US Treasury Summons Wall Street to Assess Anthropic's Mythos

An AI That Finds Vulnerabilities by Itself

Let's start with the numbers. When Anthropic tested Mythos Preview, it found that the model could successfully reproduce and exploit a vulnerability in a single attempt 83.1% of the time. For comparison, the company's own Claude Opus 4.6 scored close to 0% on the same metric.

This isn't a small improvement — it's a leap from 0% to 83%.

What can it actually do? Mythos wrote a browser exploit that chained together four separate vulnerabilities, used a complex JIT spray technique, and successfully escaped both the renderer process and the operating system sandbox. It also wrote a remote code execution exploit targeting a FreeBSD NFS server vulnerability using ROP chain techniques.

Anthropic itself says the model found thousands of new zero-day vulnerabilities in every major operating system and every major browser.

Earlier reports about Mythos finding a 27-year-old vulnerability now appear to be just the tip of the iceberg.

Fed Chair, Treasury Secretary, and Six Bank CEOs in One Room

When Anthropic released the Mythos preview on April 7, it restricted access to roughly 40 organizations under a program called "Project Glasswing." Participants included Amazon, Apple, Microsoft, Google, Cisco, CrowdStrike, JPMorgan Chase, NVIDIA, Broadcom, Palo Alto Networks, and the Linux Foundation. Each participating organization also received up to $100 million in compute resources.

Then, on April 10, Federal Reserve Chair Jerome Powell and Treasury Secretary Scott Bessent called the CEOs of Goldman Sachs, Wells Fargo, Morgan Stanley, Bank of America, and Citigroup into a single room for an emergency meeting.

The agenda: What happens if Anthropic's AI falls into the wrong hands?

CrowdStrike's CTO put it bluntly: "The window from vulnerability discovery to exploitation has shrunk from months to minutes. AI has fundamentally changed the speed of this process."

But the Pentagon Still Bans Anthropic

Here's the central contradiction.

While Powell and Bessent were convening bankers in Washington to assess Mythos, the Pentagon still lists Anthropic on its supply chain blacklist, requiring defense departments to stop using all Anthropic platforms.

President Trump and Defense Secretary Pete Hegseth's rationale: Anthropic insists on restricting the use of its AI in military scenarios.

So the conclusion is: The White House is on one hand letting Wall Street test defenses, while on the other banning the military from using the same company. The same company, the same model, the same administration — two completely opposite stances.

Former White House AI advisor David Sacks said he questions whether Anthropic is using security anxiety to market its products and influence regulatory policy. There is some merit to this criticism.

Anthropic's Explanation

Anthropic's logic is: Precisely because the model is so dangerous, they are hesitant to release it broadly. Project Glasswing's design philosophy is to let top technology companies use Mythos to find vulnerabilities in their own systems and patch them before attackers can strike.

  • Mythos finds vulnerabilities → Participating organizations patch them → Defenders gain the upper hand
  • Participants share security intelligence
  • Anthropic reports all discovered vulnerabilities to the relevant vendors

This is called "AI fighting AI." The problem is: Not everyone believes Anthropic can control access boundaries. The 40 participating organizations include commercial competitors, and sharing vulnerability information is itself a complex game of strategy.

And the "thousands" figure has not yet been broken down in detail.

What This Means

The Mythos story is more significant than any benchmark score because it hits a real nerve: If an AI can automatically find vulnerabilities in any system, the underlying logic of cybersecurity needs to be rewritten.

Powell and Bessent didn't call bank CEOs to an emergency meeting to discuss whether AI has potential. They did it because they believe the threat is real and imminent.

And that emergency meeting itself is the most powerful proof of how capable this AI is.

Regardless of whether Sacks' criticism is valid, an AI model forcing the Fed Chair to sit down with Wall Street's top bank CEOs for a security briefing — this is a first in human history.

Sources: Trump officials may be encouraging banks to test Anthropic's Mythos model (TechCrunch); Anthropic Mythos model can find and exploit 0-days (The Register); Powell, Bessent Warn Banks About Security Risks From Anthropic's Mythos AI (Bloomberg/Yahoo Finance); CocoLoop, After Anthropic's Mythos AI uncovers thousands of zero-day bugs, top US officials huddle with bank CEOs (TechXplore); Anthropic withholds Mythos Preview model because its hacking is too powerful (Axios).