/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

curl founder Daniel Stenberg says Mythos identified five vulnerabilities in curl, but a manual review found three were false positives and one was “just a bug”

daniel.haxx.se Daniel Stenberg

Context & Ripple Effects

This sits in a longer dispute over AI-assisted security reporting: Stenberg has previously said low-quality LLM-generated submissions consume scarce open-source maintainer time, including through bug-bounty channels. The new review provides a concrete test of that concern for Mythos’s output.

The result also complicates broader claims for Mythos. Anthropic has presented the model as a broad vulnerability-finding system, while Cloudflare’s subsequent testing focuses on repository-scale evaluation and exploit chaining rather than accepting individual findings uncritically.

First-order effects

  • curl maintainers must spend manual-review time separating actionable defects from false vulnerability reports; the reviewed set yielded three false positives and one ordinary bug rather than the claimed security issues.
  • Mythos’s curl result loses credibility as evidence of its vulnerability-detection accuracy unless its findings are independently reproduced and triaged.

Second-order effects

  • Security teams evaluating Mythos or similar systems will need validation workflows that distinguish exploitable vulnerabilities from generic defects and incorrect reports before escalating findings.
  • For open-source projects, automated reporting can shift costs toward maintainers unless tool vendors or deploying organizations absorb more of the triage and evidence burden.

Third-order effects

  • If high-volume AI security reporting continues to produce unevenly validated findings, vulnerability discovery will increasingly be judged on precision, reproducibility, and triage integration—not raw finding counts.
  • The pattern could deepen a split between AI tools used as analyst aids inside accountable security workflows and automated submissions sent directly to maintainers, where noise imposes externalized costs.

The trend: AI-driven vulnerability discovery is moving from headline finding totals toward scrutiny of verification quality and the operational cost of false positives.

Discussion

  • @morqon Morgan on x
    mythos scans curl, finds one “severity low” vulnerability, one bug, and three false positives already described in the docs [image]
  • @zackkorman Zack Korman on x
    Mythos found a single vulnerability in cURL (along with three false positives, and one issue they classified as a bug). The founder/lead dev wasn't super impressed. [image]
  • @lukolejnik Lukasz Olejnik on x
    “I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos”. But: read-up. https://daniel.haxx.se/... [image]
  • @martenmickos @martenmickos on x
    Mythos found one (1) vulnerability in curl - an open-source software product with an installed base of 20 billion instances. https://daniel.haxx.se/...
  • @stdlib @stdlib on bluesky
    lol someone on lobsters actually suggested Mythos did not find a bug here and Anthropic might secretly be buying black market exploits and passing them off as if they were from Mythos. we are approaching unimaginable, unhealthy levels of cope daniel.haxx.se/blog/2026/05...
  • r/BetterOffline r on reddit
    Mythos finds a vulnerability in curl, a single low severity one, and curl's creator is not impressed, calls it “a succesful marketing stunt”.
  • r/ClaudeAI r on reddit
    Curl maintainer utilized Anthropic's Mythos scan: 1 confirmed vulnerability and ~20 bugs
  • r/theprimeagen r on reddit
    Mythos finds a curl vulnerability
  • r/claude r on reddit
    Anthropic's bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
  • r/netsec r on reddit
    Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results