Someone got unauthorised access to Claude Mythos, Anthropic is investigating the leak
A small group reportedly accessed Anthropic's Mythos AI model through a third party, raising concerns about security and misuse.
by Om Gupta · India TodayIn Short
- Small group claims unauthorised early access to Anthropic’s Mythos AI model
- Access reportedly gained through third-party vendor environment loophole
- Incident raises concerns over AI security and misuse risks
A small group of unauthorised users has gained access to Anthropic Mythos, an AI model which the company has dubbed so powerful that, if it falls into the wrong hands, it could be used as a potential hacking tool. The group has claimed that it has had access to the tool since the day it was first announced. This has come at a time when many companies want to safeguard their systems against malicious actors before releasing such tools to the general public.
The tool is not available to the general public, but Anthropic has provided it to a limited batch of software providers through an initiative called Project Glasswing. This initiative was aimed at ensuring that these firms test and safeguard their own systems from potential cyberattacks.
As per a Bloomberg report, the group has gained access to the tool via a third party. They used a number of tactics to gain access, including the account of a person who worked at a third-party contractor for Anthropic.
Anthropic said it is aware of this unauthorised access to Claude Mythos Preview and has stated that it is currently investigating the issue. The company added that it has not found any evidence that the group has gained access beyond the third-party vendor or any of Anthropic’s systems.
“We’re investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments,” a spokesperson for Anthropic said in a statement to Bloomberg.
Capabilities raise concerns
When Anthropic first announced the tool, it said it is capable of identifying and exploiting vulnerabilities “in every major operating system and every major web browser when directed by a user to do so.”
The users are part of a private Discord channel that focuses on finding information about unreleased models. Bloomberg reported that the group has been using Mythos regularly since then, though not for cybersecurity purposes.
How the group accessed Mythos
As per Bloomberg, to access Mythos, the group of users made an educated guess about the model’s online location based on knowledge of the format Anthropic has used for other models.
Bloomberg, based on an interview with a member of the group, said the group is interested in playing around with new models, not wreaking havoc with them. They have not run cybersecurity-related prompts on the Mythos model. The group also has access to a slew of other unreleased Anthropic AI models.
Bigger questions around AI security
This unauthorized access has raised questions about the challenges AI companies face in preventing their most powerful and potentially dangerous technology from spreading beyond approved partners. It also raises concerns about whether anyone else may be using Mythos without permission, and for what purpose.
- Ends