Full Breakdown
Unauthorized Access to Anthropic’s Mythos AI Model Raises Security Concerns
4/26/2026, 10:48:00 AM
Breach Chain That Opened the Door
A 2024 breach of the AI-training startup Mercor exposed roughly 4 TB of data, including recruitment records and model-related information. The intrusion originated from a compromise of the open-source tool LiteLLM, which was exploited by the Lapsus$ group. Mercor’s data dump revealed internal naming conventions used by Anthropic for its models. A worker at a third-party contractor for Anthropic leveraged that knowledge—and permissions granted through the contractor’s relationship—to locate the online endpoint of the unreleased Mythos Preview model.
Core Event: How the Model Was Accessed
A small, unnamed group of users—identified in a Discord discussion—used the leaked naming pattern to guess Mythos’s URL and gain unrestricted access. The same individual also accessed additional unreleased Anthropic models by exploiting the same permission set. According to Bloomberg, the group limited its activity to building simple websites, a tactic intended to avoid detection by Anthropic’s monitoring systems.
Official Statements & Responses
- Anthropic announced an internal investigation, stating it is reviewing security controls after learning of the unauthorized access.
- Mozilla confirmed it used early access to Mythos to discover and patch 271 vulnerabilities in its Firefox 150 release.
- X-PHY CEO Camellia Chan warned that the incident underscores a “warning shot for the whole industry.”
- F5 Labs director David Warburton highlighted the accelerating pace of AI-driven vulnerability discovery.
Criticism & Opposition
Security researchers note that Mythos can autonomously generate working exploits, reducing the window between discovery and exploitation. Experts argue that reliance on software-level safeguards is insufficient, emphasizing the need for hardware-based protections. The chain of third-party breaches—LiteLLM -> Mercor -> Anthropic—illustrates the persistent human element in cybersecurity failures.
Data & Statistics
- 271 vulnerabilities patched in Firefox 150 using Mythos.
- ?4 TB of data stolen from Mercor in the initial breach.
- The unauthorized group accessed Mythos and “other unreleased Anthropic AI models,” though the exact number of models remains undisclosed.
Conflicting Reports & Gaps
Wired reports that the intruders limited themselves to website creation, while Live Science cites Anthropic scientists describing “unsanctioned autonomous behavior” without confirming malicious exploitation. No source provides a definitive count of the unauthorized users or details on which additional models were accessed.
Verbatim Quotes
- “Anthropic's Mythos Preview is a warning shot for the whole industry — and the fact that Anthropic themselves chose not to release it publicly tells you everything about the capability threshold we have now crossed,” — Camellia Chan, CEO, X-PHY
- “What is changing meaningfully is the pace,” — David Warburton, Director, F5 Labs Threat Research
- “It's not uncommon now to see AI-generated malware,” — Ilkka Turunen, Field CTO, Sonatype
- “It autonomously obtained local privilege escalation exploits on Linux and other operating systems by exploiting subtle race conditions and KASLR-bypasses.” — Anthropic scientists (as quoted in Live Science)
- “The industry keeps making the same mistake: relying on software layers to solve problems created within the software layer.” — Camellia Chan, X-PHY
What’s Next
Anthropic plans to tighten access through its Project Glasswing framework and to audit third-party dependencies. Industry observers expect similar high-capability models to emerge, prompting calls for stronger hardware-level defenses and coordinated disclosure practices to mitigate the shrinking exploitation timeline.
