Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
third-party-vendor-breachai-platform-securitybuild-pipeline-compromiseinsider-threat-incident

Unauthorized Access to Anthropic’s Mythos Preview Exposed Supply-Chain Weaknesses

Updated 2d agoFirst seen Apr 22, 20264 sources

Anthropic is investigating reports that unauthorized users accessed its unreleased Claude Mythos Preview model through a third-party vendor environment tied to its restricted Project Glasswing rollout, rather than through Anthropic’s production API. Multiple reports say a small private Discord-based group obtained access by combining a contractor’s credentials or environment access with an educated guess of the model’s online location, allegedly aided by information exposed in the recent Mercor breach linked to a LiteLLM supply-chain attack. Anthropic said it has no evidence so far of unauthorized use beyond the third party’s IT environment, while the incident has drawn attention to vendor, insider, and supply-chain risk around tightly controlled AI deployments.

The breach also intensified scrutiny of Anthropic’s claims that Mythos was too dangerous for broad release because of its offensive cybersecurity capabilities. Researchers and early evaluators cited by several outlets said Mythos appears fast and useful for vulnerability discovery, but not clearly beyond the reach of elite human researchers or materially more dangerous than existing public or open models. Critics also disputed Anthropic’s reported results, including claims about thousands of severe vulnerabilities and standout exploit discoveries, with some saying notable findings were attributable to other Claude models or depended on human guidance and weakened test conditions.

Share:
Unauthorized Access to Anthropic’s Mythos Preview Exposed Supply-Chain Weaknesses
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 23, 20262mo ago

OpenAI broadly released GPT-5.4-Cyber with safeguards

The reporting said OpenAI responded to Anthropic's restricted-release approach by broadly releasing GPT-5.4-Cyber with identity verification and trust-signal safeguards.

Report: Discord Group Uses Claude's Supposedly Secret Mythos

Researcher said Anthropic-attributed Linux bug was found by public Claude model

According to researcher Devansh, a Linux kernel bug Anthropic cited as evidence of Mythos's capabilities had actually been discovered by Claude Opus 4.6, Anthropic's publicly available model. The claim undercut Anthropic's portrayal of Mythos as uniquely capable.

Anthropic's "too dangerous" AI was accessed by guessing the URL - Boing Boing

Anthropic restricted Mythos to selected firms under Project Glasswing

Anthropic limited access to Mythos to selected companies under Project Glasswing, including firms such as Nvidia, Apple, Amazon, and Cisco, to identify and remediate vulnerabilities before broader exposure. This restricted rollout formed the backdrop to the later unauthorized access reports.

Report: Discord Group Uses Claude's Supposedly Secret Mythos
Apr 22, 20262mo ago

Anthropic said it is investigating unauthorized Mythos access

Anthropic confirmed it is investigating reports of unauthorized access to Mythos and said it had no evidence of unauthorized use beyond the third party's IT environment. The company framed the issue as involving a vendor environment rather than its production API.

Anthropic Mythos shaping up as nothingburger

Unauthorized group accessed Anthropic's Mythos Preview via third-party environment

A small unauthorized group reportedly gained access to Anthropic's unreleased Claude Mythos Preview model through a third-party contractor or vendor IT environment, rather than Anthropic's production API. Reports said the group used methods including guessing the model's online location based on prior Anthropic deployment patterns.

Anthropic Mythos shaping up as nothingburger

Mercor breach tied to LiteLLM attack exposed data linked to Mythos access

Reporting said data from a recent Mercor breach associated with a LiteLLM supply-chain attack helped expose details that enabled unauthorized users to locate or access Anthropic's Mythos Preview model.

Anthropic Mythos shaping up as nothingburger
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Affected products
4 linked
FirefoxLinux KernelFreebsdClaude Code
Organizations
18 linked
AnthropicMozillaCisco SystemsAmazon Web ServicesOpenaiMicrosoft CorporationGoogleMercorThe RegisterNvidiaHorizon3.aiBlack DuckAISLEMerckAppleVulnCheckBloombergAcalvio
Breaches
2 linked
ANTHROPIC-2026-04MERCOR-2026-04
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Unauthorized Access to Anthropic’s Mythos Preview Exposed Supply-Chain Weaknesses | Mallory