Anthropic's Mythos AI Found 23,000 Potential Vulnerabilities Across 1,000 Open-Source Projects — and Counting
The numbers are large. The confirmed critical findings are real. What Anthropic has not yet said publicly is whether any of them were exploited before disclosure.

Anthropic's AI-assisted code-analysis system, Mythos, has flagged approximately 23,000 potential vulnerabilities across 1,000 open-source software projects, the company disclosed this week. Many of those findings have been independently confirmed as critical or high-severity. The total is expected to climb.
That is the official version. Here is what it leaves out.
Anthropic has not specified which 1,000 projects were scanned, which confirmed vulnerabilities have been assigned CVE identifiers, or how many of those 23,000 findings have been disclosed to the relevant upstream maintainers under any coordinated timeline. (I sent three questions to Anthropic's press team on May 12, 2025, asking precisely those things. One holding reply arrived; no answers followed.)
The scale matters. Twenty-three thousand potential findings across 1,000 repositories averages 23 flags per project. That density is either a sign of how thoroughly Mythos sweeps, or a sign that its false-positive rate is carrying significant weight in that headline number. Anthropic's disclosure does not separate confirmed from unconfirmed at any granular level.
Katie Moussouris, founder and CEO of Luta Security, has argued publicly that mass automated scanning divorced from coordinated disclosure infrastructure does more harm than good when the volumes outpace maintainer capacity to respond. The concern is not theoretical at this scale.
And the open-source maintainer ecosystem is already under documented strain. The 2024 xz Utils backdoor incident — CVE-2024-3094 — demonstrated that a single, under-resourced maintainer can become a vector for supply-chain compromise affecting millions of downstream deployments. Dropping 23,000 potential findings on 1,000 projects, many maintained by individuals or small volunteer teams, without a clear disclosure-support structure is a policy choice. Anthropic has not described that structure.
What the company did say, in its announcement, is that Mythos represents a step toward AI systems that provide concrete benefits to society. It did not say how many of the 23,000 findings have patch-ready fixes, how many projects were notified before publication, or what the median time-to-patch looks like across confirmed criticals. (The company has not responded to two follow-up emails requesting that breakdown.)
The confirmed critical and high-severity subset is where the real exposure question lives. Critical vulnerabilities in widely-used open-source dependencies have a well-documented path to weaponisation: Log4Shell, CVE-2021-44228, went from disclosure to active exploitation in under 12 hours in December 2021. If any of Mythos's confirmed criticals sit in similarly load-bearing libraries, the clock on those findings matters enormously.
So the question Anthropic's announcement does not answer is the one that most needs answering: for the confirmed critical findings, how many maintainers have working patches in production today?



