Liberty McAteer Authored an Article Titled, "'Mythos' and Urgent AI Cybersecurity Risk."

Share this page:

Last week, Anthropic announced Claude 'Mythos', a frontier AI model that represents a quantum leap in AI cybersecurity. In short, Mythos, Anthropic / Claude's new AI model, has an unprecedented ability to identify, analyze, and exploit software vulnerabilities without human intervention. Anthropic says that Mythos has identified thousands of critical software flaws. Anthropic has therefore initiated 'Project Glasswing' - providing major banks, tech companies and infrastructure providers early access to Mythos to allow them to harden their systems. 

For companies in the finance and technology sectors, the arrival of Mythos is a watershed moment. If Anthropic’s claims about Mythos’s performance are accurate, we are now living in a fundamentally different cybersecurity landscape than we were a few weeks ago. Though Anthropic has stated that Mythos will be very hard to abuse (specifically stating that it is "the best-aligned model that we have released to date by a significant margin" - meaning the hardest to trick into performing unethical acts (link below)), it is said to be astonishingly talented at finding and exploiting software vulnerabilities. The great concern is that after Mythos is made fully public, less scrupulous providers, or even criminal organizations or rogue states, may be able to reverse engineer Mythos, turn off the safety controls and launch mass-scale hacking attacks against US (and global) digital infrastructure. 

The risk posed by Mythos is significant enough that on April 8, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell invited Wall Street executives to a meeting at Treasury headquarters to discuss concerns over Mythos. Meanwhile, OpenAI has initiated a similar program for early access to its own cybersecurity tool, Codex

Organizations should conduct a new level of diligence on their cybersecurity frameworks and protocols, as well as those of their critical vendors. This may include:

  • Tabletop "breach response" exercises
  • Penetration testing, including with the assistance and aid of enhanced-AI toolsets
  • Double checking cyber-insurance policies
  • Confirming that vendors have done the same

Moses Singer can review your user, client and vendor facing agreements to confirm:

  • There are adequate protections for cybersecurity risk
  • You have sufficient ability to examine or audit your vendor's cybersecurity programs
  • Your exposure to your users / clients is reasonably limited, especially in light of these threats
  • Your service level agreements (SLAs), force majeure clauses, and indemnity obligations address this new AI threat

We are continuing to monitor the evolution of the Mythos platform and associated risks. If you have any questions, please contact us. 

Relevant Links: