Back to Blog
AI Models March 31, 2026 5 min read

Anthropic Confirms 'Mythos' — Its Most Powerful Model Yet — After Accidental Leak

Anthropic's next-generation model, internally codenamed Mythos or Capybara, was exposed through a misconfigured content management system. The company confirmed it represents a 'step change' in capabilities — and that its cybersecurity potential is unprecedented.

Anthropic Confirms 'Mythos' — Its Most Powerful Model Yet — After Accidental Leak

Anthropic didn’t plan to announce its next flagship model this week. A human error in the company’s content management system made the decision for them.

Security researchers Roy Paz of LayerX Security and Alexandre Pauwels of the University of Cambridge discovered an unsecured, publicly searchable data store containing a draft blog post describing the model in detail. The model goes by two internal names: Capybara (the development codename) and Mythos (the marketing name, apparently the successor to the Opus line).

An Anthropic spokesperson confirmed the exposure was real and not staged, calling Mythos “the most capable model we’ve built to date” and characterizing its performance as “a step change” over Claude Opus 4.6. Early-access customers are already testing it.

What the leaked draft revealed

On coding benchmarks, Mythos scores dramatically higher than Opus 4.6. The same pattern holds across academic reasoning and, most notably, cybersecurity evaluations. The draft described the model’s ability to rapidly identify and exploit software vulnerabilities at a level that security researchers are calling “unprecedented” for a commercially available system.

That last capability is what’s generating the most alarm. Internal Anthropic documents included in the exposed cache warn that Mythos could meaningfully accelerate a cyber arms race — autonomous exploitation of zero-days at machine speed, available through an API, is a different threat model than anything the security industry has dealt with before.

The model is being trialed under what Anthropic describes as “enhanced safeguards,” though the company has not disclosed what those constraints look like in practice.

The timing is charged

Anthropic is already involved in a legal dispute with the Department of Defense over how its models can be used for military and surveillance applications. The leak arrives while that case is ongoing and while Anthropic is simultaneously trying to position itself as the “safety-first” frontier lab.

Releasing a model that Anthropic’s own internal documents flag as a cybersecurity risk — even one with safeguards — will test that positioning. The company has not announced a public release date for Mythos.

Claude Opus 4.6 was already among the top-performing models on agentic and reasoning tasks. If Mythos represents a true capability jump rather than an incremental improvement, the gap between it and every other commercially available model will be significant.

Expect Anthropic to move quickly on a formal announcement now. The draft blog post is already written.

Anthropic Claude AI Safety Cybersecurity