Mozilla shipped Firefox 150 this week with patches for 271 security vulnerabilities identified by Anthropic's Mythos Preview, the unreleased model Anthropic has so far limited to a small group of industry partners. Firefox CTO Bobby Holley disclosed the figure in a Tuesday blog post, arguing the model is "every bit as capable" as the world's top human security researchers. For comparison, Anthropic's Opus 4.6 found 22 security-sensitive bugs in Firefox 148 last month.
The jump is the point. Holley said many of the bugs Mythos surfaced could theoretically have been found by fuzzing or by an elite researcher grinding through source code for months. Mythos found them by reading the Firefox 150 codebase directly, at a cost that collapses the economics of vulnerability hunting on both sides of the fence.
Anthropic has been deliberately slow-walking access. Mythos Preview is only available to select partners, and the company has convened an industry working group called Project Glasswing to coordinate the rollout. Mozilla got access through a direct collaboration with Anthropic rather than through Glasswing itself.
Key facts
- 01Anthropic. A key thread of reporting in this story.
- 02Mozilla. A key thread of reporting in this story.
- 03Firefox. A key thread of reporting in this story.
Holley's framing is that every serious codebase is about to run a one-time gauntlet. "Every piece of software is going to have to make this transition, because every piece of software has a lot of bugs buried underneath the surface that are now discoverable," he told Wired. He says he has spoken with engineering leaders at large companies who plan to pull thousands of engineers off roadmap work for six months to do exactly that.
“Anthropic's Opus 4.6 surfaced 22 security-sensitive bugs in Firefox 148 last month. Mythos Preview surfaced 271 in Firefox 150 — a 12x jump in one model generation.”— Jaeden Schafer
The uncomfortable part is open source. Widely deployed projects are often maintained by one or two unpaid volunteers, and abandonware gets no maintenance at all. Mozilla CTO Raffi Krikorian argued in a New York Times essay last week that the maintainer "who gave 20 years of his life" to code running inside products used by billions doesn't have Mythos access — and should.
Holley claims Firefox has "rounded the curve" thanks to its head start, and expects future models to find only marginal additions. That's a strong claim, and it only holds if attackers don't get access to comparable capability before defenders finish their pass. Anthropic's staged release is a bet that they won't.
The real story here is an economic inversion. For years, the defender's job was to make bug-finding expensive enough that only well-funded attackers could afford it. Mythos drops that price to near zero for anyone who has the model — which makes who gets the model, and when, the most important security question of the next year.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.



