Skip to main content
Live
Main content

ECB studying defences against Mythos-powered attacks, Lagarde says

Christine Lagarde flagged AI-driven offensive tools as a fresh category of risk for European financial infrastructure.

Jaeden Schafer
Editor in Chief · · 4 min read
ECB studying defences against Mythos-powered attacks, Lagarde says

The European Central Bank is studying defences against attacks powered by Mythos, the AI-driven offensive security tool, ECB President Christine Lagarde said. The acknowledgement places one of the world's largest central banks among the first public institutions to name a specific AI offensive system as a financial-stability concern. Lagarde framed the work as preparatory rather than reactive, with no specific incident disclosed against the eurosystem.

Mythos has spent the last several weeks moving from a research curiosity to a named threat vector. Mozilla recently disclosed that the same tool surfaced 271 bugs in Firefox with very few false positives, an unusually clean signal-to-noise ratio for automated vulnerability discovery. The same capability that helps a browser vendor harden its codebase also lowers the cost for an attacker to find exploitable flaws in financial systems.

Lagarde did not detail the ECB's specific countermeasures, nor did she identify a target list of systems being stress-tested. The ECB oversees monetary policy for the 20-country euro area and supervises the largest banks in the bloc, putting it at the centre of any conversation about systemic cyber resilience. Payment rails, settlement systems and the supervisory data exchanges between national regulators all sit inside that perimeter.

Key facts

  • 01ECB President Christine Lagarde said the central bank is studying defences against Mythos-powered attacks.
  • 02Mythos is the same Anthropic-built offensive security tool Mozilla used to surface 271 Firefox bugs.
  • 03Lagarde's comments mark one of the first public acknowledgements by a major central bank that AI-driven offensive tooling is a financial-stability concern.

The comments slot into a wider pattern of central banks treating AI-augmented attacks as a distinct risk category from conventional cyber threats. Traditional models assume a human attacker with finite time; AI-assisted reconnaissance and exploit generation collapse that constraint. Defences calibrated to last decade's threat models — periodic penetration tests, signature-based detection, quarterly tabletop exercises — were not designed for adversaries that can iterate continuously.

Mythos itself is not a malicious tool. It was built as a security research system and, on the defensive side, it is already producing measurable wins, as the Firefox disclosure showed. The dual-use problem is the familiar one in offensive security: anything good enough to find real bugs at scale is, by definition, good enough to weaponise if it reaches the wrong operator or is reproduced by a capable adversary.

For the ECB, the practical question is less about Mythos as a brand than about the class of capabilities it represents. Banking infrastructure runs on long-lived code: core ledger systems, SWIFT integrations, custom middleware written years before modern AI tooling existed. A defender now has to assume an attacker can scan that codebase faster than the defender can audit it, which inverts a long-standing asymmetry in favour of incumbents with deep institutional knowledge.

Lagarde's framing — studying defences rather than announcing them — is also a tell about where the policy conversation actually sits. Regulators across Europe and the US have spent 2025 and 2026 trying to catch up on AI risk classifications, with most of the attention going to model providers and consumer-facing systems. Offensive AI tooling, used against critical infrastructure, has had less explicit treatment in the rule-making, even as the underlying capability has advanced quickly.

Skeptics of the alarm will note that no breach has been attributed publicly to Mythos against a financial institution, and that vulnerability discovery is not the same as successful exploitation. Patching, segmentation, and monitoring still buy meaningful time even when the discovery half of the kill chain accelerates. The risk is not that defences fail tomorrow; it is that the cadence of upgrade cycles in regulated finance is measured in years while attacker tooling now iterates in weeks.

Related · from this week
Anthropic disrupts Russian and Chinese campaigns abusing Claude
Jaeden Schafer · 4 min read →

The ECB's posture is the more interesting signal here for the AI industry. When a central bank publicly names an AI security tool as something it is preparing for, it pulls AI safety out of the model-provider blog-post genre and into the prudential-regulation conversation, where the consequences for vendors include licensing regimes, mandatory disclosures, and sanctions for misuse. Anthropic and its peers have spent the year arguing that responsible deployment of capable systems is possible; Lagarde's comment is a reminder that the institutions on the other side of that argument are now watching specific products by name.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Anthropic disrupts Russian and Chinese campaigns abusing Claude

The company says state-linked operators tried to weaponize its Claude models; access has been cut and accounts terminated.

Jaeden Schafer4 min read
White House keeps AI cybersecurity framework secret after briefing top labs
Security

White House keeps AI cybersecurity framework secret after briefing top labs

OpenAI, Anthropic, Google, Meta, and Nvidia got the details Tuesday. Everyone else, including smaller AI startups, is locked out.

Jaeden Schafer5 min read
Google logo
Security

Google launches Gemini 3.5 Flash Cyber to undercut Anthropic's Mythos

The new security model runs at a fraction of Mythos 5's cost and found 55 confirmed bugs in V8, beating Claude Opus 4.6's 36.

Jaeden Schafer4 min read