Anthropic's Mythos AI Breached via Contractor

SkimNews Take
Lab-side risk classifications don't constrain contractor access, meaning the vendor footprint—not the model tier—defines the actual security perimeter for frontier AI systems.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic's Claude Mythos Preview was illicitly accessed on April 7th — the same day the company announced limited release to select partners — by a small group operating through a private Discord channel focused on unreleased AI models.
- The breach path ran through a third-party contractor for Anthropic, whose access was leveraged alongside "commonly used internet sleuthing tools" and information from a recent Mercor data breach to make "an educated guess" about the model's online location.
- Official Mythos access is restricted to Nvidia, Google, Amazon Web Services, Apple, and Microsoft under the Project Glasswing initiative; the model can identify and exploit vulnerabilities in every major operating system and web browser, which is why Anthropic has no plans for public release.
- The Discord group has had access for roughly two weeks, providing screenshots and a live demonstration to Bloomberg as evidence, but members deliberately avoided cybersecurity use cases to keep the intrusion below Anthropic's detection threshold.
- The same group has also accessed other unreleased Anthropic AI models beyond Mythos, according to Bloomberg.
- Anthropic told Bloomberg it is investigating the unauthorized access through a third-party vendor environment and has no evidence the breach extends beyond the contractor's systems.
Why it matters: A model Anthropic itself considers dangerous enough to withhold from public release sat in an unauthorized Discord channel for two weeks via a contractor — demonstrating that the company's restricted-access model, limited to five major tech partners under Project Glasswing, failed to contain the technology to its intended audience. The group's deliberate avoidance of cybersecurity use cases kept the intrusion from triggering detection, meaning the model has been studied rather than exploited during the breach window.




