Newsletter
Join the Community
Subscribe to our newsletter for the latest news and updates
A few hours ago, Fortune broke possibly the biggest AI story of the year: Anthropic accidentally exposed its unreleased, most powerful model — Claude Mythos — through a CMS misconfiguration. Internal blog drafts, benchmark data, and strategic plans for a model that sits above the Opus tier? All of it is now public.
I've spent the last several hours going through every credible source — the original leaked archive, Fortune's exclusive, CybersecurityNews' technical breakdown, and the Reddit threads where researchers first connected the dots. Here's everything that matters, what it means for the industry, and why Anthropic is scared of its own creation.
On March 27, 2026, cybersecurity researchers Alexandre Pauwels and Roy Paz independently discovered that Anthropic's content management system (Sanity CMS) had been misconfigured. Nearly 3,000 unpublished assets — including draft blog posts, product announcements, and internal documents — were sitting in an unencrypted, publicly searchable database.
Fortune was first to verify and report the leak.
Among those assets was a fully written blog post introducing a model Anthropic calls "Claude Mythos" — codenamed "Capybara" internally. The document existed in two versions: one using the public-facing name "Mythos," the other using the internal codename "Capybara." Both are now archived and accessible.
This wasn't a hack. It was a configuration error — the kind that happens when a company moves fast and someone forgets to lock down their content pipeline. Ironic, given the model's capabilities.
Anthropic's current model lineup has three tiers: Haiku (smallest, fastest), Sonnet (mid-range balance), and Opus (largest, most powerful). Mythos is a new tier above Opus.
In Anthropic's own leaked words:
"'Mythos' is a new name for a new tier of model: larger and more intelligent than our Opus models — which were, until now, our most powerful. We chose the name to evoke the deep connective tissue that links together knowledge and ideas."
This is not an incremental upgrade. This is a new class of model.
The leaked draft blog states directly:
"Compared to our previous best model, Claude Opus 4.6, Mythos gets dramatically higher scores on tests of software coding, academic reasoning, and cybersecurity, among others."
Mythos scored "dramatically higher" than Opus 4.6 on coding benchmarks. To put that in context, Opus 4.6 — released February 5, 2026 with a 1-million-token context window — was already considered one of the most capable coding models in the industry.
The gap between Opus 4.6 and Mythos in academic reasoning is described as a "step change," not a linear improvement. Multiple sources describe this as a fundamental capability jump.
This is where things get serious — and where the story shifts from "cool new model" to "potential industry crisis."
From the leaked document:
"Although Mythos is currently far ahead of any other AI model in cyber capabilities, it presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders."
Mythos doesn't just find vulnerabilities. According to Anthropic's own assessment, it can discover and potentially exploit weaknesses in codebases at a speed and scale that current defensive tools can't match.
Here's what makes this leak genuinely significant: Anthropic built the most powerful AI model in the world, and then decided it was too dangerous to release.
From the leaked draft:
"In preparing to release Claude Mythos, we want to act with extra caution and understand the risks it poses — even beyond what we learn in our own testing. In particular, we want to understand the model's potential near-term risks in the realm of cybersecurity — and share the results to help cyber defenders prepare."
"Mythos is also a large, compute-intensive model. It's very expensive for us to serve, and will be very expensive for our customers to use. We're working to make the model much more efficient before any general release."
Two problems: (1) Safety — unprecedented cybersecurity risks; (2) Cost — too expensive to serve at scale. The combination led Anthropic to "a slower, more gradual approach to releasing Mythos than we have with our other models."
Instead of a public launch, Anthropic is doing something unprecedented: releasing the model exclusively to cybersecurity defenders first.
"That's why our release plan for Mythos focuses on cyber defenders: we're releasing it in early access to organizations, giving them a head start in improving the robustness of their codebases against the impending wave of AI-driven exploits."
The logic: if a model this powerful exists, similar capabilities will eventually appear in other labs' models too. By giving defenders a head start, Anthropic is betting the security community can build better defenses before the offensive capabilities become widely available.
1. The Capability Ceiling Just Moved — Opus 4.6 was already impressive. Mythos being "dramatically" better means we haven't hit diminishing returns on scaling.
2. The Safety Conversation Just Got Real — This is arguably the first concrete case where a major lab built something and then said "we're not comfortable releasing this." That's not a hypothetical — it's a data point.
3. CMS Security Is Not Trivial — If Anthropic — a company literally built on AI safety — can accidentally expose 3,000 assets through a CMS misconfiguration, it can happen to anyone.
4. The AI Arms Race in Cybersecurity — Mythos highlights a fundamental asymmetry: AI gets better at finding vulnerabilities faster than the industry can patch them.
Exact benchmark numbers — Anthropic described improvements as "dramatic" but hasn't released specific scores
Timeline for public release — No date. "Coming weeks" for expanded early access; general availability is TBD
Pricing — Given the "very expensive" language, expect Mythos to be significantly more costly than Opus
EU CEO summit connection — Leaked documents also mentioned a closed-door summit for European corporate CEOs that Dario Amodei is attending
I've covered AI models for years. I've seen plenty of "this changes everything" claims that didn't. This one is different.
The combination of factors — a credible leak from a major lab's own CMS, confirmed by Fortune, showing a model that the builder itself considers too dangerous to release — is unprecedented. We've officially crossed a threshold where the most advanced AI labs are building things that give them pause.
The next wave of AI won't just be more capable. It'll be capable enough to make its creators nervous. And that should make all of us pay attention.
Is the Claude Mythos leak real?
Yes. Fortune independently verified the leak, and multiple outlets (CybersecurityNews, The Decoder, Economic Times) corroborated. The documents came from Anthropic's own Sanity CMS. Anthropic has not denied the model's existence.
What does "Capybara" mean?
It's the internal codename for Mythos. The leaked CMS contained two versions of the draft — one using "Mythos" (public name) and one using "Capybara" (internal). Both are now publicly archived.
When will Mythos be available?
No confirmed date. Early access is currently limited to cybersecurity organizations. General availability depends on cost optimization and safety evaluation.
How does Mythos compare to GPT-5 or Gemini?
Based on leaked assessments, Mythos outperforms Opus 4.6 "dramatically" — and Opus 4.6 was already competitive with the latest from OpenAI and Google. Direct comparisons need independent benchmarks.
Should I be concerned about cybersecurity implications?
Context matters. Anthropic itself flagged the risk and chose to delay release rather than ship first. Their "defenders first" approach is a reasonable response to a genuine concern.
_Discover 1,000+ curated AI tools at _AIToolHunt — rated, reviewed, and categorized for every use case. Submit your tool for free →