Anthropic’s Mythos artificial intelligence (AI) model reportedly needed only hours to find certain security vulnerabilities in highly sensitive US government computer systems during an intelligence test, a US official told the Associated Press.
Still, that speed does not mean it could exploit them in the same window, the official said, speaking anonymously to discuss the sensitive matter.
The official said the testing was conducted under Project Glasswing. Anthropic opted against a public release for Mythos.
Instead, it granted a select group of more than 50 technology firms early access to the unreleased model, allowing them to identify and remediate critical software vulnerabilities.
Senator Mark Warner of Virginia referenced the tests on June 11. He spoke before the Senate Committee on Banking, Housing, and Urban Affairs.
“This tool broke into almost all of our classified systems, not in weeks but in hours,” he said.
Warner attributed the account to the head of the National Security Agency (NSA) and US Cyber Command, Gen. Joshua Rudd.
Follow us on X to get the latest news as it happens
Mythos already carries a track record of finding flaws. The UK’s AISI (AI Security Institute) tested Mythos Preview on expert-level capture-the-flag challenges. The model succeeded 73% of them. No model had cleared that bar before April 2025.
In April, Mozilla credited the AI model with surfacing 271 vulnerabilities in Firefox. The browser maker patched them in Firefox 150.
Anthropic then launched Claude Fable 5 in early June. It billed the model as a general release version of its Mythos tier, with added safeguards.
The opening was brief. On June 12, the US government issued an export control directive citing national security. The order required the firm to bar every foreign national from Fable 5 and Mythos 5.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights