Anthropic has accidentally exposed details of its unreleased Claude Mythos model after a misconfiguration in its content management system left unpublished drafts and assets accessible through an unencrypted database. The leak indicates that the upcoming model, internally codenamed “Capybara”, performs better than Claude Opus 4.6 across several advanced benchmarks, with cybersecurity emerging as its most notable strength.
A leak that highlights product direction
According to the leaked material, Claude Mythos posts stronger results in software programming, academic reasoning, and cybersecurity. That combination suggests Anthropic is pushing further into specialized, high-stakes use cases rather than limiting its roadmap to general-purpose AI assistance. The emphasis on cybersecurity is especially significant as AI firms increasingly compete to serve enterprise defense workflows and technical security teams.
The exposure was reportedly discovered by cybersecurity researchers Alexandre Pauwels and Roy Paz. In addition to model-related documents, the leak also revealed details about a closed-door summit for European corporate CEOs, underscoring how internal operational and strategic materials were caught in the same security lapse.
Cautious rollout amid high operating costs
Anthropic has confirmed the model’s advanced capabilities and said it plans to release the system carefully. Rather than launching broadly at first, the company intends to offer Claude Mythos to a limited group of early customers focused on cybersecurity defense. Anthropic also cited high operating costs as a reason for the measured rollout strategy.
The incident reflects two parallel realities in the AI industry. On one hand, it shows how quickly competition is intensifying around AI tools built for cybersecurity applications. On the other, it highlights a recurring weakness: even leading AI developers remain vulnerable to basic infrastructure and information-governance failures. For Anthropic, the leak may have prematurely showcased a powerful new model, but it also raised questions about how securely such systems are being managed before release.

