On April 7, Anthropic announced a preview of Claude Mythos and restricted access simultaneously, after testing showed the model finding vulnerabilities in real software, including Firefox, the Linux kernel and OpenBSD, that years of human security testing had missed.
Announcing and restricting on the same day is an unusual decision and says a lot about the test results. A company restricting its own product at launch is declaring that the capability found exceeded what it considered acceptable to release broadly.
The targets named give the finding its scale. Firefox, the Linux kernel and OpenBSD are projects under intense audit for decades, with bug bounty programmes and large review communities. Finding there what nobody else found isn't luck.
The restriction ran through a programme limiting access to a small group of organisations considered trusted, an arrangement competitors would adopt weeks later under a different name and similar design.
What this episode foreshadows is the entire debate that would dominate the semester: the capability that finds flaws is the same one that exploits them, and no benchmark separates the two reliably.
