Anthropic: Mythos Leak Reveals Major Security Flaws
Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
A Compromised Launch for Claude Mythos
The deployment of the Claude Mythos artificial intelligence model by Anthropic, which was supposed to be a meticulously controlled event, took an unexpected and embarrassing turn. The company had spent weeks touting the cybersecurity capabilities of its model, claiming it was too powerful to be made available to the public. However, this model was compromised, falling into the hands of unauthorized users, tarnishing the company's image.
According to Bloomberg, a small group of unauthorized users was able to access Mythos on the very day Anthropic announced its intention to offer it to a selected group of companies for testing. The existence of Mythos was first revealed through a leak. Anthropic stated that it was investigating the incident, which has damaged the image of the company that had positioned itself as a leader in AI security.
An Embarrassing Technological Flaw
From a technological standpoint, the way Mythos was compromised is particularly embarrassing for Anthropic. Bloomberg reports that the group was able to access the model by guessing its online location, a method facilitated by information leaked during a breach at Mercor, a company specializing in training data for AI. A member of the group, who had worked as a contractor to evaluate Anthropic's models, also contributed to this unauthorized access. Thus, it was not a sophisticated attack, but rather a mix of luck and insider knowledge that allowed this intrusion.
Security vulnerabilities are inevitable, and in this case, it was Mercor that accidentally leaked critical information used by the hackers. Pia Hüsch, a researcher at the Royal United Services Institute (RUSI), emphasizes that even the most secure companies are never completely safe, as human weaknesses are often the weak link. She noted that it was "initially a bit lucky" that there were no serious consequences.
A Failed Anticipation
This incident is not just a matter of bad luck. The technique used by the hackers, although basic, has long been known in the field of cybersecurity. Lukasz Olejnik, a security expert, described this failure as "totally predictable," a type of threat that the industry has been managing for decades. Anthropic should have been better prepared, especially since the Mercor breach was already known before the launch of Mythos.
Anthropic had the means to detect this intrusion. The company has systems in place to log and track the use of its models, which should have allowed for the quick identification of any suspicious activity. Yet, it seems that the monitoring was not up to par, which is all the more surprising given the risks associated with Mythos. The question arises as to why a company that claims its model is dangerous did not monitor its deployment more closely.
A Model Under Surveillance
Bloomberg reports that the group that accessed Mythos did not use it for cybersecurity activities, preferring to explore its capabilities without raising Anthropic's suspicions. This was a stroke of luck for the company, which had presented Mythos as a revolutionary tool for security, capable of detecting vulnerabilities in all major operating systems and web browsers. Anthropic had claimed that the release of Mythos was to be coordinated to bolster global cybersecurity defenses.
A Tarnished Reputation
Anthropic has often used dramatic language to describe its models, even suggesting that Claude could be conscious. However, initial feedback on Mythos confirms its cybersecurity skills. Bobby Holley, CTO of Mozilla, acknowledged its capabilities in identifying bugs in Firefox 150, sparking interest from numerous governments and financial institutions, including the NSA. Despite Anthropic being designated as a supply chain risk, the NSA and other U.S. agencies reportedly have access to Mythos, although the deployment seems to have bypassed the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
The fact that the breach was discovered by a journalist rather than by Anthropic itself also raises the obvious question of whether this is an isolated incident. Pia Hüsch notes that this incident illustrates how easy it is for a wide range of people to access these technologies, even without sophisticated means. Anthropic will likely review its supply chain to understand how this occurred and address the gaps, but she emphasized that there is a wide range of actors who would want access to a model like this, some of whom have substantial financial backing.
Disappointed Expectations
Anthropic has built its reputation on a rigorous approach to AI security, creating high expectations. The exposure of Mythos through such a basic flaw highlights a gap between the company's promises and the reality of its security practices. By presenting Mythos as a tool too powerful to be public, Anthropic has made it a prime target for hackers.
This is not the first time Mythos has been at the center of a security incident. Even before its launch, the existence of the model had been accidentally revealed through an "unsecured data treasure" on a central system containing content for its website. Now, it has been accessed via a vulnerability that the company could have anticipated. Perfection is impossible, but for a company that has proclaimed itself at the forefront of AI security, such a basic error is hard to justify, even with a bit of bad luck.
For Pia Hüsch, this episode is a true humiliation for Anthropic. The company, which aims to be at the cutting edge of AI security, has been caught off guard by such a low-level attack, calling into question its position as a responsible leader in the field.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.