Anthropic's Mythos AI model has shown significant advancements in cybersecurity capabilities, including autonomously identifying and exploiting flaws in IT systems. The latest version of Mythos successfully completed a previously unsolved cybersecurity test called "cooling tower" in three out of ten attempts, a first for any AI model tested by the AISI. This indicates that frontier AI models' autonomous cyber capabilities are rapidly progressing, doubling the length of cyber tasks they can complete in months, not years.

Anthropic has opted not to release Mythos publicly due to its advanced abilities to highlight unknown IT system flaws that could be exploited by hackers. Instead, the company has provided access to Mythos to a select group of tech companies and banks, including Apple and JP Morgan, to assist them in identifying their own system weaknesses. However, JPMorgan Chase has since cut off access for its Hong Kong staff.

Mythos has also demonstrated remarkable cryptanalytic capabilities, largely autonomously breaking the HAWK-256 post-quantum encryption candidate and discovering a novel attack that speeds up seven-round AES-128 cracking by 200 to 800 times. The HAWK-256 key recovery, which reduced the work factor from 2^64 to 2^38, cost approximately $100,000 in API usage and took about 60 hours for the AI, with human researchers taking nearly a month to verify the findings. While these encryption breakthroughs are significant for research, they do not currently threaten systems in production.