You Actually Do Need to Understand Mythos
Hank Green · 2026-05-02 · community · 1,262,164 views
What's in the video
Description written by Gemini, which watched and listened to the whole video.
Summary
Hank Green discusses the implications of Anthropic's unreleased frontier model, Claude Mythos, specifically its unprecedented capabilities in autonomous cybersecurity exploitation and vulnerability detection. The video transitions into an in-depth remote interview with cybersecurity expert Sherri Davidoff (CEO of LMG Security) exploring zero-day vulnerabilities, the gap between discovery and patching, software monoculture risks, and the future of AI-assisted security.
What is shown
- [00:00] Hank Green introduces the background of AI news noise versus genuinely consequential developments.
- [01:19] Hank breaks down Anthropic's tiered model hierarchy (Haiku, Sonnet, Opus) and positions Claude Mythos as a new tier above Opus.
- [04:14] Hank details Claude Mythos's reported cybersecurity findings, including discovering a 27-year-old vulnerability in OpenBSD and chaining multiple exploits in Linux.
- [06:40] Hank outlines Project Glasswing, Anthropic's defensive vetting coalition providing controlled access to major cloud providers and open-source foundations.
- [09:32] Hank defines penetration testing ("pen testing") and introduces his collaborative book journal project, The Book of Good Times.
- [10:55] Remote interview between Hank Green and Sherri Davidoff begins.
- [11:12] A brief cutaway clip from Invader Zim ("Worse? Or better?") referenced by Davidoff.
- [16:49] News headlines shown on screen detailing the July 2021 Kaseya ransomware attack.
- [18:24] Davidoff discusses malicious AI tools like WormGPT and the risks of unchecked "vibe coding."
- [34:43] A screenshot of Microsoft's ProxyShell exchange server vulnerability disclosure blog.
- [48:43] A Wikipedia entry on the 2009–2010 Operation Aurora cyberattacks is displayed during the discussion.
- [50:18] Hank concludes the video with final reflections on the discussion.
Claims & numbers
- Hank states Claude Mythos is reported to have roughly 10 trillion parameters, though Anthropic has not officially confirmed the parameter count ([01:54]).
- On SWE-bench, Claude Opus scored 80% while Claude Mythos achieved 93.9%; on SWE-bench Pro, Opus scored 53% while Mythos scored 77% (Hank Green, [02:11]).
- Claude Mythos analyzed major operating systems and web browsers and identified thousands of previously unknown zero-day vulnerabilities (Hank Green, [04:25]).
- Claude Mythos uncovered an unpatched bug in OpenBSD that had existed for 27 years ([05:20]).
- Claude Mythos discovered multiple separate vulnerabilities in Linux and autonomously chained them together into a working privilege-escalation exploit (Hank Green, [05:25]).
- Anthropic created Project Glasswing to distribute defensive access to tech companies (Microsoft, Google, Apple, Amazon, CrowdStrike) and open-source entities (Linux Foundation, Apache Software Foundation), alongside $100 million in compute credits for open-source security groups (Hank Green, [06:40], [07:25]).
- Researchers successfully jailbroke DeepSeek with a 100% success rate across harmful test prompts to generate functional malware from scratch (Hank Green, [08:05]).
- Sherri Davidoff states she purchased a lifetime license to the underground hacking tool WormGPT for $50 as an early adopter on the dark web, compared to its standard price of approximately $500 ([18:48]).
- Davidoff cites Microsoft's bug-tracking database breach from 2013, which was publicly reported four years later in 2017 ([21:07]).
- Davidoff mentions Dan Geer’s 2003 white paper warning about the systemic risks of software monocultures ([31:13]).
- Davidoff describes an incident involving Amazon Q where an unauthorized user added malicious code to a repository intended to wipe developers' hard drives, reaching over one million developers before being blocked ([36:43]).
Notable quotes
- Hank Green [01:14]: "There is a big and true right now, and you should probably know about it. Anthropic has a new model, it's called Claude Mythos."
- Sherri Davidoff [12:19]: "That's the critical issue, that time delay. It takes more time to patch than it does to discover the vulnerabilities."
- Sherri Davidoff [14:04]: "Strong security is simple security... to be secure we have to take the human out of the equation."
Assessment
This video is an educational commentary and expert interview examining the systemic security implications of Anthropic's Claude Mythos release and Project Glasswing. No live interactive terminal demos of Mythos are conducted on screen, as the model's release is strictly gated to vetted enterprise and open-source partners.
Described by gemini-3.8-flash on 2026-09-29 from the video's audio and frames.