Dr. Ibrar Ahmed

HomeAIArticle

AI Mechanics

Claude Mythos Found 10,000 Serious Flaws in Its First Month

Dr. Ibrar Ahmed3 min read

This is not a chatbot. Anthropic built Claude Mythos to find security flaws humans had missed for decades. Then it restricted access. In 30 days, partners reported more than 10,000 high and critical findings. Claude Mythos Found 10,000 Serious Flaws in Its First Month Project Glasswing | AI MECHANICS Of the high and critical open-source subset reviewed by humans, 90.

6% were valid. Several partners reported more than a tenfold increase on the same kind of codebases. The restriction is the point. The same discovery engine works without the patch. This episode walks the mechanism, not the press release: • Why one broad agent fails on a real repository • How the harness fans out into 20-50 narrow parallel hunts • Why a second agent tries to kill the finding • Reachability and attack path, not a lint hit • Proof: CVE-2026-5194 in wolfSSL.

Autonomous find. Human validated. Vendor patched. • May 2026 snapshot: 6,202 high and critical entered review. 1,094 confirmed. • Same engine. Defender path and attacker path. • September 2026: Mythos 5. 1 still gated. Stronger safeguards did not mean solved. • August 26 dashboard: 26,153 findings. 5,008 candidates. 91.

4% true positive. 2,300 disclosed. 421 patched. That August dashboard mixes Mythos Preview with other Claude models. It is not a Mythos-only scoreboard. Vulnerability discovery got cheap. Patching became the bottleneck. Would you trust an AI to scan your production code when every finding still needs human validation? SOURCES Project Glasswing (Apr 7, 2026): https://www.

anthropic. com/glasswing Assessing Claude Mythos Preview: https://www. anthropic. com/research/mythos-preview Glasswing initial update (May 22, 2026): https://www. anthropic. com/research/glasswing-initial-update CVD dashboard (Aug 26, 2026): https://red. anthropic. com/2026/cvd/ About the dashboard: https://red. anthropic.

com/2026/cvd/about/ Claude Fable 5. 1 and Mythos 5. 1: https://www. anthropic. com/claude-fable-and-mythos-5-1 System card: https://www-cdn. anthropic. com/0339e6a7c5c7b87f5c07798616dc32c215d14235/Claude%20Fable%205. 1%20%26%20Claude%20Mythos%205. 1%20System%20Card. pdf NUMBERS 90. 6% = 1,587 valid of 1,752 independently reviewed high/critical open-source findings.

1,094 of those were confirmed high or critical. 23,019 is every severity, side total only. August 26: 26,153 findings; 5,008 candidates; 4,576 reviewed; 91. 4% true positive; 2,300 disclosed; 421 patched. Mixed models. This video names a patched CVE and published program numbers. It does not include exploit steps, payloads, or reproduction.

WATCH NEXT LLM Inference & Performance: MORE AI MECHANICS How LLMs work: https://www. youtube. com/playlist? list=PLK3S1GR94Fzg AI agents: https://www. youtube. com/playlist? list=PLNeIEtc2-vsw Claude AI Tutorials: https://www. youtube. com/playlist? list=PLkN0YpuOmhzOZQ5OaOBhgExLQd3d8aH1z AI Mechanics. Understand the system, not the hype.

Watch the video for the full walkthrough. Use this page when you want the argument in writing without scrubbing the timeline.