[BidClub_]
Sharp Tech · · 22 min

(Preview) Mythos and Project Glasswing, The Year of Anthropic Continues Apace, Q&A on the NYT, Altman, De-globalization

Andrew SharpBen Thompson

Podcast
TL;DR
  • Anthropic’s Mythos makes AI-driven vulnerability discovery a near-term security event, even if its exact current capability remains unknowable from outside. The preview is limited to roughly 50 critical-infrastructure organizations, including Amazon, Microsoft, Apple, Google, and the Linux Foundation. Ben Thompson’s long-term call is categorical: legacy software contains vast numbers of bugs, models excel at exhaustive review, and eventually “the wolf does come.”
  • Keeping Mythos private aligns Anthropic’s safety case with its commercial interest in preserving market power and pricing power. Thompson connects this to the Anthropic team’s earlier work at OpenAI, where withholding GPT-2 could reflect genuine risk while also preventing competitors from copying the frontier. A self-serve API makes determined distillation “pretty hard to stop.”
  • Distillation narrows the model moat without eliminating it. Thompson says copied models remain “much more jagged,” less comprehensive, and behind the original—but can still be “more than good enough” against expensive frontier products. His explanation for open-source models trailing by roughly six months: that is about how long it takes to query leading APIs “a gazillion times” and train on the outputs.
  • Compute scarcity is already determining Anthropic’s product quality, access, and economics. Thompson says the company can “barely stay online,” while rationing, quantization, caching, batching, and serving distilled models cumulatively degrade the experience. Mythos is priced at roughly 5X Opus, itself significantly more expensive than GPT-5.4, strengthening the case for restricting access to customers paying “real money.”
  • The best immediate use of Mythos is finding and patching vulnerabilities before hostile actors obtain equivalent capabilities. A listener cited researchers reportedly finding more vulnerabilities in one or two months than over entire careers; Thompson conceded that this defensive deployment is plainly valuable. He tentatively linked a possible anonymous-reporting mode in leaked Quad Code source code to a Linux kernel group receiving extraordinary volumes of valid bug reports, while hedging that Anthropic’s role was uncertain.
  • Mythos intensifies the unresolved sovereignty conflict between frontier labs and governments. Andrew Sharp asks why private individuals should possess technology potentially able to penetrate companies and states, and says nationalization would likely damage Anthropic. Thompson counters that law ultimately depends on “the people who have the guns.” Washington might fear Anthropic hacking it—or decide it wants a capability like Mythos to hack China.
Digest · the substance, structured for research

1. Mythos turns code’s AI advantage into a security threat

  • Sharp’s setup: Anthropic is previewing Mythos with about 50 critical-infrastructure organizations but has no present plan for public release because it can find and exploit software vulnerabilities.

  • Thompson’s mechanism is straightforward: software is “massive amounts of language,” unusually predictable for large language models, while computers excel at the boring, line-by-line “yeoman’s work” required to inspect it.

  • Sharp calls the threat imminent; Thompson keeps the timing hedged. Mythos might already be as capable as claimed, but millions or billions of human-written lines inevitably contain bugs that increasingly capable models will uncover.

2. Safety and pricing power point toward the same closed model

  • Thompson’s cynical-but-not-dismissive framing: he points to the Anthropic team’s earlier work at OpenAI, where GPT-2 was withheld over danger concerns, but “not being open is actually good for business.” Preventing near-equivalent models also protects long-run market and pricing power.

  • DeepSeek supplies his concrete analogy: leading APIs can be queried “a gazillion times” to generate training data, helping explain why open-source alternatives may remain about six months behind the frontier.

  • Sharp asks whether distillation can reliably be prevented. Thompson’s answer is effectively no: copied models have more holes and remain less comprehensive, but policing high-speed API queries routed through cloud servers is much harder than “policing uranium.”

3. Scarce compute makes Mythos a premium product

  • Thompson says Anthropic can “barely stay online.” Five-hour usage blocks are not actually five hours: they can be shorter at certain times of day and longer at others. Quantization, serving distilled models, caching, and batching layer together and diminish quality—even if the degradation is not deliberate.

  • The pricing makes selective access commercially rational: Mythos costs roughly 5X Opus, and Opus is already significantly more expensive than the smaller GPT-5.4. Restricting access to customers who pay “real money” is therefore a business justification.

4. Defensive bug-finding is the strongest case for deployment

  • An anonymous listener’s challenge: leading security researchers reportedly found more vulnerabilities with Mythos in the last month or two than throughout their careers. Thompson accepts the narrow prescription—find and patch as many bugs as possible before bad actors gain comparable tools.

  • He tentatively links that effort to an apparent “hiding mode” in leaked Quad Code source code and a Linux kernel group receiving huge numbers of reports that were “all real bugs.” How much of that activity was actually Anthropic’s work remains an open question.

  • Thompson rejects the characterization that his criticism implies contempt: his concern is “rooted in deep respect and appreciation” because Anthropic is legitimate and has its act together in a major way.

5. Frontier capability creates a state-versus-lab power struggle

  • Sharp’s pushback — worth keeping: if Mythos could hack companies and governments worldwide, “why should a private company have all this power?” He expects government nationalization to damage Anthropic, yet sees the concentration itself as dangerous.

  • Thompson ties this to the unresolved tension from the recent dispute between Anthropic and the U.S. government. His realpolitik answer: laws are downstream from coercive power. If the state feels fundamentally threatened by someone developing “a better gun,” it may ignore legal restraints and take or constrain that capability.

  • The conflict cuts both ways: Washington could fear dependence on Anthropic’s goodwill not to attack it, or seek a capability like Mythos for offensive operations against China. Responsible patching is still, in Thompson’s view, “inviting and accentuating” a fundamental, unresolved tension.

Andrew Sharp

Hello, and welcome to a free preview of Sharp Tech. Hello, and welcome back to another episode of Sharp Tech. I'm Andrew Sharp, and on the other line is Ben Thompson. Ben, how are you doing?

Ben Thompson

I'm working through the five stages of grief.

Andrew Sharp

Harried?

Ben Thompson

What are the stages again? I was never mad, but there's—

Andrew Sharp

Bargaining is one of them. Acceptance is the final stage. Denial is definitely one of the stages as well.

Ben Thompson

Yeah. Well, you and I are together in the permanent underclass.

Andrew Sharp

Oh, boy.

Ben Thompson

We do not have access to Mythos. We are—

Andrew Sharp

Not part of Glasswing here at Stratechery—

Ben Thompson

Yeah.

Andrew Sharp

Unfortunately.

Ben Thompson

We're down at the bottom, just mucking along as best we can, making some podcasts. It is what it is.

Andrew Sharp

Just speculating from the outside. That's all we can do today, but that is what we will do. I'll begin with The Wall Street Journal.

Ben Thompson

By the way—

Andrew Sharp

Anthropic—

Ben Thompson

I used the exact same opening on Dithering. Maybe I need more material. Maybe that's why I'm in the permanent underclass.

Andrew Sharp

Cross-platform promotion.

Ben Thompson

I know.

Andrew Sharp

That's 2 weeks in a row now. I love to see it.

Ben Thompson

That's good. I'm now kind of feeling self-chastised. I need to get some new material.

Andrew Sharp

Well, it's self-chastised, so at least you're consistent with your mispronunciation. The brand remains strong here, and we will begin with The Wall Street Journal.

1. Mythos Finds The Bugs

Anthropic is taking steps to arm some of the world's biggest technology companies with tools to find and patch bugs in their hardware and software. The company is making a preview model of its new AI model, called Mythos, available to about 50 companies and organizations that maintain critical infrastructure, including Amazon, Microsoft, Apple, Alphabet-owned Google, and the Linux Foundation.

Mythos has proved to be so capable at potentially dangerous things, such as finding and exploiting software bugs, that Anthropic has, at present, no plans to release it to the general public, said Logan Graham, the head of Anthropic's Frontier Red Team, which evaluates Claude for risks.

So, Ben, generally speaking, I'll let you take it any direction you want. You wrote about Anthropic on both Tuesday and Wednesday, and this Mythos model—reading about it was pretty unsettling earlier in the week. What do you think of what's happening here?

Ben Thompson

Why is it unsettling? We just discussed it on Sharp Tech a week ago.

Andrew Sharp

Well, exactly. What we discussed, and the threats to security that we discussed, now appear to be imminent, albeit private for the time being. So I guess we can take solace in that.

Ben Thompson

Maybe that's why we're already at stage 5. I think it was a very timely discussion we had last week about the reality that this actually ties into a long-running discussion that we've had, particularly this year, about the uniqueness of programming and code, and its suitability for large language models.

Andrew Sharp

Mm-hmm.

Ben Thompson

How do you program? You put a bunch of words and symbols together in sort of arcane ways that can be difficult for a lot of humans to do. But computers are quite good at it. Large language models, in particular, can handle large amounts of language, which, at the end of the day, all software is: just massive amounts of language.

Andrew Sharp

Mm-hmm.

Ben Thompson

Again, that language may not be very understandable to you or me, but it is very predictable and understandable. Given what we've talked about, this should not be a surprise to us or to our listeners.

So, here we are. Now, how here are we? This is Anthropic. These are the same people who—going back, it's funny, people are like, "OpenAI did this too." No, the Anthropic people did this at OpenAI.

Andrew Sharp

At OpenAI. Yeah.

Ben Thompson

They're like, "Why is OpenAI not open?" Because GPT-2 posed too many dangers to the world, so it's like, "Yeah, we're not going to be open anymore." It just so happens that not being open is actually good for business.

So, let me back up. No one get mad at me until we finish this whole segment, okay?

Andrew Sharp

Okay.

Ben Thompson

Because we're going to cover lots of different areas. I already see our first email is someone that's very mad at me, so, Mr. Anonymous, relax. We're going to get there, okay?

You go back to 2019—I think it was 2019 when GPT-2 came out—and there was, "This is dangerous." There's also, "Maybe it's not the best thing in the world if we're on the leading edge to give everyone our weights," because then they can just run the model themselves, right?

Andrew Sharp

Yeah.

2. Distillation Makes Secrecy Fragile

Ben Thompson

The equivalent here—and, by the way, I think another area where we were very early—what was one of the points that we brought up with DeepSeek a year and a half ago? DeepSeek looks like it's kind of distilled from leading U.S. models.

Andrew Sharp

Mm-hmm.

Ben Thompson

Everyone just sort of takes it as a given, or they hold it up as an excuse when these labs are complaining about distillation. We've talked about this idea that you basically query the API a gazillion times for all sorts of things, and you get your own data from the model to train your own model.

How do you get these models? Why is open source only 6 months behind? Well, because it takes about 6 months to query the models a gazillion times.

Andrew Sharp

And successfully distill them. Can I ask 1 question on that? Because this came up on Sharp China, and it's come up a couple of different times on Sharp China, and I don't have a good answer. As a tech podcaster, I feel like I'm failing Bill Bishop in the course of these conversations.

Is there a way to reliably prevent distillation in the future? Because distilling a model that's as powerful as Mythos seems like it could be a problem going forward.

Ben Thompson

Yeah. A distilled model is never going to be quite as good as the regular one, and it's much more jagged. There are many more holes, much less comprehensive. In general, it's a bit where they're always going to be behind to a certain extent.

Andrew Sharp

Mm-hmm.

Ben Thompson

But that doesn't change the fact that if they're more than good enough, and these leading-edge models are very expensive, it's a great alternative if you want something else.

3. Anthropic Protects Its Pricing Power

To go back to this story, there's a very good business reason for not making this available, just like there's a good reason for not making open weights available. It's the same story.

Andrew Sharp

Yeah.

Ben Thompson

If you think about these companies wanting to have market power and pricing power in the long run, making sure there aren't nearly as good models, to the extent you can, is a way to do that.

The challenge is, if you have a self-serve, walk-up API that anyone can use, it's pretty hard to stop. We've all pirated music. It's not exactly the same story, other than to say that trying to stop people from doing stuff on the internet when there are open APIs and things that you can access is a tough game.

Andrew Sharp

Effectively impossible. You can make it harder, but not impossible.

Ben Thompson

Right. It's one of those things you often find after it's happened. You go through your logs and say, "Wow, we're getting hit on this endpoint from this set of IP addresses a gazillion times," which have been routed through a gazillion points. They're not coming from, like, the Forbidden City IP range and accessing the model. They're spinning up cloud servers on DigitalOcean or AWS or whatever and doing this. Probably AWS would be too expensive, but it's not easy, basically.

Andrew Sharp

Mm-hmm.

Ben Thompson

Just as a rough analogy, policing chips is a lot harder than policing uranium, for example.

Andrew Sharp

Yeah.

Ben Thompson

Right?

Andrew Sharp

Which you can see from satellites, and it's much easier to track all over the world.

Ben Thompson

Right. There's a bit where, if someone breaks into OpenAI and exfiltrates the weights, there's very clear thievery going on. If you're just asking a bunch of questions at a very high rate of speed—which computers are very good at—it's a lot tougher to stop.

4. Anthropic Rations Access

So, you have this sort of business issue. You also have the fact that Anthropic can barely stay online right now, right? The people—it's this massive upsurge in revenue and users. They're doing this weird rationing thing, like these 5-hour blocks, which aren't really 5 hours, because the 5 hours is shorter than 5 hours during certain times of day and then longer at other times.

People are complaining, saying, “Oh, they're purposely reducing the model quality.” There's definitely—I mean, they're serving distilled models themselves, and you can distill much more effectively if it's your model and you have full access to it instead of just using the API. They're quantizing, but they're also doing lots of things like trying to leverage cache and batch a bunch of stuff together. All these optimizations layer on each other to really diminish the experience.

Andrew Sharp

Mm-hmm.

Ben Thompson

To the extent that it's very hard to separate whether it's on purpose. I don't think it's on purpose, but it's inevitable as you're trying to scale up this compute. Even then, they can barely stay online, right?

Andrew Sharp

Yeah.

Ben Thompson

You have this new model that comes out that is extremely computationally expensive and intense. You just look at the API pricing, which is 5 times what Opus is. And, by the way, Opus is significantly more expensive than, say, GPT-5.4, which is an even smaller model. So if we could limit it not to the hoi polloi, but to people who will actually pay us real money, that's also a good business justification, right?

Andrew Sharp

Yeah.

Ben Thompson

They'd rather—

Andrew Sharp

All this is making me feel much better as we read about a potentially existentially dangerous model here. There are lots of rational reasons to approach it this way.

Ben Thompson

Right. But where we started is, the danger's totally plausible. Even if the danger—and this is why I told everyone to hold off, the people who want to be mad at me—even if it's possible they're overstating it right now, it doesn't mean they're overstating the reality in 6 months or 9 months or a year.

The fact of the matter is, we are going to have a crisis of millions, not thousands, billions of lines of code that have been built by humans from the beginning of the computing era till now, which unquestionably contain tons and tons of bugs, because that is just the reality of software. Theoretically, you could have tons and tons and millions of humans go over them and find them all, but that's not practical.

Andrew Sharp

Mm-hmm.

Ben Thompson

What are computers really good at? Doing boring, sort of—

Andrew Sharp

Yeoman's work

Ben Thompson

—line-by-line, yeoman's work and going over and working through everything. The larger these models get, the more capable they get, the larger context they have, and the more—yes, this is going to happen. If it's not happening now—and it might be happening now—it will be happening in the future, so it's almost pointless to speculate on where Anthropic is with this.

Andrew Sharp

Yeah.

Ben Thompson

I'll give Anthropic more grace here, basically. I consistently criticize them for overstating where they're at right now, and it's very much a “boy who cried wolf” situation. This is why I brought up the boy-who-cried-wolf analogy.

People talk about the boy crying wolf, and they only talk about the first 80% of the story, where the boy keeps crying wolf.

Andrew Sharp

Yeah.

Ben Thompson

At the end of the story, the wolf does come, right? It's not that the wolf didn't exist.

Andrew Sharp

And you know what? I actually was not familiar—I mean, I've obviously been familiar with the fable, but I didn't know that the wolf does come at the end of the “The Boy Who Cried Wolf” fable until reading Stratechery earlier in the week.

Ben Thompson

What? How is this possible?

Andrew Sharp

It's been probably 35 years since I read that story. Over time, I'm familiar with the cliché and not necessarily the original text undergirding the cliché that involved all the yeoman's work.

Ben Thompson

Well, the great thing is that all of those fables, the real versions, are very dark.

Andrew Sharp

Dark.

Ben Thompson

Arguably, that's something we've forgotten, right? The point of them was to instill healthy fear and instincts into children, right? There's been a real movement to soften all these things and make them more complex.

Andrew Sharp

Oh, believe me, I'm reading children's books every single night, and nobody ever dies. Nothing bad ever happens. Whereas my wife grew up with her mom reading her German fables—

Ben Thompson

That's right. The original German ones.

Andrew Sharp

They're really grisly. So perhaps we're at a better place on that front, or perhaps not. Perhaps children needed those lessons from the Germans way back when.

Ben Thompson

I think that might be the case.

Andrew Sharp

Well, you teased this email. I'll read it from Anonymous. He says:

“I was annoyed by Ben's daily update today about Mythos. Yes, there are lots of reasons to be cynical of Anthropic. I myself have very large concerns about them, both about their actual plans and their motivations, along with all the other leading AI companies. But I wish that for at least some of that update on Mythos, he could have put his cynicism to the side and talked about what he thinks a company should do if they have the capability Anthropic claims Mythos has.

“There are leading security researchers saying they've found more security vulnerabilities with Mythos in the last month or two than they've found in their entire careers. That sounds like it could be a pretty big deal. I'd love to hear Ben's thoughts if he takes the capabilities at face value, regardless of which company develops them, instead of just using it as an opportunity for another round of reasons to be cynical about Anthropic, Dario, and their motivations.”

So if these capabilities exist, what should a company do? What's the optimal course of action?

Ben Thompson

There's a great concept on The Greatest of All Talk where you guys really lay into some emailers who are begging for generic praise.

Andrew Sharp

Appreciate my team, appreciate my favorite player. Yes. There's a whole genre of email.

Ben Thompson

Right. This feels a little bit like a generic praise request here. In my update, I listed the reasons to be cynical and said—I made the wolf analogy, which is that the wolf is going to come at some point. I think I gave it credence, and even if it's not real right now, it's going to be real. So I think Anonymous has me painted as the anti-Anthropic guy, which is probably fairly fair to me.

But my Anthropic bit is rooted in deep respect and appreciation for the company. That's the only reason to be worried about them: to the extent that they're legitimate and have their shit together in a major way. I think that's been my point all along.

If you want to frame this very narrowly—and this actually came up, I don't know if I mentioned it on the podcast—when the Quad Code source code leaked, there was a bit in there about hiding mode, like anonymous mode, where you'll report issues but don't say who you are. That seems like it was probably what we're seeing now, or that was for Mythos to go out, don't show that it's Mythos finding this, but start reporting all these bugs.

I brought up that example from the—

Andrew Sharp

Reporting them to what? To companies?

Ben Thompson

No, I brought that example because there was a discussion in the Linux kernel group about—

Andrew Sharp

Just unbelievable amounts of bugs, and they're all real bugs.

Ben Thompson

They're all real bugs, right? How much of that was actually Anthropic acting? I absolutely think it is. It's a really interesting question. If you look at this narrowly, yeah, this is good. Let's get out there and fix as many of these bugs as possible before bad actors get ahold of this and figure out all these exploits.

So I will grant this to Anonymous, and I think that's a fair point. The challenge—the issue, and what I was going for in the last section of the update—is this very much ties into the ongoing Anthropic discussion we've had.

Which is, to the extent you do take them seriously, just validating all of the points, questions, and concerns that came up in the dispute with the Department of whatever you want to call it, Defense or War.

Andrew Sharp

Right.

Ben Thompson

Very annoying that this is a political point.

Andrew Sharp

A loaded topic.

Ben Thompson

Yeah.

Andrew Sharp

A loaded distinction there. Well, yeah, reading about it, any normal person would think, “Why should a private company have all this power?” The question of why the technology shouldn’t be nationalized is, I think, a natural follow-up to—

Ben Thompson

Because nationalizing stuff—

Andrew Sharp

—reading Anthropic’s—

Ben Thompson

—is terrible, right? Like, you—

5. Private Power Needs An Answer

Andrew Sharp

No, I know, but I think a lot of people will read a blog post from Anthropic and be like, “Holy crap, it can do all of this?” Obviously, the CCP’s involvement with DeepSeek seems to have junked up their operation a good bit, so I have full faith that the government would screw up Anthropic if it were nationalized. But at the same time, having the ability to hack into every company and every government on Earth seems like a pretty dangerous power to vest in a group of private individuals.

Ben Thompson

Right. Well, this is the interesting thing to think about. It’s funny to see, after I got fairly attacked for making the argument in the context of that dispute between the US government and Anthropic. My argument there was that the problem is not a question of laws. It’s that the people who have the guns, if they’re fundamentally threatened, are going to ignore the law because the law is downstream from that, right? It’s the extreme—

Andrew Sharp

Yeah.

Ben Thompson

—the extreme version of a realpolitik argument, and not just in the context of international relations, but in the context of who’s actually in charge of day-to-day life. Ultimately, where do laws come from?

Andrew Sharp

Mm-hmm.

Ben Thompson

If you want it to come from the other barrel of a gun, if someone else is developing a better gun than you, you’re entering into a fraught situation in the intervening period before you have full power, for the other entity to say, “Ah, I’m going to take that for myself. You’re not going to be able—

Andrew Sharp

Yeah.

Ben Thompson

—to develop this power.”

But what’s interesting is, you saw a few more people—I think Derek Thompson was one—from the center-left starting to say, “There might be a little bit of a concern here,” and saying—

Andrew Sharp

Right.

Ben Thompson

—“Well, wait.”

Andrew Sharp

Or at least an inevitable tension that needs to be resolved somehow.

Ben Thompson

But the tension they’re coming up with is, “Well, wait, Anthropic could hack the US government? We’re depending on their good graces not to do that?” Well, that’s one angle. Another angle is you could imagine the US government looking at this capability and saying, “Not just worried about us being hacked, but actually, we would like to be able to go hack China.”

Andrew Sharp

Right.

Ben Thompson

Right? We would be able to have this capability for ourselves. And it sounds— It’s funny because, on the one hand, you can sit here and make fun of Anthropic for being scaremongers and Chicken Littles about everything and GPT-2.

You could turn that same criticism on me, right? Where I’m scaremongering about the US government viewing it as an opponent, or someone—

Andrew Sharp

Mm-hmm.

Ben Thompson

—that needs to be brought to heel, as it were. And everyone is looking into theoreticals and seeing what might happen down the road. So, in that regard, I have appreciation and sympathy for their position as well.

This is the tension in this announcement. To the extent you do take them seriously, sure, good job. We’re glad you’re out there patching bugs. That is a good thing to happen.

Andrew Sharp

Mm-hmm.

Ben Thompson

But you are just inviting and accentuating this fundamental tension that has not yet been resolved from a month ago.

Andrew Sharp

All right, and that is the end of the free preview. If you'd like to hear more from Ben and I, there are links to subscribe in the show notes, or you can also go to sharptech.fm. Either option will get you access to a personalized feed that has all the shows we do every week, plus lots more great content from Stratechery and the Stratechery Plus bundle. Check it out, and if you've got feedback, please email us at email@sharptech.fm.

(Preview) Mythos and Project Glasswing, The Year of Anthropic Continues Apace, Q&A on the NYT, Altman, De-globalization | BidClub