Anthropic's Biggest Secret Leaked Through an Unlocked Door — and It's Called Claude Mythos

March 28, 2026

Security researchers discovered nearly 3,000 unpublished documents sitting in an unsecured, publicly searchable database belonging to Anthropic on Friday. Among them: draft blog posts for a model called Claude Mythos — internally codenamed "Capybara" — described as "the most capable we've built to date."

Anthropic confirmed Mythos is real, calling it "a step change" in capabilities. According to the leaked drafts, Mythos represents a new tier above Opus — not a version update. It scores "dramatically higher" than Opus 4.6 on coding, reasoning, and cybersecurity benchmarks. More notably, the documents warn that Mythos is "currently far ahead of any other AI model in cyber capabilities" and "presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders."

The cause of the leak? A default CMS setting that made uploaded files public unless someone manually changed the permission. An AI safety company left its most sensitive roadmap behind an unlocked door.

Markets reacted immediately. Cybersecurity stocks dropped 3–7% on Friday, with CrowdStrike falling 7% and Palo Alto Networks losing 6%, as investors priced in a future where AI offense outpaces AI defense.

Meanwhile, the leaked documents also reveal Mythos is "very expensive for us to serve, and will be very expensive for our customers to use" — which maps directly to the rate-limit tightening Claude users noticed all week.

Why it matters

This is a rare case where a leak tells you more than a launch would. The Mythos documents show Anthropic internally acknowledging that its own model may be too dangerous and too expensive for broad deployment — while simultaneously failing to secure the paperwork describing it. The cybersecurity implications alone moved billions in market value overnight.

For developers, the signal is clear: the next generation of frontier models will be significantly more capable and significantly more restricted. Rate limits, pricing tiers, and access controls are tightening across the board. If you're building on top of these APIs, plan for both capability jumps and access friction.

Also in the news

Relevant links

← Back to updates