Anthropic’s Claude Mythos Preview is emerging as a new variable in cybersecurity risk after identifying thousands of zero-day vulnerabilities across major operating systems and browsers—including flaws in cryptographic libraries critical to decentralized finance (DeFi).
The company says its model can autonomously discover and exploit previously unknown bugs at a level beyond both human researchers and existing automated tools, effectively accelerating years of security work into hours.
Early results highlight the scale of its capabilities. Mythos uncovered a 27-year-old vulnerability in OpenBSD—an operating system designed for maximum security—for under $50 in compute. It also exposed a 16-year-old flaw in FFmpeg, a core pillar of global streaming infrastructure, despite the codebase having undergone millions of scans.
Crucially, the model can move from detection to execution. It built a browser exploit by linking four separate vulnerabilities to bypass multiple layers of protection, and converted a known Linux flaw into a working attack in less than a day for under $2,000—tasks that would typically take weeks of expert effort.
The development is raising concern across the tech industry. Unlike long-term, largely theoretical risks such as quantum threats to Bitcoin, Mythos is already operational and identifying weaknesses in software that secures real assets.
For crypto markets, the key risk lies in vulnerabilities found in widely used cryptographic standards such as TLS, AES-GCM, and SSH. These systems underpin encrypted communications, HTTPS connections, and server access—foundational elements of DeFi and exchange infrastructure.
If exploited, such flaws could enable attackers to forge authentication credentials or decrypt sensitive data, introducing systemic risks.
DeFi protocols may be particularly exposed due to their open-source nature. With publicly accessible code, an AI system like Mythos can scan entire codebases, map vulnerabilities, and identify attack paths at machine speed and near-zero marginal cost.
While more than $200 billion remains locked in smart contracts across networks like Ethereum and Solana—many of which have been audited—Anthropic suggests its model operates beyond the reach of both human reviewers and conventional scanners.
The firm also warned that defenses based on friction rather than hard security guarantees may weaken against AI-driven threats. Mechanisms such as multisignature approvals, timelocks, and audit assurances may delay attacks but do not eliminate underlying code risks.
Markets, for now, remain focused elsewhere. The CoinDesk DeFi Select Index rose 7% over the past 24 hours, outperforming Bitcoin and Ether amid improving risk sentiment following a temporary U.S.-Iran ceasefire.
Still, Mythos introduces a new dimension of risk that may become harder to ignore. As AI-driven vulnerability discovery scales, it could challenge existing assumptions about the security of blockchain infrastructure.
Access to the model remains restricted. Anthropic is sharing Mythos with a limited group of roughly 40 major technology firms—including Google, Apple, and Microsoft—under its Project Glasswing initiative.























