Drooid Logo
Back to story perspectives

Full Breakdown

Mozilla Leverages Anthropic’s Mythos AI to Accelerate Firefox Security Fixes

5/8/2026, 12:28:32 PM

AI-Driven Scan of Firefox Code

During April–May 2026, Mozilla paired Anthropic’s Mythos LLM with a custom agent harness to scan Firefox’s code. The system generated 271 vulnerability reports, enabling 423 bug fixes in April—a five-fold increase over March.

Evolution of AI Bug Detection

Earlier AI scanners produced many hallucinated reports that required heavy manual triage. Mozilla credits the improvement to two factors: more capable LLMs and a project-specific harness that gives the model the same build and test pipeline as developers.

Key Personnel and Partnerships

Key contributors are Brian Grinstead (distinguished engineer, Mozilla), tech lead Christian Holler, security head Frederik Braun, Anthropic CEO Dario Amodei, and security consultant Davi Ottenheimer of flyingpenguin. The effort uses Mythos and, for comparison, the earlier Opus 4.6 model.

Quantitative Outcomes

Mozilla logged 271 vulnerabilities in Firefox 150. In April 2026 the team shipped 423 fixes, versus 31 in April 2025 and an average of 21.5 monthly fixes in 2025. Notable findings include a 20-year-old heap use-after-free and several sandbox-escape bugs that fuzzing typically misses.

Official Statements

Mozilla said it normally keeps bug reports private for months but released a sample because of “extraordinary interest and urgency.” The company claims AI reports broaden coverage and validate prior hardening. Anthropic’s leadership said responsible use could shift the advantage “a little bit to defense” and lead to “a better world on the other side of this.”

Criticism and Opposition

Security consultant Davi Ottenheimer of flyingpenguin called the Mythos claim “marketing and no real results,” labeling the step change a “rounding error.” He tested Anthropic’s Sonnet 4.6 and Haiku 4.5 models, finding eight issues in two minutes, only two of which matched Mythos. He suggested the custom harness, not the model, may drive the improvement.

Conflicting Reports & Gaps

Mozilla credits Mythos for the fix surge but does not reveal how many of the 271 bugs are fully patched. Ottenheimer notes that “Mythos found 271 bugs” is a raw output, not an independent measure of missed vulnerabilities. The lack of side-by-side benchmarking leaves the model’s true incremental value unclear.

Verbatim Quotes

  • “zero-days are numbered” — Mozilla CTO
  • “Almost no false positives” — Brian Grinstead, Mozilla
  • “It is difficult to overstate how much this dynamic changed for us over a few short months,” — Mozilla research team
  • “If we handle this right, we could be in a better position than we started, because we fixed all these bugs. There are only so many bugs to find,” — Dario Amodei, Anthropic

What’s Next

Anthropic’s Project Glasswing will grant early access to Mythos for a limited consortium of partners. Mozilla plans to refine the harness, publish more post-mortems, and encourage independent benchmarking. The security community awaits data that can separate model improvements from middleware effects.