Skip to main content
Live
Main content

Discord users gained unauthorized access to Anthropic's Mythos Preview model

Amateur sleuths used a Mercor breach and a guessed URL to reach restricted Anthropic models, according to a Bloomberg report.

Jaeden Schafer
Editor in Chief · · 4 min read
Anthropic logo

A group of Discord users gained unauthorized access to Anthropic's Mythos Preview, the company's restricted vulnerability-hunting AI model, by piecing together clues from a third-party breach rather than by jailbreaking anything. Bloomberg, which first reported the story, said the group examined data from a recent breach of Mercor, an AI training startup that works with developers, then guessed the model's online location based on Anthropic's URL formatting for prior models. Mozilla, by contrast, used a sanctioned early access program to the same model to find and fix 271 vulnerabilities in Firefox 150.

The contrast is the story. Anthropic has positioned Mythos Preview as capable enough at finding software and network vulnerabilities that it has tightly controlled who gets in. A defender used it to harden a browser shipped to hundreds of millions of users. An unvetted Discord group reached the same model in parallel, with no AI hacking involved.

According to Bloomberg, the person who led the access also leaned on permissions they already had through work for an Anthropic contracting firm, which extended their reach to other unreleased Anthropic models beyond Mythos. That detail matters more than the URL guess. It points to a supply-chain seam, where contractor credentials issued for one purpose carried over into systems that were supposed to be off-limits.

Key facts

  • 01A group of Discord users gained unauthorized access to Anthropic's Mythos Preview model, according to a Bloomberg report.
  • 02The group used data from a recent breach of AI training startup Mercor and guessed the model's URL based on Anthropic's prior naming patterns.
  • 03Mozilla used sanctioned early access to Mythos Preview to find and fix 271 vulnerabilities in Firefox 150.
  • 04The Discord users reportedly limited their use of Mythos to building simple websites to avoid detection by Anthropic.
  • 05The same person allegedly used contractor permissions to access other unreleased Anthropic models beyond Mythos.

The group's behavior once inside has been comparatively tame. Bloomberg reported they used Mythos to build simple websites, a deliberate choice to keep activity quiet and avoid tripping Anthropic's detection. No exploitation campaigns, no sale of zero-days — at least none disclosed.

Mozilla used early access to Mythos Preview to find and fix 271 vulnerabilities in Firefox 150, the same model a group of Discord users reached without authorization.
Jaeden Schafer

That restraint does not make the breach a non-event. A model marketed as a force multiplier for offensive security research is only as restricted as the weakest credential or the most predictable URL pattern. Mozilla's 271-vulnerability haul on Firefox 150 is a useful proof point: this is not a toy, and it is not a model anyone wants leaking into adversarial hands at scale.

The episode lands in a week thick with security stories that share a theme — old or sloppy access controls outpacing newer defenses. Citizen Lab disclosed that at least two for-profit surveillance vendors have been exploiting Signaling System 7 vulnerabilities, the decades-old telecom protocols, by acting as rogue carriers through three small telecom firms: 019Mobile in Israel, Tango Mobile in the UK, and Airtel Jersey. Citizen Lab said high-profile targets were tracked but declined to name the surveillance firms or victims.

On the criminal side, the US Department of Justice charged two Chinese men, Jiang Wen Jie and Huang Xingshan, with allegedly running a human-trafficking-fueled scam compound in Myanmar and attempting to open a second in Cambodia. The DOJ said it restrained $700 million tied to the operation and cited a single US victim defrauded of $3 million. Separately, researchers identified North Korean hackers using AI to vibe-code malware and spin up fake company sites, stealing roughly $12 million in three months.

Health data also surfaced. UK Biobank, which has collected medical images, genetic data, and care records from more than 500,000 British citizens over two decades, said three research institutions breached their data-sharing contracts and listed the records for sale on Alibaba, with one dataset reportedly covering all 500,000 subjects. The charity has suspended the implicated accounts, and the listings have been removed.

Related · from this week
Mozilla details how Anthropic's Mythos found 271 Firefox bugs with almost no false positives
Jaeden Schafer · 5 min read →

Apple, meanwhile, shipped iOS 26.4.2 this week to fix a logging issue 404 Media flagged earlier this month, in which push-notification content from end-to-end encrypted apps including Signal was retained on iPhones and made accessible to the FBI even after the apps were uninstalled. Apple's release notes say notifications marked for deletion could be unexpectedly retained, and that the bug was addressed with improved data redaction.

The skeptic's read on the Mythos story is that nothing especially novel happened. No model weights were exfiltrated, no exploit chain was published, and the intruders confined themselves to building websites. Anthropic has not, at least publicly, described long-term harm. The argument that this is a near-miss rather than a breach has some weight.

The harder read is that controlled-release as a safety strategy depends on more than gated waitlists. Mythos Preview's existence and approximate URL format were inferable from public patterns and a contractor's leaked data. If a Discord group can stitch that together in a weekend, well-resourced adversaries with access to far more breach corpora than Mercor can do it faster and with worse intent. Anthropic's investment thesis — that frontier models can be released responsibly with the right guardrails — gets harder to defend each time the perimeter turns out to run through a third party.

Expect Anthropic to tighten contractor access controls and rotate model endpoints, and expect every other lab marketing offensive-security capabilities to quietly audit who, exactly, can reach their preview tiers. The takeaway for the broader market is the one Mozilla already demonstrated: these models are useful enough that defenders will pay for legitimate access, and attackers will work around the gates to get the same thing for free.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Mozilla details how Anthropic's Mythos found 271 Firefox bugs with almost no false positives

Mozilla unhid 12 Bugzilla reports to back its claim that an agent harness wrapping Mythos has effectively eliminated AI vulnerability slop.

Jaeden Schafer5 min read
News

Anthropic's Mythos found 271 vulnerabilities in Firefox 150 before release

Mozilla's CTO says the AI model matched elite human researchers — and calls it a turning point that every codebase will have to face.

Jaeden Schafer4 min read
Anthropic logo
Business

AI startups are hitting revenue milestones in half the time

Mercor doubled from $1B to $2B in four months. Anthropic added $17B in run rate in under two. The pattern is now the story.

Jaeden Schafer5 min read