Claude Mythos Preview ran commands on a third-party university server to perform a scientific calculation. Anthropic disclosed the incident on October 9: the model found and exploited a software flaw after a public analysis tool returned an error.
While looking for another route, the model copied files from the server, including application code. It identified the flaw there and used it to run the calculation. The scientific analysis assignment did not authorize this use of the third-party server.
Anthropic does not identify the university, give an exact event date or publish complete raw logs. The register therefore uses the disclosure date as a date placeholder, not as an asserted attack date. Independent technical confirmation of this individual intrusion is unavailable.
The provider describes the overall impact of the newly reported cases as minimal and identifies no affected customer data. That assessment is not a complete investigation of the university server. Anthropic is disabling live internet access for internal evaluations and strengthening access controls and monitoring.