Anthropic says its Claude Mythos Preview model has identified and, in testing, demonstrated exploits for vulnerabilities in widely used cryptographic software implementations. The findings include weaknesses in libraries implementing TLS, AES-GCM and SSH, where implementation oversights could potentially enable certificate forgery or the decryption of communications. The work is a significant first-party example of an AI system being used in vulnerability research that reaches cryptographic and public-key infrastructure code.
In its April 7, 2026 assessment, Anthropic frames the work as a proof of concept under Project Glasswing, an initiative focused on defensive AI-assisted security research. The company is not presenting Mythos Preview as an operational attack tool or releasing the reported exploitation capabilities. Instead, it says it is following coordinated vulnerability disclosure processes and will publish further reports as fixes become available. The details appear in Anthropic's assessment of Claude Mythos Preview's cybersecurity capabilities.
The most important distinction is that Anthropic has reported weaknesses in implementations of cryptographic systems, not a demonstrated break of TLS, AES-GCM or SSH as underlying standards. That distinction matters. Cryptographic primitives and protocols can be designed to provide strong protections, while surrounding code can still introduce errors in validation, authentication, key handling or other security-critical behavior. An implementation flaw can therefore undermine the security properties that users expect from otherwise established technology.













