Someone Used Mythos Without Permission for Two Weeks Before Anthropic Noticed

On April 7, the same day Claude Mythos was publicly announced, an unidentified Discord group had already entered its systems.

Anthropic only detected the intrusion on April 21 — a full two weeks after the breach began. The company took that long to realize that what it describes as one of the most tightly controlled AI models in the world was being used by strangers without authorization.

How They Got In

The chain of events appears to be:

  1. Mercor, an AI training startup, suffered a data breach that exposed internal credentials.
  2. A Discord group had been monitoring GitHub for information about unreleased AI models.
  3. Group members combined the leaked Mercor data with account credentials belonging to "an employee of a third-party vendor for Anthropic."
  4. Using network reconnaissance tools — the kind commonly used in security research circles — they located and accessed the Mythos preview environment.

Bloomberg spoke with a member of the group, who said they were "just interested in the new model and didn't intend to cause trouble."

Believe that or not.

Anthropic's Response

The official statement reads:

We are investigating a report of unauthorized access to a preview version of Claude Mythos through one of our third-party vendor environments.

Standard corporate crisis communication. It does not specify the scale of the intrusion, what the group may have seen, or whether any data was taken.

Why This Is More Serious Than It Looks

Mythos is not an ordinary unreleased model.

Anthropic stated at launch that the model was only made available to 40 vetted companies because its capabilities in cyberattacks triggered internal safety thresholds. In other words, Anthropic itself judged it too risky for broad release.

An AI deemed "too dangerous to release publicly" was accessed by unidentified individuals for 15 days. This is fundamentally different from someone using a beta chatbot.

More critically: they gained access on April 7, the very day of Mythos's first public announcement. The gap between the announcement and the breach may have been only a few hours.

Third-Party Supply Chains: The Hardest Vulnerability for AI Companies to Fix

Anthropic's own security systems may be robust. But this breach did not originate inside Anthropic — it came through a contractor's employee.

Rapidly scaling AI companies inevitably rely on a large number of external vendors — for data labeling, infrastructure, testing, and compliance reviews. Every access point is a potential gap.

The chain here was: Mercor breach → vendor employee account → Anthropic internal preview environment. Each step was "someone else's problem" until it became Anthropic's own problem.

OpenAI, Google, and Meta have all experienced similar supply chain security incidents. The only difference is which ones make the news.

What Did the Group Actually Do?

That is not yet known. Bloomberg did not disclose it, and Anthropic has not said.

They may have tested the model's boundaries, run some benchmarks, or extracted something and taken it away. The claim "we didn't intend to cause trouble" cannot be verified in any way.

Anthropic now faces a situation where, until its investigation is complete, it does not fully know what happened inside that preview environment.

Sources: Some Unknown Group Is Reportedly Using Claude Mythos Without Permission (Gizmodo); CocoLoop; Unauthorized Group Gains Access to Anthropic's Exclusive Cyber Tool Mythos (Cybersecurity News)