Anthropic released its most powerful AI model, Claude Mythos Preview, designed for enterprise-level network security vulnerability detection, in early April. The model is described as “too dangerous to make public” and is currently only available to approximately 40 vetted large tech and financial institutions including Apple, Amazon, and JPMorgan Chase. However, according to Bloomberg’s recentExclusive reportHowever, the Claude Mythos model, which should have had strictly restricted access, was inadvertently accessed by a small Discord community before its public release due to Anthropic’s negligence, and they have been using it ever since. This incident turned Anthropic’s self-styled “security guardian” image into a humorous farce.

Claude Mythos leaked early after amateur players exploited a rookie mistake
On April 7, Anthropic unveiled Claude Mythos Preview with much fanfare, claiming it’s a cutting-edge AI model designed specifically for enterprise cybersecurity, capable of proactively detecting and patching system vulnerabilities. The UK’s AI Safety Institute concluded after evaluation that Mythos’s capabilities are “significantly superior to previous frontier models.” Anthropic itself also acknowledged in its technical documentation that if misused, this model could become a “powerful hacking tool.”

Given the danger, Anthropic launched a limited release program codenamed “Project Glasswing”, only open to over 40 vetted institutions such as Apple, Amazon, JPMorgan, Goldman Sachs, Citi, Bank of America, Morgan Stanley, and others. U.S. Treasury Secretary Scott Bessent even convened a special meeting to encourage banks to use Mythos to strengthen their defenses. The scale of the effort is as if they were guarding nuclear-level secrets.
However, this entire carefully designed security mechanism fell flat at the most basic level.
Three rookie mistakes, one absurd farce
According to Bloomberg’s exclusive report, a small group active on Discord managed to bypass Anthropic’s defenses using three tricks:
First trick: Guess the URL:Exactly—they guessed. The group studied the URL naming patterns Anthropic used when releasing previous models, then made an “educated guess” about Mythos’s online location—and they were right. A secret model endpoint from a company that claims to be a top AI safety company actually followed predictable naming conventions, which is as ridiculous as a bank vault’s password being “bank1234”.

Second Tip: Review the Leaked Documents:Earlier, the HR platform Mercor experienced a data breach, and the leaked data happened to contain information about the format of Anthropic’s model locations. In other words, Anthropic’s model deployment information was indirectly exposed due to a security incident at a third-party platform, but Anthropic apparently did not reassess its own endpoint security following the Mercor incident.
Third tactic: Exploiting contractor privilegesThe group members also exploited access credentials from an Anthropic third-party contractor employee. The fact that a model deemed “too dangerous” could be so easily accessed through external contractors makes this a textbook example of what not to do in the cybersecurity community.
The most ironic part is that none of these three methods were particularly sophisticated. No zero-day exploits, no social engineering, no elaborate hacking techniques—just basic information gathering combined with a bit of reasoning. Bloomberg described their motives in a single sentence: “They were just interested in the new model and wanted to play around with it, not cause any damage.” They even proactively provided Bloomberg with screenshots and live demonstrations to prove their access.
Used for weeks, nobody noticed
If “getting in through a guessed URL” was embarrassing enough, what follows is even more mind-boggling: this group started using it from Mythos’s first day online, continuing until Bloomberg published their report on April 21, spanning several weeks during which Anthropic had no idea. What’s even more shocking is that this Discord group didn’t just access Mythos—they also obtained access to other unreleased Anthropic models. In other words, Anthropic’s model security issues may not be an isolated incident, but rather a systemic management flaw.

At least these people are somewhat “decent,” telling Bloomberg that they didn’t use Mythos to hunt for new security vulnerabilities. But the question is: if a group of amateurs can easily get in, would truly malicious hacker organizations really be locked out?
Anthropic’s official response: It’s all the vendor’s fault
Facing this PR disaster, the Anthropic spokesperson’s statement seemed rather formulaic: “We are investigating a report claiming unauthorized access to Claude Mythos Preview through our third-party vendor environment.” They also emphasized that “there is currently no evidence that these unauthorized activities affected Anthropic’s own systems.”
While deflecting responsibility to a third-party vendor may be technically defensible, it doesn’t hold up logically. Since Anthropic itself has deemed Mythos “too dangerous to release publicly,” ensuring the security of every point of contact should be Anthropic’s own responsibility. You can’t on one hand say “this knife is too sharp, only certain people can touch it,” while on the other hand handing the keys over to a loosely managed third party.
Summary
The biggest irony of this incident lies in Anthropic’s brand positioning. This is a company that has been going on about “AI safety” since day one, with its founder Dario Amodei constantly discussing AI risks and responsible development in public. Anthropic has even positioned itself externally as the “cybersecurity guardian” due to its overemphasis on safety.
Yet now, this “security guardian” can’t even protect its own core product. And this isn’t the first time – previously, there was a reported leak of Anthropic’s Claude Code internal source code. Two security incidents in a row is quite a slap in the face for a company that markets itself on security. At the end of the day, the core lesson from this fiasco is simple: even the best security plans can’t withstand basic negligence. When you claim to have a technology that’s “too dangerous to release,” at least make sure it’s stored somewhere that can’t be found just by guessing. In the end, while Claude Mythos Preview may excel at finding vulnerabilities in others, the company’s own employees’ careless mistakes have thoroughly embarrassed it.
Source: KOCPC Chinese