Safety

Anthropic's Mythos Accelerates Zero-Day Discovery, Reshaping Cybersecurity Economics

Palo Alto Networks used Anthropic’s unreleased Mythos model and in three weeks reported uncovering over 20 critical low-level vulnerabilities—about five times the yield of traditional tools—at a token cost exceeding one million dollars.

Anthropic's Mythos Accelerates Zero-Day Discovery, Reshaping Cybersecurity Economics

Palo Alto Networks, a leading cybersecurity firm, was an early tester of Anthropic’s unreleased Mythos model. According to the company’s testing, the model surfaced more than 20 critical low-level vulnerabilities in three weeks — roughly five times the number traditional tools typically find in the same period.

What did it cost?

The compute used during those tests consumed more than one million dollars worth of tokens, which were spent over the course of weeks. Anthropic has set Mythos’s price at six times that of Opus 4.8. Following the news, Palo Alto Networks’ share price has risen by over 50% since April.

Practical implications

Historically, discovering a zero-day often required months of reverse engineering and manual analysis. Mythos appears to compress that timeline to days at scale, shifting the economics from uncertain payroll or consulting bills to a clearer compute-token expense — in this case, a roughly one-million-dollar token bill rather than a vague labor line item.

That acceleration benefits defenders, but it equally benefits attackers: the same model-driven speedup is available to any party that gains access to similar capabilities.

Open questions and criticism

Observers note a crucial missing metric: the false-positive rate. The number of false positives determines how well such automated findings scale in practice, because high false-positive rates impose significant human validation costs. Anthropic and testers have not published that rate publicly.

Bottom line

Spending to find vulnerabilities faster also confirms that the same models can find them for others. Many security leaders frame this spending not as a one-off budget line but as an ongoing entry fee into an accelerating arms race in cybersecurity.