In April 2026, Anthropic announced Claude Mythos.
Then they said the public couldn’t have it.
Mythos is the most powerful model in the Claude family. Its capabilities aren’t incremental — they’re generational.
Where Anthropic’s previous model (Opus 4.6) could develop working JavaScript shell exploits 2 times out of hundreds of attempts, Mythos did it 181 times and achieved register control on 29 more.
It found vulnerabilities in every major operating system and every major web browser.
It scored 31 percentage points higher than Opus 4.6 on the USAMO Mathematical Olympiad.
The UK’s AI Safety Institute confirmed significant improvement in multi-step cyber-attack simulations.
And Anthropic said: we’re not releasing this.
Instead, they launched “Project Glasswing” — a restricted access program giving Mythos only to vetted cybersecurity partners, researchers, and tech vendors. Defensive use only. No public API. No playground.
The reaction was split.
Sam Altman called it “fear-based marketing.” He argued it was an excuse to consolidate technology and power. (OpenAI later released GPT-5.4-Cyber to only a few select organizations — the same playbook.)
Security researchers pointed out that Anthropic provided no comparison with existing automated security tools and no false-positive rates. Without independent validation, how do we know Mythos is as good as they claim?
Others asked a harder question: if a model can autonomously develop working exploits against critical infrastructure software, who decides who gets to use it?
Then it got worse.
On the same day Project Glasswing was announced, unauthorized users in a private Discord server guessed the Mythos API endpoint. They reconstructed Anthropic’s naming conventions from data exposed in a prior S3 bucket leak and accessed the model without triggering alarms.
The most restricted AI model in history was compromised on day one.
For those of us in security, this is painfully familiar. The most locked-down systems are often the ones with the most creative adversaries. Security through obscurity doesn’t work — whether it’s a firewall rule or an AI model.
On June 9, Anthropic rolled out a public version of Mythos with guardrails barring cybersecurity use. A nerfed version of the full capability.
Here’s my take as someone who does this for a living:
The instinct to restrict is correct. A model that can autonomously exploit critical infrastructure shouldn’t be available to anyone with an API key.
But the execution was wrong. Restricted access without transparency creates suspicion, not trust. And day-one compromise proves that access controls alone don’t work — you need defense in depth.
The real question isn’t whether Anthropic should have released Mythos. It’s whether the cybersecurity industry is ready for AI that’s better at finding vulnerabilities than we are.
Because that model exists now. And it’s only a matter of time before someone else builds one without the guardrails.