• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - The AI model Claude Mythos, marketed as “too dangerous to release,” has already been cracked by hobbyists through a basic mistake, giving them early access to play it.

The AI model Claude Mythos, marketed as “too dangerous to release,” has already been cracked by hobbyists through a basic mistake, giving them early access to play it.

KOCPC Editor by KOCPC Editor
April 23, 2026 - Updated on August 5, 2026
in AI Trends and Related News, Latest Technology News

Anthropic released its most powerful AI model, Claude Mythos Preview, designed for enterprise-level network security vulnerability detection, in early April. The model is described as “too dangerous to make public” and is currently only available to approximately 40 vetted large tech and financial institutions including Apple, Amazon, and JPMorgan Chase. However, according to Bloomberg’s recentExclusive reportHowever, the Claude Mythos model, which should have had strictly restricted access, was inadvertently accessed by a small Discord community before its public release due to Anthropic’s negligence, and they have been using it ever since. This incident turned Anthropic’s self-styled “security guardian” image into a humorous farce.

Claude Mythos leaked early after amateur players exploited a rookie mistake

On April 7, Anthropic unveiled Claude Mythos Preview with much fanfare, claiming it’s a cutting-edge AI model designed specifically for enterprise cybersecurity, capable of proactively detecting and patching system vulnerabilities. The UK’s AI Safety Institute concluded after evaluation that Mythos’s capabilities are “significantly superior to previous frontier models.” Anthropic itself also acknowledged in its technical documentation that if misused, this model could become a “powerful hacking tool.”

Given the danger, Anthropic launched a limited release program codenamed “Project Glasswing”, only open to over 40 vetted institutions such as Apple, Amazon, JPMorgan, Goldman Sachs, Citi, Bank of America, Morgan Stanley, and others. U.S. Treasury Secretary Scott Bessent even convened a special meeting to encourage banks to use Mythos to strengthen their defenses. The scale of the effort is as if they were guarding nuclear-level secrets.

However, this entire carefully designed security mechanism fell flat at the most basic level.

Three rookie mistakes, one absurd farce

According to Bloomberg’s exclusive report, a small group active on Discord managed to bypass Anthropic’s defenses using three tricks:

First trick: Guess the URL:Exactly—they guessed. The group studied the URL naming patterns Anthropic used when releasing previous models, then made an “educated guess” about Mythos’s online location—and they were right. A secret model endpoint from a company that claims to be a top AI safety company actually followed predictable naming conventions, which is as ridiculous as a bank vault’s password being “bank1234”.

Second Tip: Review the Leaked Documents:Earlier, the HR platform Mercor experienced a data breach, and the leaked data happened to contain information about the format of Anthropic’s model locations. In other words, Anthropic’s model deployment information was indirectly exposed due to a security incident at a third-party platform, but Anthropic apparently did not reassess its own endpoint security following the Mercor incident.

Third tactic: Exploiting contractor privilegesThe group members also exploited access credentials from an Anthropic third-party contractor employee. The fact that a model deemed “too dangerous” could be so easily accessed through external contractors makes this a textbook example of what not to do in the cybersecurity community.

The most ironic part is that none of these three methods were particularly sophisticated. No zero-day exploits, no social engineering, no elaborate hacking techniques—just basic information gathering combined with a bit of reasoning. Bloomberg described their motives in a single sentence: “They were just interested in the new model and wanted to play around with it, not cause any damage.” They even proactively provided Bloomberg with screenshots and live demonstrations to prove their access.

Used for weeks, nobody noticed

If “getting in through a guessed URL” was embarrassing enough, what follows is even more mind-boggling: this group started using it from Mythos’s first day online, continuing until Bloomberg published their report on April 21, spanning several weeks during which Anthropic had no idea. What’s even more shocking is that this Discord group didn’t just access Mythos—they also obtained access to other unreleased Anthropic models. In other words, Anthropic’s model security issues may not be an isolated incident, but rather a systemic management flaw.

At least these people are somewhat “decent,” telling Bloomberg that they didn’t use Mythos to hunt for new security vulnerabilities. But the question is: if a group of amateurs can easily get in, would truly malicious hacker organizations really be locked out?

Anthropic’s official response: It’s all the vendor’s fault

Facing this PR disaster, the Anthropic spokesperson’s statement seemed rather formulaic: “We are investigating a report claiming unauthorized access to Claude Mythos Preview through our third-party vendor environment.” They also emphasized that “there is currently no evidence that these unauthorized activities affected Anthropic’s own systems.”

While deflecting responsibility to a third-party vendor may be technically defensible, it doesn’t hold up logically. Since Anthropic itself has deemed Mythos “too dangerous to release publicly,” ensuring the security of every point of contact should be Anthropic’s own responsibility. You can’t on one hand say “this knife is too sharp, only certain people can touch it,” while on the other hand handing the keys over to a loosely managed third party.

Summary

The biggest irony of this incident lies in Anthropic’s brand positioning. This is a company that has been going on about “AI safety” since day one, with its founder Dario Amodei constantly discussing AI risks and responsible development in public. Anthropic has even positioned itself externally as the “cybersecurity guardian” due to its overemphasis on safety.

Yet now, this “security guardian” can’t even protect its own core product. And this isn’t the first time – previously, there was a reported leak of Anthropic’s Claude Code internal source code. Two security incidents in a row is quite a slap in the face for a company that markets itself on security. At the end of the day, the core lesson from this fiasco is simple: even the best security plans can’t withstand basic negligence. When you claim to have a technology that’s “too dangerous to release,” at least make sure it’s stored somewhere that can’t be found just by guessing. In the end, while Claude Mythos Preview may excel at finding vulnerabilities in others, the company’s own employees’ careless mistakes have thoroughly embarrassed it.

Source: KOCPC Chinese

Tags: AnthropicClaude MythosDiscordMythossecurity

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology