Anthropic's Mythos found 10,000+ critical bugs in one month — 271 in Firefox alone
Anthropic's Mythos AI found more than 10,000 high-or-critical vulnerabilities across partner software in its first month — 271 in Firefox 150 alone, ten times the count from Firefox 148 testing — with Cloudflare reporting fewer false positives than human-led audits. A machine reaching 10x the bug count of manual review at lower noise marks a concrete capability threshold; Anthropic's plan to extend Mythos to US and allied government systems, pending stronger safeguards, signals this is being treated as critical infrastructure security.
Source: anthropic.com ↗
AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.
Anthropic
Why this matters
- → AI models now find vulnerabilities faster than humans—Mythos discovered 271 bugs in Firefox 150 versus 27 in Firefox 148, a tenfold jump that exposes critical infrastructure risk.
- → The same capabilities enable both attack and defense; without safeguards, adversaries gain asymmetric advantage in exploiting flaws across operating systems and web browsers.
- → Bugs like a 27-year-old OpenBSD flaw and 16-year-old FFmpeg vulnerability survived decades of human and automated review, showing AI reaches security blindspots humans miss.
AI's dual edge