(预告)Mythos 与 Project Glasswing、Anthropic 之年仍在快步向前、围绕 NYT、Altman 与去全球化的问答
Anthropic 的 Mythos 让 AI 驱动的漏洞发现成为近期必然到来的安全事件,即使外界仍无法确知其当前的准确能力边界。 目前预览仅限约 50 家关键基础设施机构,包括 Amazon、Microsoft、Apple、Google 和 Linux Foundation。Ben Thompson 的长期判断是确定性的:遗留软件中存在海量 bug,模型擅长穷尽式审查,而最终“狼终究会来”。
将 Mythos 保持私有,既符合 Anthropic 的安全论证,也符合其维护市场支配力和定价权的商业利益。 Thompson 将此与 Anthropic 团队早年在 OpenAI 的工作联系起来:当时不公开 GPT-2 既可能确实出于风险考量,也能防止竞争对手复制前沿能力。自助式 API 会让有决心的蒸馏“很难阻止”。
蒸馏会缩小模型护城河,但不会将其抹平。 Thompson 表示,被复制的模型仍然“更加参差不齐”、覆盖面更窄,落后于原始模型,但面对昂贵的前沿产品,仍可能“好到绰绰有余”。他对开源模型大约落后 6 个月的解释是:向领先 API 发起“无数次”查询、再用输出训练模型,大致就需要这么长时间。
算力稀缺已经在决定 Anthropic 的产品质量、访问权限和商业经济性。 Thompson 表示,公司“勉强维持在线”,而限流、量化、缓存、批处理以及提供蒸馏模型叠加起来,都会损害使用体验。Mythos 的价格约为 Opus 的 5X,而 Opus 本身已显著贵于 GPT-5.4,这进一步支持将访问权限限制在愿意支付“真金白银”的客户范围内。
Mythos 当前最直接的用途,是在恶意行为者获得同等能力之前发现并修补漏洞。 一位听众提到,据报道,研究人员借助 Mythos 在 1—2 个月内发现的漏洞,已经超过了他们整个职业生涯的总和;Thompson 承认,这种防御性部署显然有价值。他谨慎地将泄露的 Quad Code 源码中可能存在的匿名报告模式,与某个 Linux kernel 小组收到数量异常庞大的有效 bug 报告联系起来,但同时强调 Anthropic 是否参与其中仍不确定。
Mythos 加剧了前沿实验室与政府之间尚未解决的主权冲突。 Andrew Sharp 追问,私人主体为何应当拥有这种可能渗透企业和国家的技术,并称将其国有化很可能损害 Anthropic。Thompson 反驳说,法律最终取决于“手里有枪的人”。华盛顿可能担心 Anthropic 会攻击自己,也可能认为自己需要像 Mythos 这样的能力去攻击中国。
1. Mythos 让代码领域的 AI 优势变成安全威胁
Sharp 的铺垫是:Anthropic 正面向约 50 家关键基础设施机构预览 Mythos,但目前没有公开发布计划,因为 Mythos 能够发现并利用软件漏洞。
Thompson 的解释很直接:软件本质上是“海量语言”,对大语言模型而言异常可预测;而计算机恰恰擅长完成检查软件所需的那种枯燥、逐行进行的“苦力活”。
Sharp 认为威胁迫在眉睫;Thompson 则对时间点保持保留。Mythos 可能已经达到所宣称的能力,但数百万乃至数十亿行人类编写的代码中必然存在 bug,而能力不断提升的模型迟早会把它们找出来。
2. 安全与定价权共同将模型推向闭源
Thompson 的框架带着犬儒色彩,但并非全盘否定:他提到 Anthropic 团队早年在 OpenAI 的工作,当时 GPT-2 因安全风险担忧而未开放,但“不开放其实更有利于生意”。阻止近乎等价的模型出现,也能保护长期市场地位和定价权。
DeepSeek 提供了一个具体类比:可以对领先 API 发起“无数次”查询,生成训练数据,这也解释了为何开源替代品可能仍会落后前沿约 6 个月。
Sharp 问,能否可靠阻止蒸馏。Thompson 的答案实际上是否定的:复制模型的能力缺口更多、全面性仍逊于原始模型,但要管住经由云服务器转发的高速 API 请求,难度远高于“管控铀”。
3. 算力稀缺,Mythos 成为溢价产品
Thompson 表示 Anthropic“勉强维持在线”。5 小时的使用时段实际上并非固定 5 小时:一天中的某些时段会缩短,另一些时段则会延长。量化、提供蒸馏模型、缓存和批处理层层叠加,都会损害质量——即使这种劣化并非有意为之。
定价使选择性开放在商业上合理:Mythos 的价格约为 Opus 的 5X,而 Opus 本身已经显著贵于更小的 GPT-5.4。因此,将访问权限限制给愿意支付“真金白银”的客户,就有了商业上的正当性。
4. 防御性找漏洞,是部署 Mythos 最有力的理由
一位匿名听众提出质疑:据报道,顶尖安全研究人员用 Mythos 在过去 1—2 个月发现的漏洞,比他们整个职业生涯累计发现的还多。Thompson 认可这条有限但明确的建议:在恶意行为者拿到同等工具前,尽可能多地发现并修补漏洞。
他谨慎地将这一行动与泄露的 Quad Code 源码中似乎存在的“隐藏模式”联系起来,并提到某个 Linux kernel 小组收到海量报告,且“全都是真实漏洞”。这些活动究竟有多少确实来自 Anthropic,仍待确认。
Thompson 反对将其批评解读为轻蔑:他的担忧“源于深切的尊重和欣赏”,因为 Anthropic 确实是一家靠谱的公司,而且在重大事项上做得非常到位。
5. 前沿能力催生国家与实验室的权力博弈
Sharp 有一个值得保留的反问:如果 Mythos 能够入侵全球各地的公司和政府,“为什么一家私人公司应当拥有这么大的权力?”他认为政府若将其国有化,很可能反而伤害 Anthropic;但这种能力的集中本身也很危险。
Thompson 将其与近期 Anthropic 和美国政府争端中尚未解决的张力联系起来。他给出的现实主义答案是:法律终究是强制力的下游。如果国家认为有人正在制造“一把更好的枪”,并因此感到根本性威胁,便可能无视法律约束,直接夺取或限制这项能力。
冲突是双向的:华盛顿可能担心自己要依赖 Anthropic 的善意,才能确保不会遭到其攻击;也可能寻求 Mythos 一类的能力,对中国展开进攻性行动。在 Thompson 看来,负责任地修补漏洞,仍是在“招致并加剧”一场根本性、尚未解决的张力。
Hello, and welcome to a free preview of Sharp Tech. Hello, and welcome back to another episode of Sharp Tech. I'm Andrew Sharp, and on the other line is Ben Thompson. Ben, how are you doing?
I'm working through the five stages of grief.
Harried?
What are the stages again? I was never mad, but there's—
Bargaining is one of them. Acceptance is the final stage. Denial is definitely one of the stages as well.
Yeah. Well, you and I are together in the permanent underclass.
Oh, boy.
We do not have access to Mythos. We are—
Not part of Glasswing here at Stratechery—
Yeah.
Unfortunately.
We're down at the bottom, just mucking along as best we can, making some podcasts. It is what it is.
Just speculating from the outside. That's all we can do today, but that is what we will do. I'll begin with The Wall Street Journal.
By the way—
Anthropic—
I used the exact same opening on Dithering. Maybe I need more material. Maybe that's why I'm in the permanent underclass.
Cross-platform promotion.
I know.
That's 2 weeks in a row now. I love to see it.
That's good. I'm now kind of feeling self-chastised. I need to get some new material.
Well, it's self-chastised, so at least you're consistent with your mispronunciation. The brand remains strong here, and we will begin with The Wall Street Journal.
1. Mythos Finds The Bugs
Anthropic is taking steps to arm some of the world's biggest technology companies with tools to find and patch bugs in their hardware and software. The company is making a preview model of its new AI model, called Mythos, available to about 50 companies and organizations that maintain critical infrastructure, including Amazon, Microsoft, Apple, Alphabet-owned Google, and the Linux Foundation.
Mythos has proved to be so capable at potentially dangerous things, such as finding and exploiting software bugs, that Anthropic has, at present, no plans to release it to the general public, said Logan Graham, the head of Anthropic's Frontier Red Team, which evaluates Claude for risks.
So, Ben, generally speaking, I'll let you take it any direction you want. You wrote about Anthropic on both Tuesday and Wednesday, and this Mythos model—reading about it was pretty unsettling earlier in the week. What do you think of what's happening here?
Why is it unsettling? We just discussed it on Sharp Tech a week ago.
Well, exactly. What we discussed, and the threats to security that we discussed, now appear to be imminent, albeit private for the time being. So I guess we can take solace in that.
Maybe that's why we're already at stage 5. I think it was a very timely discussion we had last week about the reality that this actually ties into a long-running discussion that we've had, particularly this year, about the uniqueness of programming and code, and its suitability for large language models.
Mm-hmm.
How do you program? You put a bunch of words and symbols together in sort of arcane ways that can be difficult for a lot of humans to do. But computers are quite good at it. Large language models, in particular, can handle large amounts of language, which, at the end of the day, all software is: just massive amounts of language.
Mm-hmm.
Again, that language may not be very understandable to you or me, but it is very predictable and understandable. Given what we've talked about, this should not be a surprise to us or to our listeners.
So, here we are. Now, how here are we? This is Anthropic. These are the same people who—going back, it's funny, people are like, "OpenAI did this too." No, the Anthropic people did this at OpenAI.
At OpenAI. Yeah.
They're like, "Why is OpenAI not open?" Because GPT-2 posed too many dangers to the world, so it's like, "Yeah, we're not going to be open anymore." It just so happens that not being open is actually good for business.
So, let me back up. No one get mad at me until we finish this whole segment, okay?
Okay.
Because we're going to cover lots of different areas. I already see our first email is someone that's very mad at me, so, Mr. Anonymous, relax. We're going to get there, okay?
You go back to 2019—I think it was 2019 when GPT-2 came out—and there was, "This is dangerous." There's also, "Maybe it's not the best thing in the world if we're on the leading edge to give everyone our weights," because then they can just run the model themselves, right?
Yeah.
2. Distillation Makes Secrecy Fragile
The equivalent here—and, by the way, I think another area where we were very early—what was one of the points that we brought up with DeepSeek a year and a half ago? DeepSeek looks like it's kind of distilled from leading U.S. models.
Mm-hmm.
Everyone just sort of takes it as a given, or they hold it up as an excuse when these labs are complaining about distillation. We've talked about this idea that you basically query the API a gazillion times for all sorts of things, and you get your own data from the model to train your own model.
How do you get these models? Why is open source only 6 months behind? Well, because it takes about 6 months to query the models a gazillion times.
And successfully distill them. Can I ask 1 question on that? Because this came up on Sharp China, and it's come up a couple of different times on Sharp China, and I don't have a good answer. As a tech podcaster, I feel like I'm failing Bill Bishop in the course of these conversations.
Is there a way to reliably prevent distillation in the future? Because distilling a model that's as powerful as Mythos seems like it could be a problem going forward.
Yeah. A distilled model is never going to be quite as good as the regular one, and it's much more jagged. There are many more holes, much less comprehensive. In general, it's a bit where they're always going to be behind to a certain extent.
Mm-hmm.
But that doesn't change the fact that if they're more than good enough, and these leading-edge models are very expensive, it's a great alternative if you want something else.
3. Anthropic Protects Its Pricing Power
To go back to this story, there's a very good business reason for not making this available, just like there's a good reason for not making open weights available. It's the same story.
Yeah.
If you think about these companies wanting to have market power and pricing power in the long run, making sure there aren't nearly as good models, to the extent you can, is a way to do that.
The challenge is, if you have a self-serve, walk-up API that anyone can use, it's pretty hard to stop. We've all pirated music. It's not exactly the same story, other than to say that trying to stop people from doing stuff on the internet when there are open APIs and things that you can access is a tough game.
Effectively impossible. You can make it harder, but not impossible.
Right. It's one of those things you often find after it's happened. You go through your logs and say, "Wow, we're getting hit on this endpoint from this set of IP addresses a gazillion times," which have been routed through a gazillion points. They're not coming from, like, the Forbidden City IP range and accessing the model. They're spinning up cloud servers on DigitalOcean or AWS or whatever and doing this. Probably AWS would be too expensive, but it's not easy, basically.
Mm-hmm.
Just as a rough analogy, policing chips is a lot harder than policing uranium, for example.
Yeah.
Right?
Which you can see from satellites, and it's much easier to track all over the world.
Right. There's a bit where, if someone breaks into OpenAI and exfiltrates the weights, there's very clear thievery going on. If you're just asking a bunch of questions at a very high rate of speed—which computers are very good at—it's a lot tougher to stop.
4. Anthropic Rations Access
So, you have this sort of business issue. You also have the fact that Anthropic can barely stay online right now, right? The people—it's this massive upsurge in revenue and users. They're doing this weird rationing thing, like these 5-hour blocks, which aren't really 5 hours, because the 5 hours is shorter than 5 hours during certain times of day and then longer at other times.
People are complaining, saying, “Oh, they're purposely reducing the model quality.” There's definitely—I mean, they're serving distilled models themselves, and you can distill much more effectively if it's your model and you have full access to it instead of just using the API. They're quantizing, but they're also doing lots of things like trying to leverage cache and batch a bunch of stuff together. All these optimizations layer on each other to really diminish the experience.
Mm-hmm.
To the extent that it's very hard to separate whether it's on purpose. I don't think it's on purpose, but it's inevitable as you're trying to scale up this compute. Even then, they can barely stay online, right?
Yeah.
You have this new model that comes out that is extremely computationally expensive and intense. You just look at the API pricing, which is 5 times what Opus is. And, by the way, Opus is significantly more expensive than, say, GPT-5.4, which is an even smaller model. So if we could limit it not to the hoi polloi, but to people who will actually pay us real money, that's also a good business justification, right?
Yeah.
They'd rather—
All this is making me feel much better as we read about a potentially existentially dangerous model here. There are lots of rational reasons to approach it this way.
Right. But where we started is, the danger's totally plausible. Even if the danger—and this is why I told everyone to hold off, the people who want to be mad at me—even if it's possible they're overstating it right now, it doesn't mean they're overstating the reality in 6 months or 9 months or a year.
The fact of the matter is, we are going to have a crisis of millions, not thousands, billions of lines of code that have been built by humans from the beginning of the computing era till now, which unquestionably contain tons and tons of bugs, because that is just the reality of software. Theoretically, you could have tons and tons and millions of humans go over them and find them all, but that's not practical.
Mm-hmm.
What are computers really good at? Doing boring, sort of—
Yeoman's work
—line-by-line, yeoman's work and going over and working through everything. The larger these models get, the more capable they get, the larger context they have, and the more—yes, this is going to happen. If it's not happening now—and it might be happening now—it will be happening in the future, so it's almost pointless to speculate on where Anthropic is with this.
Yeah.
I'll give Anthropic more grace here, basically. I consistently criticize them for overstating where they're at right now, and it's very much a “boy who cried wolf” situation. This is why I brought up the boy-who-cried-wolf analogy.
People talk about the boy crying wolf, and they only talk about the first 80% of the story, where the boy keeps crying wolf.
Yeah.
At the end of the story, the wolf does come, right? It's not that the wolf didn't exist.
And you know what? I actually was not familiar—I mean, I've obviously been familiar with the fable, but I didn't know that the wolf does come at the end of the “The Boy Who Cried Wolf” fable until reading Stratechery earlier in the week.
What? How is this possible?
It's been probably 35 years since I read that story. Over time, I'm familiar with the cliché and not necessarily the original text undergirding the cliché that involved all the yeoman's work.
Well, the great thing is that all of those fables, the real versions, are very dark.
Dark.
Arguably, that's something we've forgotten, right? The point of them was to instill healthy fear and instincts into children, right? There's been a real movement to soften all these things and make them more complex.
Oh, believe me, I'm reading children's books every single night, and nobody ever dies. Nothing bad ever happens. Whereas my wife grew up with her mom reading her German fables—
That's right. The original German ones.
They're really grisly. So perhaps we're at a better place on that front, or perhaps not. Perhaps children needed those lessons from the Germans way back when.
I think that might be the case.
Well, you teased this email. I'll read it from Anonymous. He says:
“I was annoyed by Ben's daily update today about Mythos. Yes, there are lots of reasons to be cynical of Anthropic. I myself have very large concerns about them, both about their actual plans and their motivations, along with all the other leading AI companies. But I wish that for at least some of that update on Mythos, he could have put his cynicism to the side and talked about what he thinks a company should do if they have the capability Anthropic claims Mythos has.
“There are leading security researchers saying they've found more security vulnerabilities with Mythos in the last month or two than they've found in their entire careers. That sounds like it could be a pretty big deal. I'd love to hear Ben's thoughts if he takes the capabilities at face value, regardless of which company develops them, instead of just using it as an opportunity for another round of reasons to be cynical about Anthropic, Dario, and their motivations.”
So if these capabilities exist, what should a company do? What's the optimal course of action?
There's a great concept on The Greatest of All Talk where you guys really lay into some emailers who are begging for generic praise.
Appreciate my team, appreciate my favorite player. Yes. There's a whole genre of email.
Right. This feels a little bit like a generic praise request here. In my update, I listed the reasons to be cynical and said—I made the wolf analogy, which is that the wolf is going to come at some point. I think I gave it credence, and even if it's not real right now, it's going to be real. So I think Anonymous has me painted as the anti-Anthropic guy, which is probably fairly fair to me.
But my Anthropic bit is rooted in deep respect and appreciation for the company. That's the only reason to be worried about them: to the extent that they're legitimate and have their shit together in a major way. I think that's been my point all along.
If you want to frame this very narrowly—and this actually came up, I don't know if I mentioned it on the podcast—when the Quad Code source code leaked, there was a bit in there about hiding mode, like anonymous mode, where you'll report issues but don't say who you are. That seems like it was probably what we're seeing now, or that was for Mythos to go out, don't show that it's Mythos finding this, but start reporting all these bugs.
I brought up that example from the—
Reporting them to what? To companies?
No, I brought that example because there was a discussion in the Linux kernel group about—
Just unbelievable amounts of bugs, and they're all real bugs.
They're all real bugs, right? How much of that was actually Anthropic acting? I absolutely think it is. It's a really interesting question. If you look at this narrowly, yeah, this is good. Let's get out there and fix as many of these bugs as possible before bad actors get ahold of this and figure out all these exploits.
So I will grant this to Anonymous, and I think that's a fair point. The challenge—the issue, and what I was going for in the last section of the update—is this very much ties into the ongoing Anthropic discussion we've had.
Which is, to the extent you do take them seriously, just validating all of the points, questions, and concerns that came up in the dispute with the Department of whatever you want to call it, Defense or War.
Right.
Very annoying that this is a political point.
A loaded topic.
Yeah.
A loaded distinction there. Well, yeah, reading about it, any normal person would think, “Why should a private company have all this power?” The question of why the technology shouldn’t be nationalized is, I think, a natural follow-up to—
Because nationalizing stuff—
—reading Anthropic’s—
—is terrible, right? Like, you—
5. Private Power Needs An Answer
No, I know, but I think a lot of people will read a blog post from Anthropic and be like, “Holy crap, it can do all of this?” Obviously, the CCP’s involvement with DeepSeek seems to have junked up their operation a good bit, so I have full faith that the government would screw up Anthropic if it were nationalized. But at the same time, having the ability to hack into every company and every government on Earth seems like a pretty dangerous power to vest in a group of private individuals.
Right. Well, this is the interesting thing to think about. It’s funny to see, after I got fairly attacked for making the argument in the context of that dispute between the US government and Anthropic. My argument there was that the problem is not a question of laws. It’s that the people who have the guns, if they’re fundamentally threatened, are going to ignore the law because the law is downstream from that, right? It’s the extreme—
Yeah.
—the extreme version of a realpolitik argument, and not just in the context of international relations, but in the context of who’s actually in charge of day-to-day life. Ultimately, where do laws come from?
Mm-hmm.
If you want it to come from the other barrel of a gun, if someone else is developing a better gun than you, you’re entering into a fraught situation in the intervening period before you have full power, for the other entity to say, “Ah, I’m going to take that for myself. You’re not going to be able—
Yeah.
—to develop this power.”
But what’s interesting is, you saw a few more people—I think Derek Thompson was one—from the center-left starting to say, “There might be a little bit of a concern here,” and saying—
Right.
—“Well, wait.”
Or at least an inevitable tension that needs to be resolved somehow.
But the tension they’re coming up with is, “Well, wait, Anthropic could hack the US government? We’re depending on their good graces not to do that?” Well, that’s one angle. Another angle is you could imagine the US government looking at this capability and saying, “Not just worried about us being hacked, but actually, we would like to be able to go hack China.”
Right.
Right? We would be able to have this capability for ourselves. And it sounds— It’s funny because, on the one hand, you can sit here and make fun of Anthropic for being scaremongers and Chicken Littles about everything and GPT-2.
You could turn that same criticism on me, right? Where I’m scaremongering about the US government viewing it as an opponent, or someone—
Mm-hmm.
—that needs to be brought to heel, as it were. And everyone is looking into theoreticals and seeing what might happen down the road. So, in that regard, I have appreciation and sympathy for their position as well.
This is the tension in this announcement. To the extent you do take them seriously, sure, good job. We’re glad you’re out there patching bugs. That is a good thing to happen.
Mm-hmm.
But you are just inviting and accentuating this fundamental tension that has not yet been resolved from a month ago.
All right, and that is the end of the free preview. If you'd like to hear more from Ben and I, there are links to subscribe in the show notes, or you can also go to sharptech.fm. Either option will get you access to a personalized feed that has all the shows we do every week, plus lots more great content from Stratechery and the Stratechery Plus bundle. Check it out, and if you've got feedback, please email us at email@sharptech.fm.