As cited
Copy frozen at (site build).
research
Most of the bugs Claude Mythos found have never been checked by a human
Anthropic deployed Claude Mythos Preview to scan 281 open-source projects and identified 23,019 candidate vulnerabilities. External security firms reviewed only 1,900 of these candidates, with 1,596 reports sent to maintainers, 1,451 acknowledged, 97 fixes merged upstream, and 88 published as security advisories as of May 22, 2026. The remaining 21,119 candidates have not undergone external review, attributed by Anthropic to insufficient resources for validation.
Why it matters: Open-source maintainers and users of scanned projects need to understand that the majority of vulnerabilities identified by this automated artificial intelligence (AI) tool lack independent verification, creating uncertainty about their severity and exploitability.
- Source published
- First seen by Cybersecurity Tracker