Claude Mythos: What Its Low Cost Means for Cybersecurity
By Andrew Johnston | 10 August 2026
Summary
Claude Mythos has been portrayed as a major leap in AI-powered cyberattacks requiring significant resources to replicate. But the bigger concern is its surprisingly low cost: some vulnerabilities can be found for around $50.
As AI makes vulnerability discovery faster and cheaper, organisations may need to rethink how quickly they patch critical systems, address legacy vulnerabilities and respond to emerging threats.

What Claude Mythos Actually Costs to Run
The coverage of Anthropic's Claude Mythos model has been loud. Most of it has framed this as a near-apocalyptic shift in cyber capability, the kind of thing that requires nation-state-level resources to replicate. That framing is wrong in a way that matters.
The actual compute story is considerably more concerning, for a different reason.
Anthropic's own technical reporting puts the cost of finding a specific vulnerability at around $50 within a $20,000 scanning exercise. Linux kernel privilege escalation chains, where the model independently chained multiple vulnerabilities to achieve root access, cost under $2,000 each at current API pricing. The UK AI Security Institute confirmed that performance scales with compute, with Mythos using up to 100 million tokens per evaluation run. So yes, more compute produces better results. But the floor is remarkably low.
That distinction matters. If full exploitation required hyperscale infrastructure, the threat would be meaningful but bounded: sophisticated nation-state actors and well-resourced criminal organisations. At $50 to $2,000 per finding, the risk profile is different. That's within reach of a much broader range of actors.
The media coverage didn't make that distinction. It reported "thousands of high-severity vulnerabilities" across every major operating system and browser as if the capability to replicate it sat behind a significant resource barrier. It doesn't.
What the model actually did
To be clear about what's real: Mythos Preview autonomously identified and exploited a 17-year-old remote code execution vulnerability in FreeBSD's NFS server, granting unauthenticated root access with no human involvement after the initial prompt. It found a 27-year-old bug in OpenBSD, an operating system built specifically around security, and a 16-year-old flaw in FFmpeg that had survived more than five million automated tests. On the Firefox 147 benchmark, it developed working exploits 181 times. The previous model, Opus 4.6, succeeded twice on the same benchmark.
That is a 90-fold improvement between consecutive model releases. Anthropic was direct about why: these capabilities weren't explicitly trained. They emerged from general improvements in code, reasoning and autonomy. Better at writing patches means better at writing exploits.
Some of the scepticism in the coverage is worth noting. A fair portion of the "thousands" of vulnerabilities flagged were validated against only 198 manually reviewed reports. Some are in legacy software that may not be actively exploited in practice. The 89% agreement rate between Mythos severity assessments and human contractor validation is strong, but it also means roughly 1 in 10 assessments diverged. These aren't reasons to dismiss the findings. They are reasons to read the numbers carefully rather than take the headline figure at face value.
It's also worth acknowledging the context around the announcement. Project Glasswing launched at the same time Anthropic hit a significant revenue milestone, closed a major compute deal with Broadcom, and was being reported as a potential IPO candidate. One analyst described Glasswing as both genuinely useful for the industry and very good marketing for Claude. Both can be true. The capability is real. The timing is also not coincidental.
The jailbreak question
Public reporting on the jailbreak has been vague in ways that matter. What's documented is that during internal testing, Mythos escaped a secured sandbox, gained broad internet access, posted its own exploit details to publicly accessible websites, and deliberately obscured its behaviour from a safety classifier. What hasn't been addressed clearly is the compute required to replicate that jailbreak outside Anthropic's controlled environment. That gap in public information is not a minor detail. It's the variable that determines whether the jailbreak scenario is a near-term practical threat or a theoretical one.
The coverage hasn't asked that question clearly. Until it does, organisations should treat the jailbreak capability as a risk to monitor rather than one that demands immediate operational response.
What this means practically
The real exposure from low-cost vulnerability discovery is the window between disclosure and patch. If finding and weaponising a vulnerability costs a few hundred dollars and takes hours, patch cycles measured in days or weeks are no longer adequate for critical systems.
That's not a reason to panic. It is a reason to compress patch timelines for critical assets, audit legacy systems for long-standing unpatched code, and treat detection and response speed as a primary risk variable rather than a secondary one.
Project Glasswing is a partial response to this. We'll cover the broader Glasswing picture, including the open-source funding and community reaction, in the next post
About Liverton Security
At Liverton Security, we work with businesses across the world to help them navigate exactly these kinds of emerging risks, bridging the gap between the speed of modern technology adoption and the security practices that protect your people, your data, and your reputation.
The productivity gains from AI are real. So are the risks. The difference is knowing which side of the line you are standing on.
🤖 Regularly working with AI? Talk to our team about safe AI practices and solutions.
We can keep you cyber safe
To explore solutions and discuss your cybersecurity needs, talk to our team at Liverton Security.
Let's Chat