Anthropic's Mythos AI Model Identifies 23,000 Vulnerabilities in 1,000 Open Source Projects

iconCryptoBriefing
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
Anthropic's Mythos AI model uncovered 23,000 vulnerabilities in 1,000 open source projects, with 1,726 confirmed as real, including over 1,000 high or critical issues. The scan, part of Project Glasswing, found a 27-year-old flaw in OpenBSD and bugs in major OS and browsers. Released in late May 2026, the results followed a blog post on Mythos' capabilities. With a 7.5% true positive rate, the model shows strong potential for open interest analysis in security. Value investing in crypto remains cautious amid such findings.

An AI model just did what decades of human auditors couldn’t. Anthropic’s Claude Mythos Preview flagged over 23,000 potential vulnerabilities across more than 1,000 open source software projects, and external reviewers confirmed that a meaningful chunk of them are the real deal.

Of those 23,000 flags, independent security firms validated 1,726 as genuine vulnerabilities. More than 1,000 of those confirmed flaws were rated high or critical severity.

Advertisement

What Mythos actually found

The scan, conducted as part of Anthropic’s broader Project Glasswing initiative, targeted a wide swath of critical software. The goal: use semi-autonomous AI scanning to find vulnerabilities that traditional methods have missed for years.

One of the most striking discoveries was a flaw in OpenBSD that had been lurking undetected for 27 years. OpenBSD is an operating system that specifically markets itself on security.

The Mythos model uncovered issues across every major OS and web browser in its scan. Anthropic released these findings in late May 2026, building on an April blog post that first detailed the Mythos model’s capabilities.

Why crypto should be paying attention

None of the 23,000 flagged vulnerabilities directly reference cryptocurrency tokens or specific blockchain protocols. The vast majority of crypto infrastructure runs on open source software. Node clients, wallets, bridges, DeFi protocols, and exchanges all depend on libraries, operating systems, and networking stacks that fall squarely within the scope of what Mythos scanned.

The confirmation rate is also worth noting. Out of 23,000 flags, 1,726 were verified, roughly a 7.5% true positive rate. That’s quite high for automated scanning at this scale.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.