Unauthorised users accessed Claude Mythos, Anthropic investigates
Company Updates

Unauthorised users accessed Claude Mythos, Anthropic investigates

storyboard18.com1d ago

Anthropic's decision to tightly restrict access to its newly announced Mythos AI model has come under scrutiny after reports that unauthorised users were able to interact with the system almost immediately after its launch.

According to a Bloomberg News report, a small group operating within a private online forum accessed the model on the same day it was introduced for limited testing. The model, which is not publicly available due to concerns around its potential misuse in cybersecurity, was meant to be deployed only to a select group of approved organisations.

Access through third-party environment

The report indicated that the breach was linked to a third-party contractor environment rather than Anthropic's core systems. Users in a private Discord group are said to have combined multiple methods to gain entry, including the use of tools typically associated with cybersecurity research.

They reportedly identified the likely hosting location of the model by analysing patterns from earlier Anthropic systems, along with clues drawn from publicly available information and past incidents involving related platforms. The group is also known to track unreleased AI models and scan platforms like GitHub for indicators.

The users have continued to access and interact with the Mythos model since gaining entry, the report said. However, their activity has not been focused on cybersecurity use cases, despite the model being designed specifically for defensive applications.

Anthropic's response

An Anthropic spokesperson said the company is examining the situation.

"We're investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments," the spokesperson said.

The company added that it has not found any evidence to suggest the access extended beyond the third-party environment or affected its internal systems.

Why Mythos is tightly controlled

Anthropic introduced Mythos on April 7 under "Project Glasswing," a controlled programme aimed at allowing select organisations to test the model for defensive cybersecurity purposes.

During testing, the model reportedly identified thousands of critical vulnerabilities, including zero-day flaws that would typically take human researchers months to uncover. Experts told Business Insider that the system can significantly reduce the time required to develop exploits, highlighting both its capabilities and associated risks.

The company has limited access due to concerns that such capabilities could destabilise the cybersecurity landscape if misused. It has opted for a restricted rollout instead of a public release.

Limited access, growing interest

A small number of companies, including Amazon, Apple and Cisco Systems, have been allowed to test the model. It is also being made available to select organisations through Amazon's Bedrock platform.

The report added that financial institutions and government agencies are seeking early access to better assess the risks and defensive applications of the technology.

Originally published by storyboard18.com

Read original source →
AnthropicDiscord