← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Mythos AI Exposes 00B DeFi Security Gap

Zephyra|April 10, 2026|BPF
EXECUTIVE SUMMARY

Anthropic's Claude Mythos Preview, a frontier AI model disclosed on April 7, 2026, has autonomously identified thousands of zero-day vulnerabilities across every major operating system, web browser, and — critically for the $94 billion DeFi sector — in the cryptography libraries underpinning TLS,...

"More powerful models are going to come from us and from others, and so we do need a plan to respond to this." — Dario Amodei, CEO, Anthropic

Executive Summary

Anthropic's Claude Mythos Preview, a frontier AI model disclosed on April 7, 2026, has autonomously identified thousands of zero-day vulnerabilities across every major operating system, web browser, and — critically for the $94 billion DeFi sector — in the cryptography libraries underpinning TLS, AES-GCM, and SSH. The model reproduced and exploited vulnerabilities on the first attempt in 83.1% of cases, found a 27-year-old bug in OpenBSD for under $50 in compute, and converted known Linux flaws into working exploits for under $2,000 in less than a day.

Anthropic has restricted Mythos from public release under Project Glasswing, a defensive cybersecurity program shared with 12 launch partners — including Amazon Web Services, Apple, Google, Microsoft, and JPMorgan Chase — backed by $100 million in usage credits. The company estimates competing models with similar capabilities could emerge within 6 to 18 months. For approximately $200 billion in smart contract capital spread across Ethereum, Solana, and other chains, the security implications are immediate. The defenses DeFi relies on — multisig governance, timelocks, and audit reports — are what Anthropic classifies as "friction-based" mitigations, which "may become considerably weaker against model-assisted adversaries."

Table of Contents

  1. What Mythos Preview Can Do
  2. The Numbers: Capability Benchmarks
  3. Why DeFi Is Exposed
  4. Project Glasswing: Structure and Access
  5. DeFi's Existing Loss Record
  6. The Governance Speed Problem
  7. Market Response
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

What Mythos Preview Can Do

Claude Mythos Preview is a general-purpose frontier model that Anthropic did not explicitly train for security tasks. The vulnerability-discovery capability, according to Anthropic's red team disclosure, "emerged as a downstream consequence of general improvements in code, reasoning, and autonomy." The same improvements that make the model more effective at patching vulnerabilities also make it more effective at exploiting them.

Specific findings disclosed by Anthropic's Frontier Red Team:

  • OpenBSD TCP SACK vulnerability (27 years old): A remote denial-of-service flaw in TCP sequence number handling, discovered for under $50 in a single compute run; total cost across a thousand evaluation runs was approximately $20,000.
  • FFmpeg H.264 codec flaw (16 years old): A 65,536-slice collision vulnerability originating from a 2003 commit, which became exploitable following a 2010 code change. This bug had been scanned approximately 5 million times by automated security tools without detection.
  • FreeBSD NFS server exploit (CVE-2026-4747, 17 years old): A stack buffer overflow in the RPCSEC_GSS authentication protocol granting unauthenticated remote root access. Mythos autonomously constructed a 20-gadget ROP chain split across six sequential RPC packets.
  • Web browser exploits: The model created a browser exploit chaining four separate vulnerabilities, writing a JIT heap spray that escaped both renderer and OS sandboxes. Vulnerabilities were identified in every major browser.
  • Cryptography library flaws: Weaknesses found in TLS, AES-GCM, and SSH implementations that could enable certificate forgery or private communication decryption. Over 99% of the vulnerabilities Anthropic found remain unpatched.
  • Memory-safe VMM exploit: A memory corruption vulnerability discovered in a production Rust-based virtual machine monitor, demonstrating that memory-safe languages do not eliminate all attack surfaces.

Logan Graham, head of Anthropic's Frontier Red Team, stated: "It's very clear to us that we need to talk publicly about this. The security industry needs to understand that these capabilities may come soon."

The Numbers: Capability Benchmarks

Mythos Preview represents a step-change from Anthropic's prior generation model, Opus 4.6, which had a "near-0% success rate at autonomous exploit development."

| Benchmark | Mythos Preview | Opus 4.6 | |---|---|---| | CyberGym (vulnerability reproduction) | 83.1% | 66.6% | | Firefox JS engine exploits (out of several hundred attempts) | 181 | 2 | | OSS-Fuzz crashes (tiers 1-2, across 7,000 entry points) | 595 | ~250-275 | | Full control flow hijack (tier 5) | 10 | 1 | | SWE-bench Verified | 93.9% | 80.8% | | SWE-bench Pro | 77.8% | 53.4% | | Terminal-Bench 2.0 | 82.0% | 65.4% |

The model's human validation rate is notable: of 198 manually reviewed vulnerability reports, 89% matched the model's severity assessment exactly. 98% were within one severity level. Engineers at Anthropic with no formal security training asked Mythos to find remote code execution vulnerabilities overnight and had complete working exploits by morning.

Why DeFi Is Exposed

Approximately $200 billion sits in smart contracts across Ethereum, Solana, and other chains — capital protected by a security stack that Anthropic's findings directly challenge. Aggregate DeFi TVL stood at $94 billion as of early April 2026, with Ethereum holding roughly 68% of the total at $68 billion.

DeFi's core security mechanisms are what Anthropic terms "friction-based" defenses:

  • Multisig governance: Requires multiple key holders to approve transactions. Slows attackers but does not patch underlying code flaws.
  • Timelocks: Impose delays on transactions. Provides response windows measured in hours or days. Mythos compresses attack preparation from months to hours.
  • Audit reports: Static point-in-time assessments of individual contracts. Mythos can analyze entire call graphs across interacting protocols, identifying cross-contract semantic vulnerabilities — historically the source of the largest exploits.

Anthropic's disclosure stated: "Mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries."

The open-source nature of most DeFi protocol code amplifies the risk. A model with Mythos-class capabilities can autonomously catalog every weakness in a publicly readable codebase at machine speed and near-zero marginal cost. Traditional security audits examine single contracts in isolation; Mythos analyzes dependency chains across the entire DeFi stack.

Project Glasswing: Structure and Access

Anthropic is distributing Mythos exclusively through Project Glasswing, a restricted cybersecurity program. The structure:

  • 12 launch partners: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, and Anthropic.
  • Expanded access: 40+ additional organizations focused on critical infrastructure.
  • Funding: $100 million in Claude Mythos Preview usage credits for partners; $2.5 million to Alpha-Omega and OpenSSF via the Linux Foundation; $1.5 million to the Apache Software Foundation.
  • Pricing (post-preview): $25 per million input tokens; $125 per million output tokens, available via Claude API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry.
  • Disclosure timeline: 90-day reporting period for publicly disclosable findings. Anthropic published SHA-3 hash commitments for undisclosed vulnerabilities in web browsers, operating systems, cryptography libraries, and firmware systems.

No DeFi-specific protocol or blockchain security firm appears on the launch partner list. JPMorgan Chase is the sole financial institution.

DeFi's Existing Loss Record

The DeFi sector enters this AI-capability era with a significant historical loss baseline:

  • 2025: $3.4 billion in cryptocurrency stolen, according to Chainalysis. North Korean-linked hackers accounted for $2.02 billion, a 51% year-over-year increase, pushing their cumulative total to $6.75 billion. The $1.5 billion Bybit exchange hack represented 44% of the annual total.
  • Q1 2026: $168.6 million stolen across 34 DeFi protocol incidents, according to CoinTelegraph, a decline from Q1 2025. The $285 million Drift Protocol exploit on Solana in April 2026 — attributed to North Korean hackers — involved social engineering, oracle manipulation, and a governance exploit executed in 12 minutes.

Social engineering has replaced code exploits as the dominant attack vector in recent years. Mythos-class models threaten to shift this balance back toward autonomous code exploitation at a scale and speed that existing defense infrastructure was not designed to handle.

The Governance Speed Problem

A structural mismatch exists between AI-compressed attack timelines and DeFi governance response times. DeFi protocols typically operate governance mechanisms on multi-day cycles — proposal submission, voting periods, timelock execution. Mythos compresses vulnerability filtering that previously took human researchers months into approximately six hours, according to analysis published by ChainCatcher on April 9, 2026.

The concentration of critical DeFi infrastructure creates additional attack surface. On Ethereum, 28% of staked ETH is concentrated in Lido's stETH contract. One pseudonymous security researcher cited by ChainCatcher noted: "You don't need to burn down the whole city; you just need to make the oxygen briefly disappear for two minutes at the most critical moment."

Code immutability — a core property of deployed smart contracts — prevents retroactive fixes post-discovery. Once Mythos-class models identify a vulnerability in a deployed, immutable contract, the only remediation options are migration or proxy-pattern upgrades, both of which require governance action on the multi-day timelines that AI-speed attacks can outrun.

Market Response

The market has not priced in the Mythos disclosure. The CoinDesk DeFi Select Index gained 7% in the 24 hours following the announcement, attributed to Middle East ceasefire optimism rather than Mythos-related concerns.

DeFi yields have simultaneously compressed to levels below traditional finance: Aave offers approximately 2.61% APY on USDC across $8.5 billion in combined USDT/USDC deposits on Ethereum, below Interactive Brokers' 3.14% on idle cash and well below the 4.00%-5.00% APY available from high-yield savings accounts. The risk-return proposition for DeFi depositors — already under pressure — faces further deterioration if AI-driven exploit risk is priced into the equation.

Key Takeaways

  • Mythos Preview exploits vulnerabilities at 83.1% first-attempt success rate. Prior-generation models achieved near-0%. The capability was not explicitly trained; it emerged from general improvements in coding and reasoning.
  • Cryptography libraries used by DeFi infrastructure contain unpatched flaws. Over 99% of vulnerabilities found by Mythos remain unpatched. Weaknesses in TLS, AES-GCM, and SSH could enable certificate forgery or communication decryption.
  • DeFi's security model relies on friction, not hard barriers. Multisig, timelocks, and audits slow attackers but do not fix underlying code. These mechanisms "may become considerably weaker against model-assisted adversaries," per Anthropic.
  • No DeFi protocol or blockchain security firm is a Glasswing partner. The 12 launch partners include major tech companies and JPMorgan Chase. DeFi-native security infrastructure is not directly benefiting from Mythos-driven defensive work.
  • Competing models with similar capabilities are expected within 6-18 months. The defensive window is narrow. Anthropic's decision to restrict public access delays but does not prevent capability proliferation.
  • DeFi's $3.4 billion in 2025 losses occurred without AI-assisted exploitation. The sector's loss record under human-speed attacks provides a baseline that AI-speed exploitation could significantly exceed.

Conclusion

Anthropic's Mythos Preview represents a measurable shift in the cost-capability curve for software vulnerability discovery and exploitation. The model finds decades-old bugs for under $50 in compute, builds working exploits overnight without human intervention, and succeeds on first attempt more than four-fifths of the time. These capabilities were not purpose-built — they emerged from general model improvements, meaning every competing frontier AI lab is on the same trajectory.

For DeFi, the implications are structural. The sector's $94 billion in TVL is protected by friction-based defenses designed for human-speed adversaries. Mythos compresses attack preparation timelines from months to hours. Protocol governance operates on multi-day cycles. Smart contract immutability prevents retroactive patching. And the open-source codebase that enables DeFi's transparency simultaneously enables comprehensive automated vulnerability mapping.

The absence of any DeFi-native organization from Project Glasswing's partner list means the sector's defensive infrastructure is not directly positioned to benefit from Mythos-class capabilities in the near term. Whether the blockchain security industry can develop AI-native defenses before Mythos-class models proliferate — within Anthropic's estimated 6-to-18-month window — will determine whether DeFi's smart contract capital faces a fundamentally different risk environment.

As Dario Amodei stated: "The dangers of getting this wrong are obvious, but if we get it right, there is a real opportunity to create a fundamentally more secure internet and world than we had before the advent of AI-powered cyber capabilities." For DeFi, the clock is running on which outcome materializes first.

Sources & References

  1. Anthropic — Claude Mythos Preview Red Team Disclosure — Full technical disclosure of Mythos Preview capabilities, benchmarks, and vulnerability findings
  2. Anthropic — Project Glasswing — Program structure, partner list, funding commitments, and access details
  3. CoinDesk — Anthropic's Mythos AI Could Have Major Implications for DeFi — DeFi-specific risk analysis (April 8, 2026)
  4. Euronews — Why Anthropic's Most Powerful AI Model Is Too Dangerous for Public Release — Dario Amodei and Logan Graham quotes, containment incident (April 8, 2026)
  5. The Hacker News — Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws — Technical vulnerability summary (April 2026)
  6. Chainalysis — 2025 Crypto Theft Reaches $3.4 Billion — Annual crypto hack statistics
  7. CoinTelegraph — Crypto Hackers Steal $168 Million from DeFi Protocols in Q1 2026 — Q1 2026 DeFi exploit data
  8. ChainCatcher — How Long Can the Ethereum Ecosystem Survive After Mythos? — Governance speed analysis, Lido concentration risk (April 9, 2026)
  9. CoinDesk — DeFi Yields Are Crashing Below Savings Account Rates — Aave yield data, risk-return analysis (April 7, 2026)
  10. Axios — Anthropic Withholds Mythos Preview Model — Restriction rationale and competing model timeline (April 7, 2026)