Claude Mythos AI Built Working Exploits Across 50 Cloudflare Repos, Then Refused To Demo

Markets 2026-05-19 22:22

Claude Mythos AI Built Working Exploits Across 50 Cloudflare Repos, Then Refused To Demo

Cloudflare confirmed Monday that Anthropic's unreleased Mythos Preview model chained bugs into working exploits across more than 50 of its repositories.

Cloudflare Project Glasswing Findings

The disclosure came in a blog post from Cloudflare Chief Security Officer Grant Bourzikas, who said his team pointed Mythos Preview at production code spanning the runtime, edge data path and protocol stack. Cloudflare joined Project Glasswing, Anthropic's invite-only program for defensive security partners. Bourzikas called the model "a real step forward," citing two capabilities competitors lacked.

Mythos chained several small attack primitives into working proofs of concept. The model also compiled and ran exploit code in a scratch environment, then revised its hypothesis when a run failed.

The post also flagged inconsistent refusals from the preview model.

In one case, Mythos declined to write a demonstration exploit after confirming several memory bugs in a codebase, then complied when the same task was framed differently in a separate session.

Also Read: Crypto Funds Bleed $1.07B As Iran Tensions End Six-Week Inflow Run

Multi-Agent Harness Beats Solo Scanners

Cloudflare said pointing one generic coding agent at a repository did not work for vulnerability research. Bourzikas instead built a multi-stage harness running roughly 50 parallel agents on narrow tasks. The pipeline runs reconnaissance, hunting, adversarial validation, deduplication and reachability tracing.

An independent agent tries to disprove each finding before it enters the triage queue, cutting false positives that plague memory-unsafe code written in C and C++. Anthropic has committed $100 million in model credits and $4 million in donations to open-source security groups under Project Glasswing.

Mythos Preview will not be released publicly.

Crypto Smart Contracts Face AI Exploit Wave

The Cloudflare findings land as on-chain losses mount. The Verus-Ethereum bridge lost $11 million Monday in a cross-chain attack, with proceeds swapped into 5,402 Ether (ETH).

Anthropic researchers previously showed that AI agents could autonomously exploit live contracts at a profit. In one test, models scanned 2,849 deployed contracts and produced exploits worth $3,694 for $3,476 in compute.

CertiK warned on May 15 that legacy smart contracts now sit at the center of an AI-driven hunting wave. DeFi protocols lost more than $605 million across roughly 20 days in April, including the $293 million KelpDAO drain on Apr. 19. Social engineering took another $306 million across the first quarter.

Read Next: Iran Settles Hormuz Shipping Cover In Bitcoin, Eyes $10B Haul

Share to:

This content is for informational purposes only and does not constitute investment advice.

Curated Series

SuperEx Popular Science Articles Column

SuperEx Popular Science Articles Column

This collection features informative articles about SuperEx, aiming to simplify complex cryptocurrency concepts for a wider audience. It covers the basics of trading, blockchain technology, and the features of the SuperEx platform. Through easy-to-understand content, it helps users navigate the world of digital assets with confidence and clarity.

Unstaked related news and market dynamics research

Unstaked related news and market dynamics research

Unstaked (UNSD) is a blockchain platform integrating AI agents for automated community engagement and social media interactions. Its native token supports governance, staking, and ecosystem features. This special feature explores Unstaked’s market updates, token dynamics, and platform development.

XRP News and Research

XRP News and Research

This series focuses on XRP, covering the latest news, market dynamics, and in-depth research. Featured analysis includes price trends, regulatory developments, and ecosystem growth, providing a clear overview of XRP's position and potential in the cryptocurrency market.

How do beginners trade options?How does option trading work?

How do beginners trade options?How does option trading work?

This special feature introduces the fundamentals of options trading for beginners, explaining how options work, their main types, and the mechanics behind trading them. It also explores key strategies, potential risks, and practical tips, helping readers build a clear foundation to approach the options market with confidence.

What are the risks of investing in cryptocurrency?

What are the risks of investing in cryptocurrency?

This special feature covers the risks of investing in cryptocurrency, explaining common challenges such as market volatility, security vulnerabilities, regulatory uncertainties, and potential scams. It also provides analysis of risk management strategies and mitigation techniques, helping readers gain a clear understanding of how to navigate the crypto market safely.