Anthropic's Claude Mythos Preview, announced April 7, 2026, autonomously discovered thousands of zero-day vulnerabilities across every major operating system, web browser, and cryptographic library in a matter of weeks. The model achieved a 72.4% exploit success rate in controlled benchmarks — up...
"Mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries." — Anthropic, Project Glasswing Technical Report (April 7, 2026)
Anthropic's Claude Mythos Preview, announced April 7, 2026, autonomously discovered thousands of zero-day vulnerabilities across every major operating system, web browser, and cryptographic library in a matter of weeks. The model achieved a 72.4% exploit success rate in controlled benchmarks — up from near-zero for its predecessor, Claude Opus 4.6. Anthropic withheld the model from public release, restricting access to 12 corporate partners through a $100 million defensive initiative called Project Glasswing.
Three days later, Treasury Secretary Scott Bessent and Fed Chair Jerome Powell convened an emergency meeting with CEOs from Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs to assess the threat to financial infrastructure. OpenAI disclosed plans for a competing cybersecurity model codenamed "Spud." DeFi protocols holding over $200 billion in total value locked face a structural challenge: their open-source codebases are readable by the same AI that can catalogue every weakness at machine speed.
This report examines Mythos Preview's capabilities, the specific threat vectors it opens for decentralized finance, the defensive measures underway, and what the data implies for protocol security economics over the next 12 months.
Claude Mythos Preview is a general-purpose frontier model that Anthropic describes as surpassing "all but the most skilled humans at finding and exploiting software vulnerabilities." The performance gap over previous models is not incremental.
According to Anthropic's red team evaluation, published on red.anthropic.com on April 7, 2026:
The model operates autonomously after initial prompting. In one disclosed case, Mythos identified and fully exploited a 17-year-old remote code execution flaw (CVE-2026-4747) in FreeBSD's NFS server — granting unauthenticated root access — without any human involvement after the initial instruction.
Over several weeks of testing, Mythos Preview found thousands of previously unknown vulnerabilities across critical software infrastructure. Specific disclosed findings include:
| Software | Vulnerability | Age | Detail | |----------|-------------|-----|--------| | OpenBSD | TCP SACK integer overflow (DoS) | 27 years | Remote attacker can crash any host responding over TCP; discovered for under $50 in compute | | FFmpeg | H.264 codec flaw | 16 years | Introduced in 2003 commit, exposed by 2010 refactor; missed by every fuzzer and human reviewer across 5 million test runs | | FreeBSD | NFS server RCE (CVE-2026-4747) | 17 years | Unauthenticated root access via 20-gadget ROP chain; fully autonomous exploitation | | Linux | Kernel privilege escalation | Undisclosed | Exploited subtle race conditions and KASLR-bypasses for local privilege escalation | | TLS/AES-GCM/SSH | Implementation flaws in major crypto libraries | Undisclosed | Bugs enabling certificate forgery and decryption of encrypted communications |
The discovery of vulnerabilities in TLS, AES-GCM, and SSH implementations carries direct implications for every system that depends on encrypted communications — including blockchain node-to-node communication, RPC endpoints, and wallet infrastructure.
DeFi protocols face a compounded version of the Mythos threat. Three structural characteristics make decentralized finance uniquely exposed:
1. Transparent codebases. DeFi protocols are open-source by design. Their Solidity, Vyper, and Rust smart contracts are publicly readable on block explorers. An AI model operating at Mythos-level capability can scan, map, and catalogue every vulnerability in a protocol's codebase at machine speed. The transparency that enables trustless verification simultaneously enables adversarial reconnaissance.
2. Friction-based defenses, not hard barriers. Anthropic's own assessment flags multisig governance, timelocks, and audit reports as "friction-based" defenses that "may become considerably weaker against model-assisted adversaries." These mechanisms slow attackers but do not constitute cryptographic barriers. A model that can chain four browser vulnerabilities can plausibly navigate governance delays, simulate signer behavior, or identify timelock bypass vectors.
3. High-value, always-on targets. Over $200 billion sits in DeFi smart contracts across Ethereum, Solana, and other chains, according to DeFiLlama data. Aave alone approaches $50 billion in lending TVL. Unlike traditional bank vaults, these contracts execute 24/7, cannot be taken offline for patching, and cannot reverse transactions once confirmed.
Q1 2026 data provides a baseline for current attack patterns. According to DeFiLlama, 34 DeFi protocols lost a combined $168.6 million in Q1 2026 — an 89% decline from Q1 2025's $1.58 billion (inflated by the $1.4 billion Bybit breach). However, the composition of attacks is shifting: social engineering and private key compromises accounted for 84% of dollar losses, while pure smart contract exploits declined. The Mythos announcement inverts that trend line. Automated code-level exploitation at 72.4% success rates makes on-chain vulnerabilities economically viable targets again.
Anthropic chose not to release Mythos Preview publicly. Instead, it launched Project Glasswing on April 9, 2026, restricting the model to 12 founding partners:
An additional 40+ organizations that build or maintain critical software infrastructure received secondary access. Anthropic committed $100 million in model usage credits and $4 million in direct donations to open-source security organizations. Responsible disclosure timelines follow a 90+45 day window — vulnerabilities are reported to affected parties, who have 90 days to patch before public disclosure, with a 45-day extension if needed.
The government response was immediate. On April 10, Treasury Secretary Scott Bessent and Fed Chair Jerome Powell convened CEOs from five of the six largest U.S. banks — Citigroup's Jane Fraser, Morgan Stanley's Ted Pick, Bank of America's Brian Moynihan, Wells Fargo's Charlie Scharf, and Goldman Sachs' David Solomon — at Treasury headquarters. JPMorgan's Jamie Dimon did not attend but was briefed separately. The meeting focused on ensuring banks recognize the threat posed by AI-driven vulnerability discovery and accelerate defensive upgrades.
OpenAI disclosed plans for a competing cybersecurity model, internally codenamed "Spud," to be distributed through its existing Trusted Access for Cyber program, according to Axios reporting on April 9.
The DeFi sector has no seat at the Project Glasswing table. JPMorganChase is the only financial institution among the 12 founding partners, and its participation covers centralized banking infrastructure, not decentralized protocol code. This absence is conspicuous.
Early protocol-level responses suggest the sector is improvising:
Lido DAO, the largest liquid staking protocol by ETH staked, opened a governance forum discussion on April 10 titled "Frontier AI & Protocol Security: Is Lido Ready for the Mythos Era?" The proposal outlined three defensive measures: (1) engaging Glasswing partners CrowdStrike or Palo Alto Networks to apply Mythos-level tooling to Lido's staking contracts; (2) implementing autonomous AI red-teaming to simulate multi-step attack chains against Solidity code; and (3) replacing point-in-time audits with continuous AI-integrated CI/CD security pipelines. A community member raised concerns about "Black Box Governance" — the risk that automated security responses could centralize decision-making in what is supposed to be a decentralized protocol.
The broader audit industry is already integrating AI. According to a Security Boulevard report from March 2026, a purpose-built AI security agent detected vulnerabilities in 92% of 90 previously exploited DeFi contracts (representing $96.8 million in exploit value), compared to 34% detection for a baseline GPT-5.1-based coding agent. OpenAI and Paradigm's EVMBench showed GPT-5.3-Codex exploiting over 70% of critical Code4rena bugs — up from under 20% when the benchmark was first built.
Smart contract audit pricing ranges from $20,000 for simple protocols (500–1,000 lines) to $100,000+ for complex DeFi protocols requiring 3–4 auditors over 4–6 weeks. Protocols using active monitoring with automated response capabilities reduced average loss per incident by over 80% compared to those relying solely on pre-deployment audits, according to industry data compiled by Zealynx Security.
The economics of AI-driven vulnerability exploitation favor attackers. Mythos discovered a 27-year-old OpenBSD bug for under $50 in compute. Converting a known Linux vulnerability into a working exploit cost approximately $2,000 — a task that traditionally required weeks of specialist labor.
CrowdStrike's 2026 Global Threat Report noted AI-assisted attacks are up 89% year-over-year. The cost curve for offense is declining faster than the cost curve for defense:
For DeFi protocols, the math is straightforward. The value at risk ($200B+ in TVL) divided by the cost to scan it ($50–$2,000 per vulnerability) produces an attack surface with unprecedented return-on-investment for adversaries. This gap will widen as model capabilities improve and inference costs decline.
The $168.6 million lost in Q1 2026 across 34 protocols may look modest in hindsight if Mythos-class models — or their open-source successors — enter wider circulation before defensive tooling catches up.
Mythos Preview does not alter the fundamental architecture of DeFi security. It accelerates the timeline on which existing weaknesses become exploitable. The vulnerabilities it discovered — in cryptographic libraries, operating systems, and network protocols — were already present. What changed on April 7 is the cost and speed at which they can be found and weaponized.
The DeFi sector faces a structural mismatch: it is excluded from the primary defensive initiative (Project Glasswing), its codebases are public, and its defenses rely on mechanisms that Anthropic itself classifies as friction rather than barriers. The $200 billion in TVL represents the largest publicly auditable pool of smart-contract-secured value in existence.
The protocols that survive the Mythos era will be those that shift from point-in-time audits to continuous AI-driven security monitoring, that treat formal verification as a requirement rather than an option, and that invest in defensive AI tooling at a rate commensurate with the offensive capability now demonstrated. The data does not support waiting.