Anthropic's Claude Mythos Preview, released April 7 under restricted access, has autonomously discovered thousands of zero-day vulnerabilities across every major operating system, browser, and cryptographic library — including the TLS, AES-GCM, and SSH protocols that underpin DeFi wallet infrastr...
"Anyone have good Anthropic connect. We would love to test mythos on Uniswap." — Hayden Adams, Founder, Uniswap
Anthropic's Claude Mythos Preview, released April 7 under restricted access, has autonomously discovered thousands of zero-day vulnerabilities across every major operating system, browser, and cryptographic library — including the TLS, AES-GCM, and SSH protocols that underpin DeFi wallet infrastructure, multisig governance, and node communication. The model generated working exploits 72.4% of the time, up from near-zero for prior AI models. It found a 27-year-old bug in OpenBSD for under $50 in compute and a 16-year-old flaw in FFmpeg missed across 5 million automated security scans.
The implications for $200 billion in DeFi total value locked are immediate. On April 10, Treasury Secretary Scott Bessent and Fed Chair Jerome Powell convened an emergency meeting with CEOs of five systemically important banks — Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs — to address AI-driven cyber risk. Anthropic committed $100 million in usage credits and $4 million in direct donations to open-source security organizations under Project Glasswing, a controlled disclosure program involving 40 technology and financial firms. Over 99% of vulnerabilities discovered by the model remain unpatched.
This report examines how Mythos reshapes the threat model for DeFi protocols, quantifies the security gap between current audit practices and AI-driven exploitation capabilities, and assesses what the industry's response signals about the maturity of onchain security infrastructure.
Anthropic published Mythos Preview's technical benchmarks on April 7 via red.anthropic.com. The data describes a step-function improvement over prior models:
Firefox 147 JavaScript engine exploitation: Mythos Preview achieved 181 working exploits versus 2 for Claude Opus 4.6 across several hundred attempts, with 29 additional runs achieving register control. Human penetration testers estimated comparable exploits would require weeks to develop.
OSS-Fuzz corpus (7,000 entry points): Mythos Preview produced 595 tier-1/2 crashes and reached tier-5 (full control flow hijack) on 10 separate targets. Claude Sonnet 4.6 and Opus 4.6 each achieved tier-5 on a single target.
CyberGym accuracy: 83.1% for Mythos versus 66.6% for Claude Opus 4.6.
Cost structure: The model found a 27-year-old TCP SACK denial-of-service vulnerability in OpenBSD — an OS designed specifically for security — for under $50 per successful run, totaling approximately $20,000 across 1,000 scaffold runs. A 16-year-old FFmpeg H.264 integer overflow was discovered for roughly $10,000. Linux kernel privilege escalation chains were developed for under $1,000 in under half a day.
Professional human security contractors reviewed 198 of the model's findings. In 89% of cases, contractors assigned identical severity ratings. In 98% of cases, assessments fell within one severity level.
Anthropic stated: "We did not explicitly train Mythos Preview to have these capabilities. Rather, they emerged as a downstream consequence of general improvements in code, reasoning, and autonomy."
The DeFi-specific risk centers on Mythos's demonstrated ability to identify weaknesses in TLS, AES-GCM, and SSH — the exact protocols that MPC (multi-party computation) and multisig wallet implementations rely on for key management, transaction signing, and node communication.
According to Anthropic's system card, "mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries."
This language applies directly to the DeFi security stack. Multisig governance, timelocks, and third-party audit reports are friction-based mechanisms. They increase the cost and time required for attacks. They do not eliminate the attack surface. When the cost of discovering and chaining exploits drops from months of expert labor to hours of compute at under $2,000, the calculus changes.
Ethereum holds $68 billion in TVL as of April 2026, according to ChainCatcher, with 28% of staked ETH concentrated in the Lido protocol. stETH functions as critical infrastructure across DeFi lending and liquidity markets. A vulnerability in the cryptographic layer beneath these systems — not the smart contracts themselves, but the transport and signing protocols they depend on — would create cascading risk across the composability stack.
Traditional DeFi security relies on a layered approach: formal verification of individual smart contracts, third-party audits, bug bounties, multisig governance with timelocks, and community monitoring. Each layer adds friction. The cumulative friction was, until now, sufficient to keep all but the most sophisticated state-sponsored attackers at bay.
Mythos compresses the attacker's timeline. According to analysis published by ChainCatcher, the model can reduce vulnerability analysis that takes humans months to complete into hours. Critically, Mythos analyzes entire call graphs — the full chain of contract interactions — rather than individual contracts in isolation. Traditional audits, by contrast, are typically scoped to single contracts or small contract sets.
This means the model can identify cross-contract semantic vulnerabilities that auditors miss. The leading AI models now crack 55% of smart contract exploits, up from 2% one year ago, according to data cited by Bankless.
The governance response gap compounds the problem. Decentralized protocols route security decisions through token-holder voting, multisig approval chains, and timelock delays. When attack preparation time compresses from weeks to hours, governance mechanisms designed for deliberation become the slowest link in the defense chain.
The $285 million Drift Protocol exploit on April 1, 2026 — three days before the Mythos release — illustrates how human-level attacks already overwhelm friction-based defenses. TRM Labs attributed the hack to UNC4736, a North Korean state-sponsored group. Attackers deposited $1 million in initial capital and spent six months on intelligence gathering before executing.
The critical vulnerability was not a smart contract bug. Attackers socially engineered multisig signers into pre-signing hidden authorizations and exploited a zero-timelock Security Council migration. The result: Solana TVL dropped $1 billion in a day, Drift's TVL fell from $550 million to under $250 million, and SOL declined approximately 10%.
Drift required state-level resources and half a year of preparation. Mythos's demonstrated capability — chaining 2-4 vulnerabilities per exploit autonomously, without human intervention after an initial prompt — suggests comparable or more complex attack chains could be assembled at a fraction of the cost and time.
Project Glasswing: Anthropic restricted Mythos Preview to 40 partner organizations including AWS, Apple, Google, Microsoft, JPMorgan Chase, NVIDIA, Cisco, CrowdStrike, and the Linux Foundation. The company committed $100 million in usage credits and $4 million in direct donations to open-source security organizations. Anthropic plans to publish findings on vulnerabilities identified and resolved within 90 days.
Federal response: On April 10, Treasury Secretary Scott Bessent and Fed Chair Jerome Powell convened CEOs of Citigroup (Jane Fraser), Morgan Stanley (Ted Pick), Bank of America (Brian Moynihan), Wells Fargo (Charlie Scharf), and Goldman Sachs (David Solomon) at Treasury headquarters. JPMorgan's Jamie Dimon did not attend. The meeting addressed AI-driven cyber risk to systemically important financial infrastructure. According to CoinDesk, the episode "highlights a fundamental change in how regulators are framing AI risk, not merely as a technological challenge, but as a potential catalyst for systemic events."
Pentagon involvement: The Department of Defense has designated Anthropic as a supply-chain risk, though this classification is currently contested in court.
Protocol-level response: Uniswap founder Hayden Adams publicly requested access to Mythos for protocol testing. Hyperliquid invested $29 million in its policy center. These are early, ad hoc responses. No standardized framework for AI-driven security assessment exists in DeFi.
The financial mismatch between DeFi losses and insurance coverage is stark. Crypto losses to hacks totaled $3.4 billion in 2025. Q1 2026 added $168.6 million from 34 protocol exploits. Against this, Nexus Mutual — the largest DeFi insurance protocol — has paid out $18.6 million across its entire history. As of late 2022, approximately 1% of DeFi TVL carried insurance coverage. Current capacity per vault on newer products like Covered Vaults tops out at $50 million.
DeFi lending protocols carry $55 billion in TVL, with Aave alone at approximately $50 billion. Typical yields of 2-4% APY in Morpho vaults may not adequately compensate for tail risk. Analysis by M0's founder suggests 2.5-4% annual premium would represent fair compensation for lending risk — a figure that, if priced into yields, would push net returns to zero or negative for many strategies.
When the cost of identifying exploitable vulnerabilities drops to thousands of dollars, the economic incentive for attacks scales. The insurance industry's capacity has not kept pace with loss severity, and the Mythos disclosure widens the gap further.
What changes: The cost floor for vulnerability discovery has collapsed. Single-contract audits are no longer sufficient as a security standard. Friction-based defenses — the backbone of DeFi security — face an adversary that treats friction as a solvable optimization problem. AI-driven continuous auditing will likely become a prerequisite for institutional DeFi participation.
What doesn't change: Smart contract risk is still the responsibility of protocol teams. Code quality, formal verification, and defense-in-depth retain value. The economic logic of DeFi — transparent, permissionless financial infrastructure — remains intact. The question is whether security infrastructure can scale to match the threat.
Anthropic noted that AI models have reached "a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities." The defensive application of this capability — AI-powered continuous auditing, real-time threat detection, and automated patching — is available to the same organizations that face the threat. The asymmetry lies in adoption speed.
Mythos Preview represents a measurable shift in the economics of vulnerability discovery. The model did not introduce new theoretical risks to DeFi. It reduced the practical cost of exploiting existing risks by orders of magnitude. A 27-year-old bug found for $50. A privilege escalation chain built for $1,000 in half a day. An exploit success rate of 72.4% where prior models achieved near-zero.
The $200 billion question is not whether DeFi can survive AI-powered adversaries — the same AI capabilities serve defense as well as offense. The question is whether the decentralized governance structures that manage protocol upgrades, security patches, and risk parameters can operate at the speed AI-driven threats demand. The Drift exploit showed that even six months of human preparation can overwhelm multisig governance. Mythos compresses that timeline to hours.
Project Glasswing's 90-day disclosure window provides a finite buffer. After that, the vulnerability dataset becomes a race condition: patched systems versus unpatched systems, protocols with AI-driven security versus those relying on annual audits. The data suggests this is not a future problem. It is a current one, priced in compute at approximately $2,000 per exploit chain.