Anthropic announced Claude Mythos, a frontier model capable of autonomously discovering exploitable software vulnerabilities at unprecedented scale, and refused to release it publicly after being alarmed by its own creation. Initial testing surfaced thousands of zero-day flaws hiding for decades in every major operating system and browser, including a 27-year-old OpenBSD bug, a 16-year-old FFmpeg flaw, and CVE-2026-4747, a 17-year-old FreeBSD NFS remote root-access exploit. Access was instead granted to twelve partner organizations — Apple, Google, Microsoft, JPMorgan, and Nvidia among them — and the U.S. government was briefed separately. The Federal Reserve, Treasury, and CEOs of every major U.S. bank convened in closed-door meetings to assess the systemic risk, as the time between vulnerability discovery and weaponization collapses from days to hours.

Relevant URL: https://red.anthropic.com/2026/mythos-preview/