Technology
Anthropic says Claude Mythos Preview found flaws in weakened cryptography
Anthropic said Claude Mythos Preview uncovered new attacks against weakened cryptographic algorithms, the kind of software that helps protect online financial transactions and private communications. The result matters because the company is not describing a theoretical classroom exercise: it is testing whether a general-purpose AI model can push cryptanalysis far enough to expose weak points before banks, governments and tech firms finish hardening the systems they already rely on.
The company’s research note, Assessing Claude Mythos Preview’s cybersecurity capabilities, said Anthropic announced Claude Mythos Preview as a new general-purpose language model and described it as showing strong cybersecurity performance. The note listed Nicholas Carlini, Newton Cheng, Keane Lucas, Michael Moore, Milad Nasr, Vinay Prabhushankar and Winnie Xiao as authors, underscoring that the evaluation was built around a dedicated security team rather than a marketing claim.

A separate evaluation from the United Kingdom’s AI Security Institute added outside scrutiny to that assessment. The government-backed body published its own review of Claude Mythos Preview’s cyber capabilities, giving the model a second look from an independent safety-focused institution. That is especially relevant because the attacks Anthropic highlighted were found in weakened cryptographic systems, not in a broad public break of modern encryption used across most banking, messaging and cloud infrastructure.
Anthropic has also tied the model to a much larger security effort called Project Glasswing. In an update on that program, the company said it had worked with approximately 50 partners and that, since launch, those partners had used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities. That scale suggests the model is being used as a serious vulnerability-hunting tool, not just to flag low-level bugs.

The practical question for security teams is not whether AI can scan for flaws, but whether it can accelerate discovery faster than defenders can patch. Anthropic’s own positioning points in that direction: it linked Claude Mythos Preview to code security work and restricted wider use because of its cybersecurity abilities. For financial firms, communications providers and public-sector agencies, the immediate risk is less a collapse of today’s strongest encryption than the chance that AI makes older or weakened systems far easier to break before they are retired.
Sources
- [1]nytimes.com
- [2]anthropic.com
- [3]aisi.gov.uk
- [4]facebook.com
- [5]postquantum.com