Anthropic Loses Its World-Ending AI to a Discord Server That Guessed the URL
Anthropic, the company that has spent two years warning Congress that artificial intelligence might extinguish the human species, announced this week that its most dangerous model to date has been quietly accessed by a Discord chat whose members figured out where it lived by Googling. The company described the incident as “unauthorised access through a third-party vendor environment,” which is corporate for “we left it on the porch.”
The model, called Mythos, was released in April under a programme named Project Glasswing, available only to a hand-picked club of fourteen companies including Apple, JPMorgan Chase, and Cisco. Anthropic told the press the tool was so capable of breaking into software that wider release would constitute a national security risk. It then placed the tool on a server that a contractor’s roommate’s friend reportedly located in under an hour.
How the Discord Forum Cracked the Most Dangerous AI on Earth
According to Bloomberg’s reporting, the group made an “educated guess” about Mythos’s online location based on Anthropic’s previous URL conventions. They did this on the same day the model was announced. This is roughly the cybersecurity equivalent of finding a bank vault by trying the door.
One member of the Discord works for a third-party contractor that Anthropic uses, which provided initial access. The rest of the work involved the kind of pattern recognition normally reserved for figuring out which of your neighbour’s cars is parked across the street. Jim Gaffigan once observed that he is not a smart man because he cannot use a computer without his wife in the room. Jim Gaffigan could have found Mythos.
The group is using the model “regularly,” sources said, “though not for cybersecurity purposes.” Translation: they are asking it to write fan fiction. The most powerful instrument of digital destruction ever assembled is currently being used to generate sonnets about Pokémon.
Anthropic’s CEO Warned Congress, Then Forgot Where He Parked
Anthropic CEO Dario Amodei has spent the last eighteen months touring Washington explaining that AI may end civilisation. He has done podcasts. He has done op-eds. He has done a TED talk about the risks of releasing models without adequate safeguards. The model in question was then released with a safeguard that can be summarised as “please don’t guess our URL pattern.”
Norm Macdonald used to say that the worst part about being old was that nobody told you. The worst part about being a frontier AI lab is that nobody tells you the back door is open until a teenager screenshots it. Anthropic says it has “no evidence the activity extended beyond the third-party vendor environment,” a sentence that has been spoken by every breached company in the history of breaches, and which has never once been followed by a press release saying “actually it did extend further but we wanted you to relax for a few news cycles first.”
The Dangerous Capabilities, Now Available in a Discord Channel
Mythos was reportedly used by Anthropic itself to discover a 27-year-old vulnerability in OpenBSD, an operating system whose developers had previously believed they had thought of everything. Mozilla used a Mythos preview to patch 271 vulnerabilities in Firefox. The model has been described by federal officials as capable of breaking into “every major operating system and web browser,” which raises the question of what Anthropic thought a third-party vendor’s contractor would do with it on his lunch break.
Treasury Secretary Scott Bessent convened a meeting of senior bankers in Washington this month to discuss Mythos. The bankers were told the model was so important to national financial security that they should consider running it against their own systems. Several of those banks are in the Project Glasswing pool. Their cybersecurity teams are now competing with a Discord server full of strangers who got there first by guessing.
OpenAI’s Sam Altman Calls It “Fear-Based Marketing,” Which Is Rich
Sam Altman, who has spent four years describing his own products as potentially world-ending and then selling them to anyone with a credit card, called Anthropic’s Mythos promotion “fear-based marketing.” This is a man who once warned the Senate that AI could “cause significant harm to the world” while simultaneously asking them not to regulate it. Sam Altman accusing someone of fear-based marketing is like Jerry Seinfeld accusing someone of overusing observational humour about airplane food.
Twelve Things Worth Noticing About the Mythos Leak
One. The model was released on a Tuesday and breached on a Tuesday. Anthropic appears to have included same-day delivery as a feature.
Two. The Discord group says they are not using the model for cyberattacks. They are using it for entertainment. The most expensive entertainment system in human history is currently being run by people who probably also have an ironic Letterboxd account.
Three. Anthropic’s official statement said the breach was confined to “one of our third-party vendor environments.” The phrase “one of our” suggests there are several third-party vendor environments, each presumably as well-secured as the first.
Four. The model is named Mythos, after the Greek word for “story.” This is appropriate, because the security plan also appears to have been a story.
Five. Mozilla used Mythos to patch 271 holes in Firefox. Those holes had presumably been there the whole time. Mozilla’s developers are currently reflecting on this as one reflects on a bad school photograph.
Six. The Discord forum is described as a community that “seeks out information about unreleased AI models.” This is the same hobby as collecting Pokémon cards, except the cards can dismantle the global banking system.
Seven. JPMorgan Chase, Goldman Sachs, Bank of America, and Morgan Stanley are all reportedly testing Mythos. Their compliance officers will be available for comment after they finish drinking.
Eight. Anthropic released the model under a programme called Project Glasswing. Glasswing butterflies are named for being transparent. This is, in retrospect, foreshadowing.
Nine. The contractor whose access was used works for an unnamed third-party vendor. Anthropic has not said which vendor. The vendor has not said anything because the vendor is presumably under a desk.
Ten. Dario Amodei has, on multiple occasions, suggested that frontier AI labs need to coordinate carefully on security to prevent leaks. The leak occurred internally before any rival lab could be blamed. Coordination achieved.
Eleven. The U.S. Treasury Secretary held a meeting about this model. The Treasury Secretary’s job is to manage trillions of dollars. He is now part of a story about a Discord server. History has a sense of humour and a low boredom threshold.
Twelve. The phrase “we are investigating” appears in every official Anthropic statement about the incident. This is the corporate equivalent of saying “I’m fine” while standing in a kitchen fire.
What Happens Next
Anthropic says it is reviewing access controls at its third-party vendors and has found “no evidence” of broader compromise. The Discord forum still has access to the model. Both of these things are simultaneously true, in the way that “the door is locked” and “the door is locked from the inside while the windows are open” are simultaneously true.
Patton Oswalt has a bit about how the future is going to be incredible because the smartest people in the world are working on it, and also terrifying because the smartest people in the world are working on it. Mythos is the bit made flesh. The most carefully controlled AI model in the world is being used by anonymous strangers to generate jokes and probably some pornography, while the company that built it is on a press tour explaining that AI must be controlled or it will doom us all.
Anthropic, headquartered in San Francisco and led by CEO Dario Amodei and President Daniela Amodei, announced its Mythos Preview model on April 7, 2026, under an initiative called Project Glasswing. The model is being shared with a small group of companies including Amazon, Apple, Cisco, JPMorgan Chase, and Nvidia, with banks including Goldman Sachs, Citigroup, Bank of America, and Morgan Stanley reportedly testing as well. Bloomberg first reported on April 21 that a private Discord forum had gained access to the model on the same day it was publicly announced, partly through a member who works for a third-party Anthropic contractor and partly by guessing the model’s URL based on Anthropic’s previous naming conventions. Anthropic told outlets including TechCrunch, CBS News, and Yahoo Finance that it was “investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments” but had found no evidence of impact to its core systems. The leak was first traced through hacked data from AI training startup Mercor. Treasury Secretary Scott Bessent convened a meeting of major American bank executives in Washington in April to discuss Mythos. OpenAI CEO Sam Altman publicly called Anthropic’s Mythos promotion “fear-based marketing.” The unauthorised users have reportedly been using the model continuously since gaining access, though not for cybersecurity purposes.
Auf Wiedersehen, amigo!
