On April 7, Anthropic launched Claude Mythos — an AI model so powerful the company itself admitted it "could enable dangerous cyberattacks." Access was locked down to just 40 hand-picked organizations: Microsoft, Apple, Google, Cisco, plus heavyweight banks like Goldman Sachs, Citigroup, and Morgan Stanley, under an initiative called Project Glasswing.
On that exact same day, a small group of users in a private Discord channel was already inside.
🕵️ How they got in
According to Bloomberg, the group didn't "hack" Anthropic. They did something more embarrassing:
1. They guessed the URL where Mythos was hosted — based on familiarity with how Anthropic structures URLs for its other models.
2. Someone on the inside — an employee at a third-party contractor — helped facilitate access.
3. Vendors with penetration-testing privileges had shared accounts and API keys that unauthorized users then used.
Anthropic's response:
We're investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments.
The Discord group has been using Mythos regularly since. They gave Bloomberg screenshots and a live demo of the software.
Stay protected,
🌍 Planet VPN
#cybersecurity #ai #anthropic #claudemythos #privacy #vpn #supplychainattack #infosec #planetvpn #aisecurity

