Anthropic puts the “myth” in Mythos with its HackerOne bug bounty program
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Anthropic has launched a public bug bounty program on HackerOne, covering assets like Claude.ai, the Anthropic API, Claude Code, and internal infrastructure. Rewards are determined using CVSS scoring. The launch follows Anthropic's earlier invite-only safety bounty programs and a 2024 Vulnerability Disclosure Program. The timing is notable: it comes one month after Anthropic unveiled Claude Mythos, a restricted-access AI model claimed to autonomously discover and chain software vulnerabilities. Critics, including AI Now Institute's Dr. Heidy Khlaaf and security consultant David Ottenheimer, have questioned Mythos's benchmarking transparency, lack of false-positive metrics, and absence of independent validation. Some observers see the traditional human-led bug bounty launch as implicitly contradicting Anthropic's claims about AI-driven vulnerability discovery. The UK AI Security Institute did find Mythos capable of completing multi-stage cyberattack simulations, but cautioned against overinterpreting results from controlled environments.