Developed by AI company Anthropic Following the data breach that revealed the model’s existence, the company said it has begun testing with early access customers a new AI model that is more powerful than any previously released AI model.
An Anthropic spokesperson said the new model represents a “step change” in AI performance and is “the most capable we’ve ever built.” The company said the model is currently being trialled by “early access customers.”
A model description was accidentally stored in a publicly accessible data cache and reviewed by. luck.
A draft blog post published on an insecure, publicly searchable data store by Thursday evening calls the new model “Claude Mythos” and says the company believes it poses an unprecedented cybersecurity risk.
The same cache of insecure, publicly discoverable documents revealed details of a planned invitation-only CEO summit in Europe as part of the company’s efforts to sell AI models to large enterprise customers.
The AI Institute left material in an unsecured public data lake, including what appears to be a draft of a blog post announcing a new model, according to documents independently located and reviewed by Roy Pass, a senior AI security researcher at computer and network security firm LayerX Security, and Alexander Powells, a cybersecurity researcher at the University of Cambridge.
In total, Powells said, there appear to be nearly 3,000 assets linked to Anthropic’s blog that were previously hidden from the company’s news and research sites, but were nevertheless publicly accessible within this data cache. luck You were asked to rate and review the material.
After receiving notification of a data breach, luck Anthropic on Thursday removed the ability for the public to search its data store and retrieve documents from it.
In a statement provided to luck, Anthropic admitted that the draft blog post became accessible due to “human error” in the configuration of its content management system. The report described unpublished material left in unsecured, publicly searchable data stores as “early drafts of content being considered for publication.”
In addition to mentioning Mythos, the draft blog post also discusses a new stage of AI models called “Capybara.” “‘Capybara’ is the new name for a new layer of models that is bigger and more intelligent than our most powerful Opus model to date,” Anthropic said in a statement. Capybara and Mythos seem to refer to the same underlying model.
Currently, Anthropic sells each model in three different sizes. The largest and most capable model version is branded Opus, a slightly faster and cheaper but less capable version is branded Sonnet, and the smallest, cheapest and fastest version is called Haiku. However, Anthropic explained in a blog post that Capybara is a new stage model that is even bigger and more capable than Opus, but also more expensive.
“Compared to our previous top model, Claude Opus 4.6, Capybara scored dramatically higher on tests such as software coding, academic reasoning, and cybersecurity,” the company said in a blog post.
The document also states that the company has completed training on Claude Mythos, which a draft blog post describes as “the most powerful AI model we have ever developed.”
In response to questions about a draft blog post, the company confirmed that it had trained and tested the new model. “We are developing a general-purpose model that has made meaningful advances in inference, coding, and cybersecurity,” an Anthropic spokesperson said. “Given the strength of its capabilities, we are thinking carefully about how we release it. As is standard practice across the industry, we are working with a small group of early access customers to test the model. We believe this model is a step change and the most capable we have built to date.”
document luck And the content reviewed by cybersecurity experts consists of structured data of web pages with headlines and publication dates, suggesting that they are part of a planned product launch. It outlines a careful rollout strategy for the model, starting with a small group of early access users. The draft blog notes that this model is expensive to run and is not yet ready for general release.
Significant new cybersecurity risks
New AI models pose significant cybersecurity risks, according to leaked documents.
“In preparing for the release of Claude Capybara, we want to act with extreme caution and go beyond what we have learned from our own tests to understand the risks it poses. In particular, we want to understand the potential short-term risks of this model in the realm of cybersecurity and share our results to help prepare cyber defenders,” the document reads.
Anthropic seemed particularly concerned about the model’s cybersecurity implications, noting that the system is “far ahead of any other AI model in cyber capabilities today” and “foreshadows a wave of models that will be able to exploit vulnerabilities in ways that far exceed defenders’ efforts.” In other words, Anthropic is concerned that hackers could use this model to carry out large-scale cyberattacks.
Because of this risk, the company said in a draft blog that its release plans for the model are focused on cyber defenders, “releasing it to organizations in early access to give them a head start in improving the robustness of their codebases against the impending wave of AI-driven exploits.”
Anthropic and OpenAI’s latest generation of frontier models cross thresholds that both companies say pose new cybersecurity risks. When OpenAI released GPT-5.3-Codex in February, the company said it was the first model classified as “high-performance” for cybersecurity-related tasks under its readiness framework, and the first model directly trained to identify software vulnerabilities.
Anthropic, on the other hand, avoided a similar risk with Opus 4.6, released the same week. This model demonstrated its ability to surface previously unknown vulnerabilities in production codebases. The company confirmed that this capability is dual-purpose. This means that in addition to helping hackers, it also helps cybersecurity defenders find and resolve vulnerabilities in their code.
The company also reported that hacker groups, including groups associated with the Chinese government, attempted to exploit Claude in real-world cyberattacks. In one of the documented incidents, Anthropic discovered that a Chinese state-backed group had already conducted a coordinated campaign using Claude code to infiltrate approximately 30 organizations, including technology companies, financial institutions, and government agencies, before the company detected it. Over the next 10 days, Anthropic investigated the full scope of the operation, banned the accounts involved, and notified affected organizations.
A luxury executive retreat
According to cybersecurity experts, the leak of non-public information appears to have been caused by a user error in the content management system (CMS), the software used to publish the company’s public blogs.
Digital assets created using a content management system are set to public by default and are typically assigned a publicly accessible URL upon upload, unless the user explicitly changes the settings to keep these assets private. As a result, a large cache of images, PDF files, and audio files appears to have been inadvertently exposed to insecure, publicly accessible URLs via an off-the-shelf content management system.
Humanity was acknowledged in a statement. luck “An issue with one of our external CMS tools resulted in access to draft content.” It said the issue was due to “human error.”
Many of the documents appeared to be discarded or unused assets from past blog posts, such as images, banners, and logos. However, some appeared to be personal or internal documents. For example, an asset has a title that describes an employee’s “parental leave.”
The document also includes a PDF with information about an invitation-only retreat for European CEOs to be held in the UK, said Anthropic CEO Dario Amodei. I will attend. The names of the other attendees are not listed, but they are listed as Europe’s most influential business leaders.
The two-day retreat is described as an “intimate gathering” for “thoughtful conversations” at a converted 18th-century mansion hotel and spa in the English countryside. Attendees will hear from lawmakers and policymakers about how companies are implementing AI, and will be able to experience Claude’s unreleased capabilities, according to the document.
An Anthropic spokesperson said: luck The event is “part of an ongoing series of events that we have hosted over the past year. We look forward to hosting European business leaders to discuss the future of AI.”
