Claude Mythos is too dangerous for public consumption...
Fireship · 2026-05-02 · community · 1,104,216 views
What's in the video
Description written by Gemini, which watched and listened to the whole video.
Summary
Fireship presents an episode of The Code Report analyzing Anthropic's announcement of Claude Mythos Preview and Project Glasswing. The host examines the dramatic cybersecurity claims surrounding the withheld frontier model, details the high-profile vulnerabilities it uncovered, and discusses community skepticism regarding whether Anthropic is exaggerating risks for defensive hype and enterprise partnerships.
What is shown
- [00:05] Excerpts of Anthropic's announcement for Project Glasswing and Claude Mythos Preview, showing safety warnings and benchmark comparisons.
- [00:21] Social media reactions from developers and commentators (Theo, Ole Lehmann, Igor Brigadir, ThePrimeagen).
- [01:08] Title card for The Code Report (dated April 10, 2026).
- [01:39] Code snippets and technical descriptions of specific zero-day vulnerabilities discovered by Mythos:
- A 16-year-old H.264 slice count mismatch bug in FFmpeg causing heap out-of-bounds writes.
- A 27-year-old TCP SACK handling vulnerability in OpenBSD causing null-pointer writes and remote crashes.
- Cross-origin bypass and sandbox escape exploits in major web browser JavaScript engines.
- A Linux kernel KASLR bypass and memory-page bit flip enabling write access to
/usr/bin/passwdfor root privilege escalation.
- [02:40] News reports regarding US Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell warning banking CEOs about model risks.
- [02:59] Project Glasswing partner roster (including Apple, Google, Microsoft, CrowdStrike, AWS, Cisco, Linux Foundation, and JPMorgan Chase).
- [03:51] Technical counterarguments and caveats, highlighting that finding the OpenBSD bug required 1,000 parallel agents costing ~$20,000 in compute, and that Firefox testing targeted a harness without defense-in-depth sandboxing enabled.
- [04:47] Sponsor walkthrough for Browserbase and its open-source Stagehand SDK for browser agents.
Claims & numbers
- The presenter says Anthropic withheld Claude Mythos Preview from general availability due to risks that the fallout for economies, public safety, and national security could be severe.
- On SWE-bench Pro, Mythos Preview achieved 77.8% compared to Claude Opus 4.6 at 53.4%.
- On Firefox JS shell exploitation evaluations, Mythos Preview achieved an 84.0% success rate (72.4% full, 11.6% partial), compared to 15.2% for Claude Opus 4.6 and 4.4% for Sonnet 4.6.
- Anthropic committed up to $100M in usage credits and $4M in direct donations to open-source security organizations under Project Glasswing.
- The presenter notes Mythos has been used internally at Anthropic since February 24, 2026.
- The presenter reports that finding the OpenBSD vulnerability required 1,000 parallel agent runs across the codebase, costing nearly $20,000 in compute.
- The presenter points out that the 84% Firefox exploit rate targeted a SpiderMonkey testing harness without browser sandbox protections or defense-in-depth mitigations active.
Notable quotes
- [01:35] "During Anthropic's internal testing, they discovered that Mythos is basically a zero-day vending machine."
- [02:35] "I've found more bugs in the last couple of weeks than I found in the rest of my life combined." (Anthropic employee clip)
- [04:39] "It's a big club, and you ain't in it." (quoting George Carlin regarding Project Glasswing access)
Assessment
This is a tech commentary and news breakdown video combining humor, internet memes, and critical analysis of Anthropic's research report. The presenter accurately references real benchmarks and technical disclosures published by Anthropic while contextualizing the testing methodology and compute costs to temper hyperbolic marketing claims.
Described by gemini-3.8-flash on 2026-09-29 from the video's audio and frames.