Several of the largest U.S. banks are hastening repairs to weaknesses in their IT systems after Anthropic’s AI tool Mythos revealed hundreds — and in some cases thousands — of previously hidden vulnerabilities. These discoveries are prompting urgent software updates and system fixes, which may lead to temporary service disruptions for customers.
Who has access and how is information shared?
Multiple large U.S. lenders — including JPMorgan Chase, Goldman Sachs, Citigroup, Bank of America and Morgan Stanley — already have access to Mythos. The big banks are informing smaller financial institutions about the vulnerabilities they find so those institutions can prepare their own IT networks even if they do not directly access the tool.
What Mythos does and why it pressures banks
Mythos is notable for chaining together low-risk, standalone vulnerabilities into more complex, high-risk attack vectors. The tool uncovers relationships and paths far faster than human analysts typically can. It is also effective at finding bugs in both bespoke (proprietary) and open-source software. This capability increases pressure on banks to replace or update unsupported and aging systems more quickly.
Faster remediation timelines and operational impacts
A key challenge is the acceleration of remediation timelines: certain security holes now need to be fixed within days, whereas similar fixes previously might have taken weeks. The increased workload means banks may need to take systems offline more frequently for maintenance or patching. Affected institutions say they are trying to minimize customer inconvenience while carrying out these urgent updates.
Costs and access considerations
Mythos uses token-based pricing: one million input tokens cost $25, while one million output tokens cost $125. The article notes that this pricing is five times the cost of Anthropic’s more widely available flagship model, Opus 4.7. High fees pose a particular barrier for smaller banks. To offset this, Anthropic has offered a $100 million credit line to partners and released Claude Security, a tool intended to make vulnerability assessments more broadly accessible.
Early practitioner experience and preparation
Adam Meyers of CrowdStrike — a member of Anthropic’s Project Glasswing partner program — said his team spent a full weekend after gaining access developing a methodology for using Mythos effectively before they even began searching for bugs. A banking regulator quoted in the coverage said the tool’s performance meets expectations, particularly in uncovering links that would take human analysts much longer to discover.
Why this matters
The vulnerabilities Mythos exposes and the speed of those discoveries are accelerating bank IT modernization and may cause short-term operational disruptions. Over the longer term, the work could improve systemic security if institutions can absorb the costs and meet the faster remediation demands.
Related event
The topic will be covered in the cybersecurity session of the Financial IT conference on May 28, 2026, which will address the banking sector’s digital trajectory and the impact of AI.


