Palo Alto Networks says Mythos found 24+ critical bugs using $1M+ in tokens; Anthropic subsidizes Mythos but some companies plan to boost their Mythos budgets
Aaron Holmes /The Information:
Context & Ripple Effects
Mythos’s reported results at Palo Alto Networks extend Anthropic’s earlier claim that the preview model had found thousands of high-severity vulnerabilities across major software categories. Cloudflare’s testing across more than 50 repositories added a separate example of organizations evaluating it through structured vulnerability-discovery harnesses.
The Palo Alto report also puts an operating-cost figure around that capability: finding critical bugs required more than $1 million in tokens, with Anthropic subsidizing usage. That makes deployment economics as consequential as raw model performance.
First-order effects
- Palo Alto Networks has a larger set of critical bugs to validate, remediate, and coordinate disclosure around, while Mythos becomes a more credible tool for high-volume vulnerability research.
- Anthropic’s subsidy lowers the immediate cost barrier for customers testing Mythos; companies planning higher budgets signal that some see enough security value to fund continued use.
Second-order effects
- Security teams evaluating Mythos will need to measure findings quality, remediation capacity, and token spend together; a tool that surfaces more bugs can shift the bottleneck from discovery to triage and patching.
- Cloudflare’s repository-scale tests and the reported ability to chain bugs into exploits give other vendors and large software operators a clearer template for assessing AI-assisted vulnerability research, while raising urgency around disclosed vulnerabilities.
Third-order effects
- If subsidy-backed use converts into repeatable customer spending, AI security tooling may be priced and adopted around cost per validated finding or remediated risk rather than model access alone.
- The same capability that accelerates defensive bug discovery can shorten the path from public vulnerability disclosure to exploitation, as Anthropic researchers have reported; durable adoption will depend on whether defenders can operationalize patching at comparable speed.
The trend: This is one data point in the shift from AI-assisted code review toward agentic vulnerability research whose usefulness is increasingly constrained by remediation throughput and inference economics.