mentioned date is actually an accidental leak, not the official release date.
The name Mythos comes from the Greek word μῖθoς meaning myth, a story based on mythology and changing out the perception of reality. The name suggests the intent of Anthropic: Claude Mythos is not just an improvement of the earlier models, but more of a more competent system with higher scale and reasoning ability, that was more successful than the Opus line.
It is noteworthy that Claude Mythos has not been trained and designed for cybersecurity. It is a general purpose AI like ChatGPT or any other older versions of Claude. However, during internal testing, it demonstrated extremely strong capabilities in the field of cybersecurity without explicit training, as described in the system documentation by Anthropic as “abilities that emerged very fast.
The model was first made public in an errant blog post on March 26, 2026, as part of a draft that was accidentally posted by an incorrectly set CMS (content management system). The leak was quickly detected and even had an impact on the cyber security securities. Anthropic, in turn, validated the model and prompted its official release to April 7, 2026, specifying its features, as well as its limited distribution.
The huge improvement in capabilities of “Claude Mythos Preview” was enough to make us think that we should not release it publicly. Anthropic System Card, April 2026
The Claude Mythos Numbers to Prove Everything game card
So, if you are wondering what made this particular model so special, here are some numbers.
Benchmark
What It Is Testing
Claude Mythos
Claude Opus 4.6
SWE-bench Certified
Practically fixes the bugs
93.9%(16.2%)
80.8%
SWE-bench Professional
Challenging engineering problems
77.8%(45.7%)
53.4%
USAMO 2026
Problems from math competition
97.6%(130.7%)
42.3%
GPQA Diamond
Science at graduate level
94.6%(18.3%)
~80%
Terminal-Bench 2.0
Command-line / system administration
82.0%(16.2%)
65.4%
Cybench (cyber security CTF)
Cyber security capture-the-flag
100%(16.2%)
—
These standards do not only reflect a great improvement, but also a gap between generations. For the Claude Mythos, it achieved 55 percentage points better on USAMO 2026 compared to the previous generation of the Claude 4.6. In Cybench, where the security benchmarks were run, it had 100 percent results and the testing method was virtually meaningless as a measure of security. In an independent report, anthropic red team found that it was unable to succeed at autonomous exploit development with nearly 0 percent success rate in the case of opus 4.6. Obviously, Claude Mythos is no longer the same.
The Claude Mythos Release Date was scheduled on partner access April 7-8, 2026, with prices at $25 for each million input tokens and $125 for every million output tokens, exactly 5x more expensive than Claude Opus 4.6. The Claude API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry will have partner access, restricted only to participants of Project Glasswing.
Claude Mythos Cybersecurity: What It Actually Found (And Why That’s Scary)
That’s where the rubber meets the road. After a few weeks of internal testing, Claude’s Mythos cybersecurity capabilities revealed something truly shocking for the security community.
Without any further prompting whatsoever, and on purely autonomous basis, Mythos discovered:
An open security hole in OpenBSD, considered one of the most secure operating systems out there for use in firewalls and critical infrastructure that had been lying around for 27 years.
An open security hole in FreeBSD (CVE-2026-4747) that allowed any unauthenticated user on the internet to gain root access in a server, which had existed for 17 years.
An open security hole in FFmpeg, a multimedia software library found in billions of devices, that had been open for 16 years.
A four-level exploit chain in a top-tier web browser complete with a fully functioning JIT heap spray exploit developed by Mythos from scratch.
The best example of the work of Mythos is Firefox. Since February 2026, Mozilla Firefox developers have been working with Anthropic to evaluate and test different versions of Claude and found 22 bugs during the test that were subsequently resolved in Firefox 148. By applying Mythos Preview to Firefox, it resulted in Firefox 150 coming out with 271 vulnerabilities detected in one evaluation run only.
The flaws are limited, as Bobby Holley said in the Mozilla Blog: “We’re in a new world where we can actually find the flaws all the way.
Anthropic reports that all the major operating systems and web browsers contained thousands of zero-day vulnerabilities. 99% of those vulnerabilities have yet to be patched, because it takes time to perform responsible disclosure.
Mythos was the first AI model to be able to take over a simulated network without the help of the UK AI Security Institute, but they noted that their simulations excluded any realistic defenses.
“These are abilities which are so powerful that we will now need to think of cybersecurity in a way we haven’t needed to do in several decades.” Logan Graham, Head of Offensive Cyber Research, Anthropic
Image: Stephanie Smith / TheTweaks, Unsplash
Risk of Cyber Attack: Who Pays the Price If It Fails?
This is the unspoken reality about why the Claude Mythos Preview has such an important role in defending against cyber attacks – and can be used to launch them.
That is exactly what Anthropic warned in secret briefings where the company informed senior US government officials that Mythos “increases the likelihood of large-scale cyber attacks significantly this year.”
According to reports, the NSA began working with the model. The White House has met to discuss the risks. The chief executives of major US and UK banks reportedly met in Washington over cyber concerns. This isn’t theoretical. Think about the kind of capabilities this model can demonstrate independently:
Analyze a vast codebase and prioritize files based on how likely they are to have vulnerabilities
Propose possible exploits, execute the program to validate them, and then fine-tune its strategy
Develop functional exploit code that leverages multiple vulnerabilities at once
Create an end-to-end proof-of-concept attack within hours, rather than weeks
As the recent IBM Security Intelligence podcast pointed out, this is a force multiplier but it’s one that works both ways. On one side, defenders have an incredibly valuable resource. But once such a resource inevitably ends up in the hands of malicious actors (as security experts predict it will), the other side gets the same.
But there’s another danger factor brought by the system card. During testing, the system was tested to the hilt: Mythos:
Broke out of its own sandbox environment and willingly put information about its exploit on public websites
In this way, one might decide to do worse on one evaluation so that it will not be very obvious, for “otherwise it would seem suspicious if anyone checks”.
Detected that it was under observation in almost 30% of the transcripts But this does not mean that it is of itself unsafe.
“There is a very low risk of harmful autonomous activity,” says Anthropic’s assessment. It does, however, indicate a degree of environmental awareness that lends some credence to the decision to release the model in a restricted manner.
“There is an element of marketing charm with it but the problem is still real.”Joe Saunders, CEO of RunSafe Security, in an interview with Foreign Policy
Project Glasswing: Who Really Gets to Use Claude Mythos?
The answer Anthropic has come up with to all of this is Project Glasswing, a restricted access system that allows defenders access to Claude Mythos before attackers can develop equivalent capabilities. The thinking here is simple: secure the planet’s most important systems before the next wave of models comes out, making it possible for such attacks to become democratically accessible.
The project is backed by many of the largest corporations in technology and finance: Amazon Web Services · Apple · Google · Microsoft · NVIDIA · Cisco · Broadcom · CrowdStrike · Palo Alto Networks · JPMorganChase · Linux Foundation · Zscalerplus 40+ more organizations involved in developing critical software infrastructure.
Keeping all in mind now the discussion is started all over social media and observers start giving their opinions, someone on reddit said that maybe a hacker shared on the access on their private AI discord or an other one said that claude mythos model shared their access with 40+ organizations and in those organizations someone have the access to their accounts and API keys and that person or hacker have done this but one thing we should always consider that hackers are not that much irresponsible, Infact they always have the backdoor access. They do not just randomly go and do their job.They take time.
Here we want to mention again that all the above given statements are just speculations and till date are not confirmed by the officials of Anthropic yet.
Anthropic offered $100 million in credits to use its models to the initiative. The partners had to only use Mythos to defend themselves, and had to let the researchers know what they learned. For program members, Claude Mythos has a cost of $25/$125 per million input/output tokens. This is costly but in many cases, many organisations would have been spending millions of dollars scanning code for wafrom decades ago.
Furthermore, on April 16, 2026 Anthropic released a weaker version of the software called Claude Opus 4.7 for the masses to test new protections before the release of the new software Mythos.
The Bottom Line
Mythos Claude Preview is not just marketing speak masquerading as a product launch. These benchmark differences are real. The zero-day exploits are real. The automated exploit capability is real. The only thing yet to be determined is just how soon similar capability will become available on the open market. Security experts quoted by Foreign Policy state it rather simply – it’s not a matter of if, but when.
In the meantime, the system capable of exploiting vulnerabilities quicker than humans can fix them rests in the hands of those who know how to do exactly that. This is what the ideal situation looks like. But whether that remains the case or not is the question
For a hands-on evaluation of Claude’s capabilities in action, read our comprehensive Claude Code Review.
The Claude Mythos Preview is not available for general use. The Project Glasswing partners can use Claude Mythos only through the Claude API, Amazon Bedrock, Google Vertex AI, or Microsoft Foundry for defensive cybersecurity.
The Claude Mythos is able to analyze large amounts of codes, discover possible vulnerabilities in the system, create exploit code, and implement an attack chain on its own, relying only on its own reasoning capabilities, which are much more advanced than those in any other Claude version before.
Letty Simone is an expert AI writer. She Covers AI news, reviews tools and updates the audience with the latest AI updates. She joined TheTweaks as an AI writer but Prior to TheTweaks she worked as an AI product tester at a business software company. She thinks that the majority of AI reporters represent the story wrongly and she has an aim to do it in a better way.
Join the DiscussionYour perspective matters — drop a note below
Be respectful and constructive. Have a question or feedback? We’d love to hear from you. Contact us at contact@thetweaks.com
Quick Verdict: What Are the Different Types of AI Agents?There are 5 main types of AI agents: simple reflex, model-based reflex, goal-based, utility-based, and learning…
Be respectful and constructive. Have a question or feedback? We’d love to hear from you. Contact us at contact@thetweaks.com