Latest / Elon Musk Podcast / Anthropic Claude Mythos Hacked Global Infrastructure
Transcript
- 0:00Anthropic built an artificial intelligence model so dangerous
- 0:03it autonomously hacked into software infrastructure that had
- 0:06been secure for decades, prompting the company to lock
- 0:10the technology away from the public entirely.
- 0:12Yeah, that model is Claude Mythos.
- 0:14It actually uncovered a hidden vulnerability in the open BSD
- 0:17operating system that had sat completely undetected for a
- 0:21really, really long time. We are essentially looking at a
- 0:25fundamental tension here between these incredible technological
- 0:29capabilities and just a complete loss of control over how those
- 0:32capabilities operate out in the wild.
- 0:34So how did a technology deemed too dangerous to release, spark
- 0:38a legal war with the military, prompt this highly exclusive
- 0:41corporate alliance, and get breached by a random discord
- 0:44group all at the exact same time?
- 0:46To understand how all these threads connect, we have to, you
- 0:49know, look at what this model actually is internally.
- 0:52Anthropic called this the Capybarrateer.
- 0:54And The thing is, Anthropic did not explicitly train this model
- 0:57to execute cyberattacks, right? Like it wasn't fed endless
- 1:01databases of malicious code with instructions to just break
- 1:04things. What totally blows my mind here
- 1:06is the origin of these offensive skills.
- 1:08They emerged entirely as a byproduct of its advanced
- 1:11reasoning and coding capabilities.
- 1:13Like when an artificial intelligence gets exceptionally
- 1:16good at understanding what a piece of code is supposed to do,
- 1:19and then it compares that to what the code actually does.
- 1:22It spots the difference. Exactly.
- 1:23It recognizes the gap between those two states, and that gap
- 1:26is where vulnerabilities live. So the model essentially learned
- 1:30to just reason its way through complex software logic.
- 1:33And the results from that reasoning process are just
- 1:35staggering. I mean, Mythos found a bug in
- 1:38FFM PEG code. And for context for you
- 1:41listening, FFM PEG is the underlying technology used for
- 1:44video encoding and decoding all over the Internet.
- 1:46Yeah, it's everywhere. Pretty much every time you watch
- 1:49a video online, FFM PEG is involved in making sure those
- 1:52pixels actually render correctly on your screen.
- 1:55If an attacker controls an FFM PEG vulnerability, they could
- 1:59theoretically compromise your device just by having you stream
- 2:02a video. Yeah, a maliciously crafted
- 2:04video file could execute code on your laptop while you just sit
- 2:08there thinking you're watching a standard clip.
- 2:10And that specific bug had been missed by 5 million automated
- 2:14fuzz tests. And fuzz testing is where
- 2:18developers basically just throw massive amounts of random data
- 2:21at a program to see if it crashes.
- 2:24If you are testing the structural integrity of a house,
- 2:27fuzz testing is like driving a bulldozer into the living room.
- 2:30You know, throwing rocks at the windows and blasting the roof
- 2:34with a fire hose just to see what breaks.
- 2:36Right, it's pure brute force, and millions of those tests just
- 2:39missed the flaw. But Mythos didn't do that.
- 2:42It read the architectural blueprints, noticed a load
- 2:45bearing pillar was missing a single bolt, and realized a
- 2:48slight breeze from a specific angle would collapse the whole
- 2:51structure. That is.
- 2:52Wild it reasoned its way to the flaw without firing a single
- 2:55random test. But it goes far beyond just
- 2:57finding single bugs, right? Because Mythos autonomously
- 3:00chained multiple vulnerabilities together to achieve complete
- 3:04Linux kernel privilege escalation.
- 3:06And normally, if you access a computer, you are just a guest
- 3:10user. You can browse the Internet,
- 3:11maybe open a document, but you obviously can't delete system
- 3:14files or install malware. Privilege escalation is well,
- 3:18it's like walking into an office building as a visitor, finding a
- 3:21janitor's closet left unlocked, grabbing a master key from that
- 3:24closet, using that key to enter the security room.
- 3:27And suddenly you own the building.
- 3:28Yes, suddenly you can disable all the cameras and unlock the
- 3:32main vault. It found a tiny flaw, used that
- 3:35to access another system, found a flaw there, and Justice KET
- 3:38climbing the ladder until it went from having basic user
- 3:42access to total root control of the machine.
- 3:45And it did all of this without human guidance.
- 3:48Well, let me reset the pace for a second.
- 3:49Here, we're talking about a machine moving from a basic
- 3:53level of access to total control entirely on its own.
- 3:56The window between vulnerability discovery and exploitation
- 3:59shrinks to practically 0. It fundamentally alters how
- 4:03defenders must respond to cyber threats, because if an attacker
- 4:06has this capability, human defenders simply cannot type
- 4:10fast enough to patch systems and keep up with machine speed
- 4:12attacks. And that exact realization LED
- 4:16directly to Project Glass Wing. Recognizing the extreme danger,
- 4:20Anthropic restricted access to this model, limiting it to a 40
- 4:24company alliance. We're talking about heavyweights
- 4:27here, Apple, Google, Microsoft and Crowdstrike.
- 4:31The big players. Exactly.
- 4:33Anthropic also backed this initiative with a $100 million
- 4:37credit pool for these companies to run intensive scans on their
- 4:40infrastructure to find and fix bugs before adversaries could
- 4:44exploit them. I have to push back on the
- 4:45setup, though. I mean, is this like giving the
- 4:47world's smartest guard dog exclusively to billionaires
- 4:50while everyone else just has to leave their doors unlocked?
- 4:52But keeping this tool within an exclusive circle?
- 4:55You create massive antitrust risks.
- 4:57Smaller cybersecurity firms are totally excluded, right?
- 5:00They get nothing. And major operational technology
- 5:02and industrial control system vendors are entirely left out of
- 5:05the alliance. Companies like Siemens and
- 5:07Rockwell, they build the actual software that runs physical
- 5:11infrastructure. We are talking water treatment
- 5:14plants, power grids, factory floors.
- 5:17If they don't get the artificial intelligence to patch their
- 5:20flaws, our physical infrastructure remains totally
- 5:23exposed while tech monopolies secure their search engines and
- 5:26cloud servers. It creates a huge transparency
- 5:29vacuum. This arrangement concentrates
- 5:31security advantages among existing monopolies.
- 5:35Section 1 of the Sherman Antitrust Act prohibits
- 5:37combinations and restraint of trade, and that includes certain
- 5:41types of information sharing. When forty of the most powerful
- 5:44firms share technical data and best practices in a private
- 5:47circle, it risks aligning their market behavior in ways that
- 5:51suppress competition. Smaller competitors are simply
- 5:54denied the opportunity to safety proof their systems at the exact
- 5:57same speed. So the most advanced security
- 5:59tool ever created is essentially locked in this corporate
- 6:02fortress to prevent a global catastrophe.
- 6:04But that exclusive fortress was bypassed almost immediately by a
- 6:08private Discord group. Wait, back up.
- 6:10Stop right there. How does a group of random
- 6:13Discord users access the most guarded artificial intelligence
- 6:17code on Earth? What fascinates me here is that
- 6:20this wasn't some like Mission Impossible style heist.
- 6:24Nobody shattered complex encryption algorithms.
- 6:26They didn't crack AES 256 encryption or anything.
- 6:30It was a cascading chain of human errors across a supply
- 6:33chain. They basically just walked
- 6:35through a side door that someone left propped to open first.
- 6:38Anthropic had a misconfigured content management system.
- 6:42Assets published there were set to public by default unless
- 6:46explicitly changed. Yeah, that error alone exposed
- 6:50thousands of internal assets. And then a packaging error
- 6:53leaked the architecture for a related tool, specifically an
- 6:57NPM packaging error. That's Node package manager.
- 7:01When developers build software they pull in pre written bundles
- 7:03of code called packages so they don't have to write everything
- 7:06from scratch. Makes sense, but if a developer
- 7:08accidentally publishes an internal package to the public
- 7:11registry instead of their private one, anyone can download
- 7:13it. So a developer might be rushing
- 7:15to meet a deadline, they push an update, and they accidentally
- 7:18type the command to publish to the public and PM registry
- 7:21instead of the internal company server.
- 7:23Just one typo and that package contained references to the
- 7:27internal architecture, but the real fatal blow was a breach at
- 7:31a third party training contractor named Mercker.
- 7:34Right, because training contractors hire thousands of
- 7:37people to rate artificial intelligence outputs and they
- 7:40need access to company systems to do their jobs.
- 7:44So you end up with a massive surface area of human workers
- 7:47and literally any one of them might reuse a password or fall
- 7:50for a phishing scam. Which is exactly what happened.
- 7:53They lost terabytes of data, Slack Communications internal
- 7:56tickets, and, crucially, Anthropics internal naming
- 7:59conventions for unreleased models.
- 8:01The Discord group found out that the Mythos project followed a
- 8:04specific alphanumeric formatting pattern for its web addresses.
- 8:07So the group used a technique called location guessing because
- 8:12they knew the internal code name was Capybara and they understood
- 8:15the semantic structure Anthropic used for their URLs.
- 8:18From that Mercury leak they knew the addresses probably look
- 8:21something like model Capybara V1 internal.
- 8:24They just iterated through potential web addresses until
- 8:27they found the specific Capybara endpoint on Anthropics
- 8:31interface. But finding the door is one
- 8:33thing. They still needed a way to get
- 8:34inside. Exactly.
- 8:36And one member of this discord group happened to be a third
- 8:39party contractor for Anthropic. They had valid API credentials.
- 8:43While those credentials were not explicitly authorized for
- 8:46Mythos, they remained functional within the broader environment
- 8:49because of excessive permissions granted to contractors.
- 8:53It's like figuring out a hotel's room numbering system, wandering
- 8:56the halls until you find the hidden VIP suite, and then
- 8:59realizing your generic cleaning staff key card hasn't been
- 9:03deactivated yet. And for some bizarre reason, it
- 9:05opens the penthouse door, right. They plug their valid
- 9:08credentials into the hidden URL they guessed and they were in.
- 9:12This exposes the extreme fragility of the artificial
- 9:15intelligence supply chain. The security of this world
- 9:18altering technology is only as strong as the absolute weakest
- 9:23third party contractor. It opens up entirely new vectors
- 9:27for cyber criminals. You don't need to hack the
- 9:29heavily fortified central servers if you can just find an
- 9:32external vendor with sloppy access controls and a leaky
- 9:36communication channel. So if a private company cannot
- 9:39keep hobbyists out of their most dangerous systems, who should be
- 9:42managing this technology? The United States government
- 9:45observed these capabilities and demanded Anthropic amend its
- 9:48defense contracts to allow any lawful use of their artificial
- 9:52intelligence. But Anthropic refused.
- 9:54They maintained 2 absolute red lines in their negotiations.
- 9:58First, they explicitly banned the use of their models for mass
- 10:01domestic surveillance of citizens.
- 10:03And second, they prohibited their technology from powering
- 10:06fully autonomous weapons without human oversight over targeting
- 10:10and firing decisions. And the government retaliated
- 10:12aggressively. The Pentagon actually designated
- 10:14Anthropic a supply chain risk. Yeah, that is a highly specific
- 10:19label normally used for foreign adversaries capable of covert
- 10:23sabotage. Putting that label on a domestic
- 10:26tech company is an extraordinary escalation.
- 10:28The president then issued A directive ordering all federal
- 10:32agencies to immediately cease using Anthropic technology.
- 10:36The General Services Administration even terminated
- 10:39the contract that made the company's services available
- 10:42across the federal government. But Anthropic fought back.
- 10:45They sued the government, alleging First Amendment
- 10:47retaliation and due process violations.
- 10:50They argued they were being punished for their public
- 10:52advocacy regarding safety guardrails.
- 10:55They also pointed out the government failed to follow the
- 10:57procedural steps required by law before excluding A vendor from
- 11:00federal supply chains. And a federal judge actually
- 11:03agreed with him, securing A preliminary injunction and
- 11:06calling the government's motives pretextual.
- 11:09This changes the power dynamic in military contract and
- 11:12completely it forces society to ask whether a private tech
- 11:15corporation can legally dictate operational constraints to the
- 11:19armed forces. Well, the military argues a
- 11:21private contractor should not hold veto power over lawful
- 11:25operational decisions. But the tech company argues
- 11:29their systems are simply not reliable enough for lethal
- 11:32environments and can make totally inexplicable, reckless
- 11:35decisions. Yet despite the federal ban and
- 11:38the supply chain risk designation, the National
- 11:41Security Agency confirmed they are still actively deploying
- 11:45Mythos. The irony is just wild.
- 11:47The intelligence community is relying heavily on the exact
- 11:49tool the military blacklisted, right?
- 11:52The NSA operates in the realm of signals intelligence and cyber
- 11:55espionage. They collect zero day
- 11:57vulnerabilities. They don't care about the red
- 11:59line regarding autonomous weapons because they aren't
- 12:01flying drones. They are infiltrating networks.
- 12:04So they just quietly keep using the tool while the rest of the
- 12:07federal government publicly bans it.
- 12:09It creates A deeply confusing compliance environment for
- 12:12federal agencies and defense contractors who were told to
- 12:15literally cease commercial activity with the company while
- 12:18a major intelligence agency continues to run the most
- 12:21restricted version of the platform.
- 12:23Meanwhile, Open AI struck a deal with the Pentagon by agreeing to
- 12:26their terms. Instead of imposing new
- 12:28technical red lines, they just relied on existing legal
- 12:31frameworks. They launched GPT 5.4 cyber with
- 12:35a much wider, way less restricted roll out.
- 12:38Their whole philosophy is that no one should be picking winners
- 12:41and losers in cybersecurity and that wider access to the taste,
- 12:44faster defense. But some experts argue the
- 12:47apocalyptic narrative around mythos is overblown.
- 12:50The Artificial Intelligence Security Institute analyzed the
- 12:53model and noted it struggles significantly when actual
- 12:56security alerts and active defenses are running in the test
- 12:59environment. I really have to highlight the
- 13:01critique from researchers in investigating the actual data
- 13:04here. The flagship demonstration of
- 13:06the models power involved finding vulnerabilities in a web
- 13:09browser. But critics pointed out the
- 13:11model exploited bugs that an older model had already found
- 13:14inside a patched browser in a test harness, where the
- 13:16sandboxing and basic defenses were entirely stripped out.
- 13:20Yeah, let me explain why stripping out the sandbox
- 13:22matters. A sandbox and software is an
- 13:24isolated environment. It restricts what a program can
- 13:27do so that if a piece of code goes rogue, it cannot infect the
- 13:31rest of your computer. Taking the sandbox away for the
- 13:34test is like bragging about picking a lock but conveniently
- 13:38omitting that the door was already taken off its hinges.
- 13:40Right. And when you remove those
- 13:42artificial advantages, the Exploits accessory plummets from
- 13:45over 70% down to roughly 4%. So critics suggest Anthropics
- 13:50too dangerous to release stands might just be marketing a
- 13:54corporate strategy designed to avoid open sourcing the
- 13:56technology or sharing it more widely, all under the guise of
- 14:00an existential security threat. Wait, hold on, Even if the
- 14:03success rate drops to 4%, is that actually comforting?
- 14:06If a machine can execute 10,000 exploit attempts in a minute, a
- 14:104% success rate still means it is breaching your system 400
- 14:13times. That is exactly the counter
- 14:16argument. A low success rate at machine
- 14:18speed, still a huge volume of successful hacks.
- 14:22But if safety warnings are perceived as just another
- 14:25corporate strategy to maintain market dominance, actual
- 14:28existential threats might just be ignored by regulators and the
- 14:32public when they finally do arrive.
- 14:34The emergence of autonomous cyber capabilities forces
- 14:38society to rethink security entirely, basically pitting
- 14:42private corporate alliances against government demands and
- 14:44rogue hackers. And it really leaves us
- 14:46wondering who ultimately gets to decide the rules of engagement
- 14:49in this new era of automated warfare?
- 14:52Elected governments or private techs?
- 14:54Executives. If you're not subscribed yet,
- 14:56take a second and hit follow on whatever app you're using.
- 14:58It helps us keep making this. We appreciate you being here.
- 15:01Also, check out our YouTube channel for more business and
- 15:03tech updates. There's a link in the
- 15:04description.