(Preview) Mythos and Project Glasswing, The Year of Anthropic Continues Apace, Q&A on the NYT, Altman, De-globalization
Summary
- Anthropic’s Mythos makes AI-driven vulnerability discovery a near-term security event, even if its exact current capability remains unknowable from outside. The preview is limited to roughly 50 critical-infrastructure organizations, including Amazon, Microsoft, Apple, Google, and the Linux Foundation. Ben Thompson’s long-term call is categorical: legacy software contains vast numbers of bugs, models excel at exhaustive review, and eventually “the wolf does come.”
- Keeping Mythos private aligns Anthropic’s safety case with its commercial interest in preserving market power and pricing power. Thompson connects this to the Anthropic team’s earlier work at OpenAI, where withholding GPT-2 could reflect genuine risk while also preventing competitors from copying the frontier. A self-serve API makes determined distillation “pretty hard to stop.”
- Distillation narrows the model moat without eliminating it. Thompson says copied models remain “much more jagged,” less comprehensive, and behind the original—but can still be “more than good enough” against expensive frontier products. His explanation for open-source models trailing by roughly six months: that is about how long it takes to query leading APIs “a gazillion times” and train on the outputs.
- Compute scarcity is already determining Anthropic’s product quality, access, and economics. Thompson says the company can “barely stay online,” while rationing, quantization, caching, batching, and serving distilled models cumulatively degrade the experience. Mythos is priced at roughly 5X Opus, itself significantly more expensive than GPT-5.4, strengthening the case for restricting access to customers paying “real money.”
- The best immediate use of Mythos is finding and patching vulnerabilities before hostile actors obtain equivalent capabilities. A listener cited researchers reportedly finding more vulnerabilities in one or two months than over entire careers; Thompson conceded that this defensive deployment is plainly valuable. He tentatively linked a possible anonymous-reporting mode in leaked Quad Code source code to a Linux kernel group receiving extraordinary volumes of valid bug reports, while hedging that Anthropic’s role was uncertain.
- Mythos intensifies the unresolved sovereignty conflict between frontier labs and governments. Andrew Sharp asks why private individuals should possess technology potentially able to penetrate companies and states, and says nationalization would likely damage Anthropic. Thompson counters that law ultimately depends on “the people who have the guns.” Washington might fear Anthropic hacking it—or decide it wants a capability like Mythos to hack China.
Deep dive
1. Mythos turns code’s AI advantage into a security threat
Sharp’s setup: Anthropic is previewing Mythos with about 50 critical-infrastructure organizations but has no present plan for public release because it can find and exploit software vulnerabilities.
Thompson’s mechanism is straightforward: software is “massive amounts of language,” unusually predictable for large language models, while computers excel at the boring, line-by-line “yeoman’s work” required to inspect it.
Sharp calls the threat imminent; Thompson keeps the timing hedged. Mythos might already be as capable as claimed, but millions or billions of human-written lines inevitably contain bugs that increasingly capable models will uncover.
2. Safety and pricing power point toward the same closed model
Thompson’s cynical-but-not-dismissive framing: he points to the Anthropic team’s earlier work at OpenAI, where GPT-2 was withheld over danger concerns, but “not being open is actually good for business.” Preventing near-equivalent models also protects long-run market and pricing power.
DeepSeek supplies his concrete analogy: leading APIs can be queried “a gazillion times” to generate training data, helping explain why open-source alternatives may remain about six months behind the frontier.
Sharp asks whether distillation can reliably be prevented. Thompson’s answer is effectively no: copied models have more holes and remain less comprehensive, but policing high-speed API queries routed through cloud servers is much harder than “policing uranium.”
3. Scarce compute makes Mythos a premium product
Thompson says Anthropic can “barely stay online.” Five-hour usage blocks are not actually five hours: they can be shorter at certain times of day and longer at others. Quantization, serving distilled models, caching, and batching layer together and diminish quality—even if the degradation is not deliberate.
The pricing makes selective access commercially rational: Mythos costs roughly 5X Opus, and Opus is already significantly more expensive than the smaller GPT-5.4. Restricting access to customers who pay “real money” is therefore a business justification.
4. Defensive bug-finding is the strongest case for deployment
An anonymous listener’s challenge: leading security researchers reportedly found more vulnerabilities with Mythos in the last month or two than throughout their careers. Thompson accepts the narrow prescription—find and patch as many bugs as possible before bad actors gain comparable tools.
He tentatively links that effort to an apparent “hiding mode” in leaked Quad Code source code and a Linux kernel group receiving huge numbers of reports that were “all real bugs.” How much of that activity was actually Anthropic’s work remains an open question.
Thompson rejects the characterization that his criticism implies contempt: his concern is “rooted in deep respect and appreciation” because Anthropic is legitimate and has its act together in a major way.
5. Frontier capability creates a state-versus-lab power struggle
Sharp’s pushback — worth keeping: if Mythos could hack companies and governments worldwide, “why should a private company have all this power?” He expects government nationalization to damage Anthropic, yet sees the concentration itself as dangerous.
Thompson ties this to the unresolved tension from the recent dispute between Anthropic and the U.S. government. His realpolitik answer: laws are downstream from coercive power. If the state feels fundamentally threatened by someone developing “a better gun,” it may ignore legal restraints and take or constrain that capability.
The conflict cuts both ways: Washington could fear dependence on Anthropic’s goodwill not to attack it, or seek a capability like Mythos for offensive operations against China. Responsible patching is still, in Thompson’s view, “inviting and accentuating” a fundamental, unresolved tension.