Anthropic Accidentally Leaks 'Claude Mythos' — Its Most Powerful and Dangerous Model Yet
A CMS security blunder exposed nearly 3,000 unpublished Anthropic assets on March 27, including internal documents describing Claude Mythos — a model the company says poses unprecedented cybersecurity risks.
Anthropic’s content management system exposed approximately 3,000 unpublished assets on March 27, 2026 — including internal documents, images, and PDFs — that revealed the existence of an unreleased model called Claude Mythos. The company confirmed the leak the same day rather than issuing a denial, which itself is the tell: this is real, and it’s coming soon.
What the Documents Say
Mythos is described in the leaked materials as “the most powerful system the company has built to date.” Three capability areas stand out:
- Software programming — significant improvement over Claude Opus 4.6
- Academic reasoning — top-of-class on mathematical and scientific benchmarks
- Cybersecurity — Anthropic’s own documents state the model “far surpasses all existing AI models” in this domain
That last point explains the restricted release strategy. Anthropic says Mythos poses “unprecedented cybersecurity risks” — language the company has not used for any previous model. The plan is an invite-only rollout, limited initially to selected early customers using it specifically for cybersecurity defense. No public release is planned in the near term.
The Leak Itself
The exposure occurred through a basic CMS misconfiguration, not an external breach. Nearly 3,000 staging assets became publicly accessible — an embarrassing operational failure for a company whose entire value proposition involves responsible, controlled AI development. The leak included draft blog posts, internal PDFs, and images associated with Mythos product positioning.
Anthropic’s decision to confirm rather than downplay the leak was strategically sound. Denying the existence of a model that thousands of people may have already cached is a losing position. The confirmation also lets Anthropic frame the narrative: this is a safety-first restricted rollout, not a rogue release.
The UK Retreat Detail
Among the leaked assets: plans for an invite-only retreat in the UK where CEO Dario Amodei will personally demonstrate Mythos features to European corporate executives. This fits Anthropic’s broader enterprise pattern — direct executive access for high-value customers before broader deployment.
Why the Cybersecurity Angle Matters
“Far surpasses all existing AI models” on cybersecurity benchmarks is an extraordinary claim. If accurate, Mythos represents a capability inflection point in automated vulnerability research, exploit generation, and threat analysis. That’s exactly why Anthropic is keeping it behind a closed customer program initially: demonstrating it works for defense while limiting offensive exposure.
The comparison to previous models matters for context. Claude Opus 4.6 already ranks first on SWE-Bench at 80.8%. A “step change” above that, applied to cybersecurity, suggests Mythos can find and reason about vulnerabilities at a level current models cannot.
Sources: Fortune — fortune.com/2026/03/27/anthropic-leaked-ai-mythos-cybersecurity-risk; The News — thenews.com.pk/latest/1396861, March 27, 2026
Related reading
- AI Models Claude Sonnet 5 Is Out: Near Opus Performance at One-Third the Cost
- AI Models Anthropic's Claude Mythos Preview: The Most Capable AI Model Ever Evaluated — Locked Behind Project Glasswing
- Hardware Anthropic Is Building an In-House Chip Design Team, Paying Up to $485K to Escape the Nvidia Tax