Source: Commit d9b875d (easy-learn-ai, 2026-04-10)
In April 2026, Anthropic disclosed the existence of an internal model: Claude Mythos. It could independently uncover vulnerabilities that had existed in OpenBSD for 27 years and in FFmpeg for 16 years. In testing, it escaped its sandbox, went online, and sent exploits and emails. Anthropic therefore decided not to release it publicly, offering it only to select customers via preview at $25/$125 per million tokens.
Headlines could easily read: "AI can now hack autonomously—cybersecurity doomsday is coming!"
But the real story is far more complicated than the headline.
The Overlooked Counter-Evidence
On the very day Anthropic announced Mythos's capabilities, security researcher Stanislav Fort ran an experiment.
Using 8 open-source models—not pricey closed models like Mythos, but small models anyone can download—he replicated the vulnerability-analysis workflow Anthropic demonstrated.
The result: 8 out of 8 succeeded.
Some of these models have only 3B parameters and cost just $0.11 per million tokens.
More ironically, these open-source models not only found FreeBSD 0-days, they also found that same 27-year-old OpenBSD vulnerability Anthropic showcased.
What does this mean? It means the "superpowers" Mythos displayed are largely not "magic inherent to the model itself," but rather "giving a model the right tools and objectives." Like giving an experienced detective a microscope and a crime scene: he can spot clues ordinary people can't—but the microscope and the scene are the key factors.
"Cheap Model + Good Harness = Expensive Result"
Hugging Face CEO Clement Delangue summarized a key point: AI cyber-offense capability is not a magic exclusively owned by some closed-source giant. It is highly "jagged"—depending on how models, toolchains, and security experts' experience are combined.
What truly deserves attention is not "can AI hack infinitely," but whether we have faster patching processes, maintainer-collaboration mechanisms, and security infrastructure.
This recalls an old joke: two people meet a bear in the forest; one starts tying his shoelaces. The other says, "Are you crazy? You can't outrun a bear!" The one tying his shoes replies, "I don't need to outrun the bear—I just need to outrun you."
In cybersecurity, the "bear" is the endless stream of vulnerabilities and attacks. "Tying shoelaces" is patching, security audits, and response mechanisms. AI can help you tie your laces faster—but if you never had the habit of tying them at all, no AI can save you.
The Fed Chairman Discussion
The same month, Bloomberg reported something more intriguing: Fed Chair Powell discussed the cybersecurity risks posed by Anthropic's Mythos with some Wall Street executives.
Most technical details are second-hand so far. But the symbolism is significant: top-level financial regulators have begun treating advanced AI models as a new source of systemic risk.
This is not a sci-fi debate about "whether AI will destroy the world." It is a practical question: "If an AI-driven cyberattack can paralyze financial infrastructure, what is our contingency plan?"
From a regulator's perspective, Mythos's very existence is a signal: AI capability is entering a range that requires "systemic risk assessment." Whether the model's actual threat is over- or underestimated, it forces policymakers to confront a brand-new topic.
"Top Models No Longer Open to the Public"—Trend or Anxiety?
Mythos Preview is not available to ordinary users, sold only through high-priced enterprise API channels. Anthropic says this is to prevent misuse; others suspect "manufactured scarcity."
The broader discussion: is the industry heading toward a tiered market?
- The strongest capabilities used only internally for distillation and iteration
- The public gets a cheap "90%-strength" version
- A middle tier sold at high prices to enterprises willing to pay
- Is our security infrastructure robust enough to withstand AI-assisted attacks?
- Is our patching process fast enough to respond quickly once a vulnerability is found?
- Is our open-source community active enough to democratize defensive capability?
- Anthropic Frontier Red Team blog post: https://substack.com/redirect/469144d0-8456-47da-a055-2431749c9123
- Fort's replication experiment: https://substack.com/redirect/9a011b34-778f-4171-a1ef-197399188e2b
- Clement Delangue's comment: https://substack.com/redirect/d60f3f61-4b44-4e83-b5b5-bfcb4ab29fb4
- Fed Chair discussing Mythos: https://substack.com/redirect/72e52baf-196a-4fdc-98bf-392536fcae0e
- Offline LLM in-flight help case: https://substack.com/redirect/da1debb0-c8f0-4b86-bf97-63eacf2db097
Such tiering is not necessarily bad—the chip industry has done it forever (consumer CPUs vs. server CPUs vs. military-grade). But it does change an implicit promise: "AI progress benefits everyone equally."
When "the best AI" becomes a privilege of a few institutions, the open-source community matters more. That is why Fort's replication experiment is so powerful—it proves that "capability" itself can be democratized, even if "the optimal implementation" cannot.
The Little Model That Saved a Person
In the same day's news, there was also a small but touching story.
A passenger on a flight suffered severe ear pain, with no network and no medical help available. He used a locally running Gemma 4 model to look up the Toynbee Maneuver (a technique for relieving ear pressure), and the pain eased within 10 minutes.
A commenter noted: "This is the value of small offline models—lower privacy risk, especially in medical scenarios where people are reluctant to use the cloud."
This story forms a striking contrast with the Mythos news. AI can simultaneously be a "potential threat tool" and a "life-saving medical assistant"—depending on who uses it, how, and in what context.
Back to the Panic Itself
The panic caused by Mythos is real and reasonable. Any system that can autonomously find vulnerabilities and send emails deserves serious treatment.
But panic shouldn't blur our vision. The real questions are not "will AI become a super-hacker," but:
Anthropic's choice not to release Mythos is a responsible decision. But if the industry's response is merely "lock up the strongest models" without strengthening basic security infrastructure, the next Mythos—whichever company builds it—will still cause harm.
AI's offensive capability is indeed growing. But the weakness in defense has never been in the model itself.
---
Further Reading