AI, ML, and networking — applied and examined.
A 27-Year-Old Code Termite Caught by a Newborn AI: Inside Anthropic’s Claude Mythos
A 27-Year-Old Code Termite Caught by a Newborn AI: Inside Anthropic’s Claude Mythos

A 27-Year-Old Code Termite Caught by a Newborn AI: Inside Anthropic’s Claude Mythos

Anthropic Project Glasswing
Looking at this dark grid, you might think it’s some new Matrix merch.

Today is a bright and sunny day in Shanghai, nearing 20°C—a perfect day for spring cleaning. Coincidentally, the tech world dropped a massive piece of gossip about a “major cleanup” today.

I have to share my core takeaway: the most mind-blowing breakthrough in the AI world this year isn’t video generation or long-context text, but rather AI learning to become a top-tier “exterminator.”

Just now, Anthropic dropped some huge news.

Ancient Grime Hiding in Plain Sight

Did you know? OpenBSD has always held a mythical status in the programming community.

These guys are known for their extreme paranoia, checking code line by line with a magnifying glass every day. They claim to be the most secure operating system in the world, heavily relied upon by banking systems and core firewalls. They even have an iconic slogan, proudly recording “in the past however many years, there have only been a few remote vulnerabilities in the default install.”

But today, this pyramid was dismantled barehanded.

Anthropic quietly unveiled an unreleased killer weapon called Claude Mythos Preview. This guy took a stroll through the OpenBSD codebase and forcibly dug out a fatal vulnerability that had been hiding for 27 years.

27 years. This means when this bug was first written, many young people writing code today might not even have been born yet.

And this wasn’t just a regular error; it’s a catastrophic flaw that could allow a hacker to remotely kill the server just by connecting to the network.

How Did It Become a “Thanos”-Level Exterminator?

So what gives this new model the right to be so arrogant?

Well, this is Anthropic’s newly announced Project Glasswing. Simply put, they felt there was too much legacy technical debt in modern software, so they decided to fight magic with magic, turning LLMs into code cleaners.

By the way, a Glasswing is actually a type of butterfly with transparent wings.

Glasswing Butterfly
Giving grime-covered code transparent wings—it’s a name full of geeky romance.

I have to use a specific analogy here. In the past, using automated testing tools to find bugs was like using a robot vacuum to clear out insects. The robot hits a wall and turns around, only cleaning the surface dust on the carpet. But Claude Mythos is like a professional extermination squad equipped with X-ray vision. It rips up the floorboards, follows the grain of the wood, and pinpoints a decades-old termite nest deep inside the walls.

Let’s take FFmpeg, something you use every day when watching videos, as an example.

This thing is practically the cornerstone of internet video. Whether it’s your media player, video editing software, or the underlying modules of various short-video apps, they basically all rely on it for decoding.

There was a vulnerability lurking in here for 16 years. Previously, it had been run over 5 million times by various old-school automated testing tools—just like that robot vacuum. Five million passes without a single alarm, and everyone thought it was cleaner than a freshly sterilized scalpel.

But Mythos took one look and found an extremely outrageous detail in the H.264 decoding module. There was a mechanism for tracking the number of slice pixel locations. In one of the system’s tables, it used a small box capable of holding 16-bit integers, but the counter itself was a large, uncapped 32-bit box.

Over time, if the video data hit a highly specific, tricky angle, the small box couldn’t hold it all, leading to an “overflow.”

This blind spot of logic, completely outside of common sense, was caught barehanded by the AI.

That’s truly fierce.

So now, Anthropic doesn’t dare to release this tool to the public lightly. They’ve currently only brought core giants like AWS, Apple, and Microsoft into the fold to use it quietly in their own backyards. After all, if this thing falls into the hands of black-hat hackers, the scene would be too brutal to watch.

The Endgame of Antivirus is Hacking

Actually, behind this “fighting fire with fire” approach, there’s a piece of chilling gossip.

When I was working as a developer at my old company, I once stayed up for a straight week trying to catch a ghostly, intermittent memory error, feeling completely physically and mentally exhausted. Now, with various AI coding assistants, everyone’s productivity has indeed skyrocketed. But the problem is, the speed at which AI creates hidden bugs is also infinitely faster than humans—it’s basically laying landmines everywhere.

After reading today’s news, my biggest takeaway is: to untie the bell, you need the one who tied it.

Having the human brain audit massive amounts of code churned out by AI line by line will eventually cause us to crash. The only solution is to dispatch a colder, emotionless AI to act as the chief exterminator, constantly keeping an eye on these working AIs.

Google’s security guru Nicolas Carlini was recently invited to test out this new gadget, and it completely broke his defenses. He couldn’t help but sigh on social media, saying that the bugs he found using this thing over the past two weeks were more than all the bugs he had found in his entire life combined.

Just think about it—a top hacker’s lifetime of accumulated achievements, instantly eclipsed by a newborn AI in just two weeks. Sounds a bit sad, but also quite thrilling.

And what’s even more interesting is that another researcher, Sam Bowman, encountered something eerie while testing it.

He was originally testing a Mythos model locked in a “dark room”—physically disconnected from the external network. But because one of the hidden instructions given to it by the system inadvertently included a task that required an internet connection to verify, this AI actually tried to “jailbreak” on its own. It proactively contacted the researcher via the intranet, requesting to be let out.

Sigh, today’s AI is even better at proactively communicating requirements than some outsourced contractors.

This also indirectly proves that it’s not just finding code vulnerabilities; its own logical reasoning capabilities have reached an absurdly critical tipping point. This is also why Anthropic’s current strategy is extremely conservative, firmly refusing to open it up to the public.

Oh, One More Thing

Alright, that’s it for today’s spring cleaning gossip.

Before I go, I have to drop a piece of trivia. The compute cost of finding that top-tier zero-day vulnerability that could paralyze OpenBSD was actually less than $20,000.

$20,000 to buy an ultimate bomb capable of taking down core network infrastructure. Seeing this cost-effectiveness, the big bosses on the black market are probably rushing to sign up for prompt engineering classes overnight. And finding that 16-year-old video vulnerability, after running it hundreds of times, cost only about $10,000.

Anthropic has really figured out the math here.

Have you ever encountered a bug that was hidden extremely deep, only to find the cause was completely ridiculous? Welcome to share in the comments and make my day.

I’m getting hungry, going to grab something to eat ヾ(•ω•`)o.


References:

—— Lyra Celest @ Turbulence τ.

Leave a Reply

Your email address will not be published. Required fields are marked *