10 HeroEN

Generative AI is no longer seen merely as a tool for writing documents or assisting with code. It is increasingly being recognized as a technology that could reshape the structure of cybersecurity itself. Recently, one name has drawn significant attention from the security community and major enterprises.

That name is Claude Mythos Preview from Anthropic, commonly referred to as Mythos. It is Anthropic’s Claude Mythos Preview, an AI model commonly known as “Mythos”.

Mythos is not a widely available AI service for general users. It is a high-performance AI model made available through Anthropic’s Project Glasswing, a limited defensive security program involving selected major companies and government-related organizations. The reason this model attracted attention from security experts around the world was not simply because it could write well or generate code. It was because Mythos demonstrated the ability to read software code in depth, identify hidden vulnerabilities, and analyze whether those vulnerabilities could lead to real-world exploitation.

This raises a fundamental question.

Does Mythos really mean that an “AI hacker” has arrived?

This question is not simply about one AI model. The real significance of Mythos is not in the sensational idea that “AI can hack like a human.” What deserves attention is that the speed and scale of vulnerability discovery, analysis, and exploitability assessment are beginning to change at a structural level.

In that sense, the Mythos shock is a strong signal of how AI could reshape the cybersecurity threat landscape.


Mythos Shock: What Is Claude Mythos Preview?

Mythos is a high-performance Claude-family AI model developed by Anthropic. Its full name is Claude Mythos Preview. The first thing to understand is that Mythos was not created as a dedicated hacking tool.

At its core, Mythos is a general-purpose frontier AI model based on large language model technology. It is designed to understand context, analyze complex code, and carry out multi-step reasoning. What makes Mythos notable is that these advanced reasoning capabilities become especially powerful when applied to the domain of cybersecurity.

If conventional generative AI responds to requests such as “Find the error in this code,” Mythos has shown a capability closer to understanding the broader codebase, isolating hidden vulnerabilities, and evaluating whether they could be used to construct a viable attack path.

Category Description
Name Claude Mythos Preview
Developer Anthropic
Model Type A high-performance frontier AI model operated under limited access, not a public chatbot for general users
Core Capabilities Strong performance in security-related tasks such as code analysis, vulnerability discovery, and exploitability assessment
Access Model Provided for defensive security use to selected companies and organizations through Project Glasswing
Public Availability Not available to general users

For this reason, it would be inaccurate to describe Mythos simply as a “security program.” A more precise description is that it is a general-purpose AI model whose coding, reasoning, and analytical capabilities have advanced to the point where they can support high-level security work.


How Is Mythos Different from Other AI Models?

It would be easy to misunderstand Mythos as simply “an AI that writes code better.” But that misses the key point. Many generative AI models already assist with code writing and debugging.

What sets Mythos apart is its ability to connect the multi-step agentic workflow required for security analysis into a coherent sequence.

Comparison Point Claude Mythos Preview Claude Opus 4.6 GPT-5.4 Gemini 2.5 Pro
Developer Anthropic Anthropic OpenAI Google DeepMind
Model Type Unreleased frontier AI model Public Claude frontier model Public GPT frontier model Public Gemini frontier model
Access Model Limited access for selected Project Glasswing participants Available to general users and enterprise customers Available through ChatGPT, API, and Codex Available through Gemini app, Google Search, Google AI Studio, Vertex AI, and related services
Primary Purpose High-risk software vulnerability discovery and defensive security analysis Advanced reasoning, coding, document analysis, and enterprise productivity Professional work, coding, analysis, and agentic tasks Multimodal reasoning, search, productivity support, coding, and agentic tasks
Cybersecurity Role Vulnerability discovery, reproduction, and exploitability analysis are central issues Can support security analysis, but is operated as a general-purpose model Can support security work, but is positioned primarily as a productivity and agentic AI model Can support security work, but is positioned mainly around multimodal, search, and developer assistance
Operational Difference Access is restricted due to its advanced cyber capabilities Used as part of the general Claude product family Publicly available commercial AI model Publicly available commercial AI model

The key point in this comparison is not that Mythos is simply a more powerful AI model. Major frontier AI models such as Claude Opus, GPT-5.4, and Gemini 2.5 Pro also demonstrate strong capabilities in coding, reasoning, document analysis, and agentic tasks.

What makes Claude Mythos Preview different is that it showed particularly strong performance in vulnerability discovery and exploitability assessment. As a result, it was not offered as a public service, but operated through the limited-access Project Glasswing program. In this sense, Mythos can be understood as an example of AI moving beyond general productivity assistance and beginning to support parts of the core workflow traditionally performed by security experts.

10 Mthos는 무엇이 다른가EN

A Powerful AI Model Under Limited Access

The real reason Mythos drew attention from the Western cybersecurity community was not just its performance. It was the potential cybersecurity implications of making such a model broadly available.

Most AI models are released as public services only after going through safety guidelines and alignment processes. A familiar example is that they refuse requests to generate malware. Mythos, however, demonstrated the ability to identify software weaknesses and evaluate whether they could be used in an attack scenario, even when used for defensive purposes.

What would happen if this kind of capability were made available without restriction to adversarial hacking groups or underground marketplaces?

Modern enterprise software environments are built on thousands of open-source components, third-party libraries, APIs, and external integrations. No matter how carefully they are maintained, security gaps can still exist. In the past, finding these weaknesses required highly skilled human experts and significant time.

If AI can scan an entire codebase, identify likely vulnerabilities, and help automate the validation process, the time and effort required to prepare an attack could fall significantly. This is why Anthropic chose not to provide Mythos as a public service, but to operate it in a limited program for defensive security use. Once an AI model’s cyber capabilities cross a certain threshold, controlling how it is deployed becomes as important as the capability itself.


The Real Change Mythos Reveals: The Speed of Vulnerability Discovery

The most important keyword in the Mythos discussion is automation.

When we say AI can find vulnerabilities, we are not simply saying that it can point out suspicious lines of code. Real security analysis requires understanding code structure, identifying suspicious paths, and verifying whether a weakness could actually lead to exploitation.

Historically, this work belonged to highly skilled security experts. Mythos showed that AI can assist with a meaningful portion of this process. According to Anthropic, Mythos Preview scored 83.1% in the CyberGym vulnerability reproduction evaluation, outperforming Claude Opus 4.6 at 66.6%. The UK AI Security Institute also reported that Mythos completed a 32-step enterprise network attack simulation from start to finish in 3 out of 10 attempts, demonstrating its ability to execute multi-step cyber tasks.

These numbers do not simply mean that Mythos is “smarter.” They suggest that parts of the workflow traditionally performed by security experts — vulnerability discovery, reproduction, and exploitability assessment — can be accelerated with AI assistance.

This does not mean that AI can automatically compromise every enterprise system. The AI Security Institute also noted that the evaluation was conducted in a weakly defended experimental environment, and that the results should not be interpreted as proof that the model could compromise well-defended real-world systems in the same way.

The message Mythos sends is more practical.

Weak security structures may be exposed faster, and exploited faster, in the age of AI.


Why Financial Services, Data Centers, and Public Sector Organizations Are Paying Attention

The Mythos shock is not only relevant to AI labs or cybersecurity researchers. Financial institutions, large-scale data centers, public infrastructure, and supply-chain ecosystems are especially sensitive to this shift because account and privilege compromise in these environments can lead to cascading damage.

Sector Key Risks Growing Pressure in the AI Era
Financial Services Compromise of customer accounts, internal accounts, administrator privileges, and approval workflows More sophisticated phishing, account takeover, and fraudulent transaction approval risks
Data Centers Compromise of operator accounts, access privileges, and server access permissions Cascading impact across customer systems and service availability risks
Public Sector Compromise of administrative and public-service systems, internal accounts, and sensitive data access Exposure of personal data, disruption of public services, and erosion of public trust
Supply Chain Compromise of partner accounts, external access privileges, and management systems Indirect intrusion through less-protected suppliers and partners

The essence of security in these critical environments is not simply about making the external wall thicker. Once an attacker obtains an internal account by any means, the real question becomes how far that account can move, what privileges it can exercise, and how effectively internal access can be controlled.


What Is the Defense Layer AI Cannot Easily Replicate?

As AI accelerates vulnerability discovery and attack automation, enterprise security standards must also evolve.

Traditional defense strategies often assumed that if the firewall was strong enough and the external perimeter was closed, the internal environment could be trusted. Mythos challenges this assumption. In an AI-accelerated threat environment, organizations must ask one question before anything else:

Is the user requesting access to this internal system really who they claim to be?

Attackers no longer need to break down the front gate. With stolen credentials, reused passwords, or authentication data obtained through phishing, they can often enter systems while appearing to be legitimate users. If AI makes phishing more convincing, automates social engineering, and assists repeated authentication bypass attempts, this risk becomes even more serious.

Digital information-based MFA — such as SMS OTPs, mobile push approvals, and email links — remains useful, but it is not a complete safe zone. As long as authentication codes or approval requests move as data, they can still be exposed to phishing, session hijacking, user error, and push fatigue attacks.

Biometric information is not a perfect isolated zone either. As AI-generated deepfakes and sophisticated spoofing techniques advance, biometric authentication will continue to face challenges.

However, unlike passwords or OTPs that move across a network as digital information, physical biometric factors require far more conditions and resources for an attacker to capture and reproduce. When combined with device-based verification and anti-spoofing technologies, biometric authentication can create a structure in which stolen account information alone is not enough to complete access.

This is why biometrics and hardware-based verification are gaining attention in the AI era. The goal is not to build authentication that can never be bypassed. The goal is to increase the time, effort, and complexity an attacker must overcome.

10 AI 시대의 인증 전략EN

Security Strategy After Mythos: From Fear to Practical Physical Trust

Viewing the Mythos shock merely as the arrival of a movie-like “AI hacker” misses the point. What Mythos shows is that both attackers and defenders are entering a security environment where AI can accelerate action.

In an era where software vulnerabilities and digital information can be analyzed faster with AI, relying on a single perfect security program is no longer realistic. Enterprise security must move away from the idea of eliminating every attack and toward designing layered verification points that attackers must overcome before they can succeed.

One of the most important layers is the combination of biometric information and hardware-based verification. When credentials such as passwords, OTPs, and tokens can be exposed as data, a system that verifies both the user’s physical characteristics and the trustworthiness of the authentication device can become a strong security layer.

Ultimately, the goal of cybersecurity in the AI era is not to create a system that cannot be attacked. It is to build a system that increases the time, effort, and complexity required for an attacker to succeed, while re-verifying the real user and their privileges even if an account is compromised.

Organizations should move beyond the question, “How can we block AI attacks perfectly?” Instead, they should start from a more practical question:

In an environment where all digital information can be threatened, how should we establish trust in real user access?

 

 

References

Anthropic. (2026). Project Glasswing: Securing critical software for the AI era. Anthropic.

AI Security Institute. (2026, April 13). Our evaluation of Claude Mythos Preview’s cyber capabilities. UK AI Security Institute.

Google Cloud. (2026). Claude Mythos Preview on Vertex AI. Google Cloud Blog.

OpenAI. (2026). Introducing GPT-5.4. OpenAI.

Google DeepMind. (2025). Gemini 2.5: Our most intelligent AI model. Google.

Kim, K.-T. (2026, May 8). “AI 해킹, 다음 타깃은 금융·데이터센터”…인증체계 고도화 시급. Newsis.

ISO/IEC. (2017). ISO/IEC 30107-3: Information technology — Biometric presentation attack detection — Part 3: Testing and reporting. International Organization for Standardization.