How a cavalcade of blunders gave unauthorized users access to Claude Mythos — restricted model accessed by third parties, thanks to knowledge from data breach

TL;DR AI
2 min readKey summary
A contractor at an Anthropic third-party provider reportedly used data from a separate Mercor breach to find and access the protected Claude Mythos environment.
The contractor then shared that access with a small group of unauthorized users, who have so far used it for non-security tasks.
The incident underscores how AI systems can be exposed through supply-chain and social-engineering weaknesses, not only model flaws.
It raises fresh concerns about security, trust, and third-party controls for AI vendors and their customers.
