It's pretty clear at this point that Mythos' capability to discover and exploit zero-day vulnerabilities at scale is but an incremental improvement over existing models like the ones available to OpenAI's Plus/Pro subscribers. Anthropic tries to create marketing hype around Mythos using two psychological tricks. 1. Put large numbers in the headlines. "Mythos discovered 271 vulnerabilities in Firefox" makes the model…
I work for a company that has been using Mythos for vulnerability detection in our software. The results we're getting are revolutionary to the point that our software security teams are heavily overloaded addressing the deluge of thousands of real bugs/vulnerabilities and design flaws across our billions of lines of code. For comparison, we are invested heavily the the AI space to the point where Anthropic is one of…
“Too dangerous to release” or just too expensive?
171–180 of 189 posts
Re: “Too dangerous to release” or just too expensive?
#172Earlier quoted context omitted.
For example, It was recently let loose on cURL and its maintainer is less than impressed: https://www.theregister.com/security/2026/05/11/anthropics-b...
If you remove the fluff that the register added and stick with https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v... it seems like a claim that's a claim fairly distant to "its all hype". Less than expected perhaps? Maybe the code really is unexpectedly robust? I guess time will tell on that point.
> "My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing."
> "I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos."
> "An amazingly successful marketing stunt for sure."
Personally I see this as a very strong claim of hype. I take away from this that Mythos is a hyped up marketing stunt, and not what it was preesented to be by Anthropic at all.
Re: “Too dangerous to release” or just too expensive?
#173Earlier quoted context omitted.
As far as my understanding goes. It is not a breakthrough model itself but finetuned model with right tools and skills. Fairly similiar to today's coding agents with difference that they are made for software engineering not cyber security.
Mythos is the next point on the scaling curve. It has considerably more parameters than most frontier models of today. Which gives it a lot more oomph per token. Is it a "breakthrough" as in "something novel and unexpected"? No. Is it a "breakthrough" as in "something we know works, but made to work on a greater scale"? Very much so.
Re: “Too dangerous to release” or just too expensive?
#174Earlier quoted context omitted.
Now imagine that your work specs are generated by an AI agent that the EM is using. Do you still care about the work?
Brother, I don't care who writes the specs as long as they sign the checks on time. And yes, I do care about my work even if upstream is slop. In a relay race, you can lower your performance to weakest leg, or you can be the strongest leg. And maybe I just like to run.
Re: “Too dangerous to release” or just too expensive?
#175Earlier quoted context omitted.
Mythos is the next point on the scaling curve. It has considerably more parameters than most frontier models of today. Which gives it a lot more oomph per token. Is it a "breakthrough" as in "something novel and unexpected"? No. Is it a "breakthrough" as in "something we know works, but made to work on a greater scale"? Very much so.
So it's just a bigger model? Like for example todays 1T models?
It matters because the "g factor" of today's LLMs is at least in part a function of raw scale. Larger models are just smarter - assuming you can handle the training and inference at this increased scale.
Re: “Too dangerous to release” or just too expensive?
#176Earlier quoted context omitted.
So it's just a bigger model? Like for example todays 1T models?
Supposedly 10T scale. Literally the next big thing. A bit like what OpenAI tried with GPT-4.5 - but Anthropic actually made it work with MoE, reasoning, tool use, RLVR, etc. It matters because the "g factor" of today's LLMs is at least in part a function of raw scale. Larger models are just smarter - assuming you can handle the training and inference at this increased scale.
Re: “Too dangerous to release” or just too expensive?
#177Earlier quoted context omitted.
Multiple people who have already used Mythos or been given its reports on their software have publicly stated that it's all hype, and that it is not really finding any new critical bugs which other models cant.
In this very thread we have a counter-example. What to think? https://news.ycombinator.com/item?id=48149519
The cURL creators report is the only real substance we have to go on. There are plenty of random comments both ways, but Im sure you and I would both agree that we shouldnt base our opinions on random internet comments and should wait for more official reports like the cURL one to make best judgement.
Re: “Too dangerous to release” or just too expensive?
#178Earlier quoted context omitted.
are you able to detail a single safeguard you plan to implement, so that I can stop believing it's vaporware and/or a scam?
How would it be vaporware? It's out in the wild and has been used by individuals/corporations.
Re: “Too dangerous to release” or just too expensive?
#179Re: “Too dangerous to release” or just too expensive?
#180Earlier quoted context omitted.
CURL has been scanned with multiple LLMs. Mythos was last and as a result found only 1 issue. If Myhos was really much better I'd expect it to find a lot more issues despite the others already there. Also, the competing models are getting better. Opus 4.5 was better than everyone else when it was new, but only a few months later and there are a lot of models that are better (not just the newer Opus models)
Curl had a prominent bug bounty programme, has 180k lines of prod code, and is mainly a client app/lib. I would look at other projects before making judgements about mythos on this one.
We already know that mythos will be branded catnip for sub-SOTA projects. They could have build SOTA secure software development practices last week, last month or last year. But didn't care. What will their experience with mythos tell us other than AI hype can create corporate will to take security seriously?