The oldest vulnerability found by Mythos Preview was a 27-year-old bug in OpenBSD.
AI Fact-Check
“On April 7, 2026, Anthropic announced a new, unreleased model called Claude Mythos Preview. As part of the announcement, Anthropic's red team blog and multiple news outlets reported that the model had autonomously discovered thousands of zero-day vulnerabilities. Among the specific examples highlighted were a 27-year-old vulnerability in the OpenBSD operating system and a 16-year-old vulnerability in the FFmpeg video software library. Context: ⚠️ Actual number differs by >10%. Anthropic stated that due to the model's powerful and potentially dangerous cybersecurity capabilities, it would not be made generally available. Instead, it is being provided to a limited group of partners, including major tech companies like Google, Apple, and Microsoft, under a new initiative called Project Glasswing, which aims to secure critical software.”
Source Videos (2)
Related Claims
Mythos autonomously wrote a remote code execution exploit on FreeBSD's NFS server that gained full root access by splitting a chain over 20 packets.
The earlier Mythos preview version developed a moderately sophisticated multi-step exploit to gain broad internet access from a system meant to be restricted.
Project Glasswing discovered a 27-year-old vulnerability in OpenBSD that enables an attacker to crash any OpenBSD server by transmitting a small amount of data.
FFmpeg acknowledged a patch for a vulnerability found by Mythos.
The Mythos AI model is able to find zero-day vulnerabilities almost completely on its own with almost no guidance from a human.