Skip to content
Briefings are running a touch slower this week while we rebuild the foundations.See roadmap
Iran Conflict 2026
30MAR

Tom's Hardware challenges Mythos zero-day claims

2 min read
08:00UTC

A technical review found Anthropic's marketing relied on 198 manual reviews to support claims of thousands of severe vulnerabilities.

ConflictDeveloping
Key takeaway

Only 198 manual reviews support Anthropic's claim of thousands of zero-day discoveries.

Tom's Hardware published a critical review of Anthropic's Mythos claims on 9 April, noting that the "thousands of zero-days" assertion rested on only 198 manual reviews 1. Many of the flagged vulnerabilities were in outdated software no longer in active use. The gap between Anthropic's marketing language and the verified sample is wide enough to warrant caution.

The Bessent-Powell emergency meeting at Treasury headquarters proceeded regardless of this scrutiny. Challenger data confirmed AI-attributed cuts crossed 107,094 the same month , suggesting federal regulators assessed the systemic risk of AI broadly, beyond Mythos's specific claims. Whether Mythos found hundreds or thousands of exploitable flaws, the CyberGym benchmark score of 83.1% versus 66.6% for its predecessor represents a measurable capability jump that the twelve Glasswing partners will deploy in production environments.

Deep Analysis

In plain English

When Anthropic announced that Claude Mythos had found 'thousands' of serious security flaws in software, it was a dramatic claim. Tom's Hardware, a technology publication, looked at how Anthropic had actually counted those flaws. The answer was: 198 human reviewers manually checked the model's outputs. Many of the flaws it identified were in old software that organisations had already stopped using. The gap between 'thousands of vulnerabilities' and 198 verified reviews is significant. The US Treasury and Federal Reserve held their emergency meeting with bank CEOs regardless of this critique, which suggests the regulators assessed the risk from the model's overall capability trajectory, not just the specific zero-day count.

First Reported In

Update #5 · The model they won't release

Tom's Hardware· 10 Apr 2026
Read original
Causes and effects
This Event
Tom's Hardware challenges Mythos zero-day claims
Independent scrutiny of Mythos's capability claims introduces uncertainty about the model's actual security impact, even as regulators acted on the headline numbers.
Different Perspectives
Gulf shipping and insurance markets
Gulf shipping and insurance markets
With Hormuz and Bab el-Mandeb both hostile at once, war-risk underwriters face their first dual-chokepoint pricing problem; the rerouting hedge that absorbed one closure is gone for Israeli-linked hulls. Any deal that reopens Hormuz without a Houthi stand-down clause delivers only partial shipping relief.
Russia and China
Russia and China
Russia and China met IAEA chief Grossi jointly in Geneva on 5 June to coordinate an advance blocking position against Washington's censure resolution, the first documented instance of proactive pre-session obstruction rather than reactive post-vote dissent. Beijing's move came four days after OFAC designated Shanghai Qianye Energy under Iran energy sanctions.
Saudi Arabia
Saudi Arabia
Saudi Arabia was left out of the emergency $4.01 billion Patriot waiver Qatar received on 2 May as its own PAC-3 stocks ran near-empty from intercepting Iranian salvoes over Aramco facilities. Riyadh is on a standard 18-month FMS queue behind a production line booked through 2030, with no equivalent priority to Qatar's Al Udeid basing role.
Houthis (Ansar Allah)
Houthis (Ansar Allah)
The Houthis declared a complete ban on Israeli Red Sea navigation on 8 June and struck Jaffa, their first attack on Israeli territory since April, seven days after the Tasnim authorisation to activate other fronts including Bab el-Mandeb. The declaration put both chokepoints under hostile authority simultaneously.
Iran
Iran
Iran agreed the 9 June mutual halt after the Mahshahr exchange and coordinated with Russia and China to block Washington's IAEA censure resolution, using the Board as a second front while the bilateral pause held on the military one. Tehran's acceptance of the Lebanon carve-out contradicts the linkage position it stated on 1 June.
Benjamin Netanyahu and the IDF
Benjamin Netanyahu and the IDF
Israel struck the Karun Petrochemical plant at Mahshahr on 8 June over Trump's explicit objection, then agreed a halt with Iran the following day scoped on Israeli terms with Lebanon carved out. Netanyahu's posture is that the IDF will not accept Iranian missile factories as off-limits regardless of US diplomatic timelines.