On April 7, 2026, Anthropic disclosed that its unreleased Claude Mythos Preview model had autonomously discovered thousands of zero-day vulnerabilities across every major operating system, web browser, and cryptographic library — including TLS, AES-GCM, and SSH implementations that underpin $68 b...
"We should be planning for a world where, within six months to 12 months, capabilities like this could be broadly distributed or made broadly available, not just by companies in the United States." — Logan Graham, Offensive Cyber Research Lead, Anthropic
On April 7, 2026, Anthropic disclosed that its unreleased Claude Mythos Preview model had autonomously discovered thousands of zero-day vulnerabilities across every major operating system, web browser, and cryptographic library — including TLS, AES-GCM, and SSH implementations that underpin $68 billion in Ethereum total value locked and $200 billion across all DeFi chains. The model achieved a 72.4% exploit success rate, up from near-zero in predecessor models, and found bugs dating back 27 years at compute costs under $50 per vulnerability.
Three days later, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell convened an emergency meeting with CEOs from Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs to assess systemic risk. Anthropic has restricted Mythos to 12 launch partners under Project Glasswing, backed by $100 million in usage credits and $4 million in direct donations to open-source security organizations. No DeFi protocol, blockchain project, or wallet company is among those partners.
Claude Mythos Preview, a general-purpose frontier model not yet publicly released, discovered zero-day vulnerabilities in production software that had evaded human researchers and automated scanning tools for decades. According to Anthropic's 170-page System Card:
Emanuel Salmona, cofounder and CEO of Nagomi Security, characterized the scope: "Mythos found critical vulnerabilities across every major operating system and browser — some of them decades old — in weeks."
Over 99% of the zero-days discovered remained unpatched at the time of disclosure, according to Anthropic's technical assessment.
The gap between Mythos Preview and its predecessor models is not incremental. It is categorical.
| Benchmark | Opus 4.6 | Mythos Preview | |-----------|----------|----------------| | Firefox 147 working exploits | 2 | 181 (+29 with register control) | | OSS-Fuzz tier-5 results (7,000 entry points) | 1 | 10 (on fully patched targets) | | CyberGym accuracy | 66.6% | 83.1% | | Exploit success rate (overall) | Near-zero | 72.4% |
On manual review, 89% of 198 findings matched contractor severity ratings. 98% fell within one severity level. The model did not merely find bugs. It built working exploits autonomously, including a 20-gadget return-oriented programming (ROP) chain for the FreeBSD NFS vulnerability.
Mythos discovered implementation flaws in three cryptographic protocols that form the transport-layer security backbone for virtually all blockchain infrastructure:
The crypto industry's reliance on these protocols is total. Every RPC call, every front-end interaction, every validator communication passes through TLS. Every hardware wallet backup encrypted at rest uses AES. Every cloud-hosted node is administered via SSH.
As the PostQuantum analysis noted: "If AI can find implementation flaws in battle-tested crypto libraries, it will certainly find them in newer PQC implementations with months rather than decades of scrutiny."
Anthropic's disclosure highlighted a structural vulnerability in how DeFi protocols defend themselves. The company stated that "mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries."
Three core DeFi defense mechanisms fall into this category:
The numbers underscore the stakes. Ethereum alone holds $68 billion in TVL as of April 2026. Aave approaches $50 billion. DeFi lending protocols collectively exceed $55 billion. Crypto losses totaled $3.4 billion in 2025, with $1.4 billion from the Bybit exchange hack alone — 44% of the year's total. Q1 2026 has already logged $168.6 million in losses.
The majority of 2025 losses came from operational failures — stolen keys, social engineering — not on-chain code exploits. Mythos collapses the distinction. An AI that can find implementation bugs in SSH and TLS turns infrastructure compromise into a code problem, not a human problem.
Anthropic restricted Mythos Preview to a coalition of 12 organizations under Project Glasswing:
Additionally, over 40 critical-software maintainers received access. Anthropic committed $100 million in Mythos Preview usage credits and $4 million in direct donations to open-source security organizations.
No blockchain foundation, DeFi protocol, crypto exchange, wallet provider, or Web3 security firm is among the launch partners. The Ethereum Foundation, Solana Foundation, Coinbase, Binance, OpenZeppelin, Trail of Bits, and Hyperliquid — all absent. This omission is notable given that $200 billion in smart-contract-locked value depends on the same cryptographic infrastructure Mythos has already proven it can compromise.
Anthropic has committed to publishing a public report within 90 days of the launch — early July 2026 — covering fixes, lessons learned, and disclosable vulnerabilities.
The emergency meeting convened by Treasury Secretary Bessent and Fed Chair Powell on April 10 included CEOs from five systemically important banks: Citigroup, Morgan Stanley, Bank of America, Wells Fargo, and Goldman Sachs, according to Bloomberg.
Regulators framed Mythos as a potential catalyst for systemic financial events, not merely a technological challenge. Anthropic had consulted with U.S. officials before the disclosure regarding both defensive and offensive capabilities. The company is simultaneously engaged in a legal dispute with the Pentagon, which designated Anthropic a supply-chain risk.
Cynthia Kaiser, former senior FBI cyber official and now senior VP at Halcyon, stated: "The wannabes, this undercurrent of people who have not been capable of doing these operations just a year ago, now have some of the most powerful tools ever known to humankind in their hands."
Casey Ellis, founder of Bugcrowd, framed the asymmetry: "A defender needs to be right all the time, whereas an attacker only needs to be right once."
Markets have not priced in the Mythos threat. The CoinDesk DeFi Select Index gained 7% in the 24 hours following the April 7 disclosure, outperforming both Bitcoin and Ether. No major DeFi protocol has announced emergency security reviews or governance proposals in response.
Hyperliquid allocated $29 million to a policy center. The Ethereum Foundation staked 70,000 ETH (~$143 million) rather than redirecting resources to security infrastructure. The disconnect between the disclosed threat level and the industry response is significant.
Anthropic estimates that comparable AI capabilities could become broadly available within 6 to 18 months — whether from U.S. companies, foreign state actors, or open-source reproductions. Spencer Whitman, chief product officer at Gray Swan AI Security, noted that smaller models may achieve comparable results with better prompting, suggesting the timeline could compress further.
Charlie Eriksen, a security researcher at Aikido Security, stated: "Anybody with a computer can develop very powerful offensive cyber capabilities in a short amount of time, without needing a lot of expertise."
Jonathan Iwry, a fellow at the Wharton Accountable AI Lab, raised the governance question: "The most striking aspect of this situation is how reliant we are on the judgment of a handful of private actors who aren't accountable to the public."
The implication for DeFi is direct. Protocols that rely on friction-based defenses — multisig, timelocks, single-contract audits — have a finite window to upgrade their security posture before AI-assisted exploitation becomes commoditized.
The Mythos disclosure is not a theoretical exercise. It is a demonstrated capability with published benchmarks, third-party validation, and a government-level response. The model found decades-old bugs in hardened production code at trivial cost. It built working exploits autonomously. It compromised the cryptographic libraries that DeFi infrastructure depends on.
The DeFi industry's response — silence and a 7% price rally — reflects either informed confidence or uninformed complacency. The data does not support the former. No protocol has been tested. No blockchain security firm has access. No emergency governance proposals have been submitted.
The 6-to-18-month clock is running. When comparable capabilities reach adversarial actors — state-sponsored or otherwise — the $200 billion question is whether DeFi's security model will have upgraded from friction to hard barriers. The current evidence suggests it will not.