Introduction
On 7 April, Anthropic announced the successor to Claude Opus: Mythos Preview (‘Mythos’).1 While it is a general-purpose language model, it has demonstrated particular ability in the field of computer security. This includes finding and exploiting zero-day (undiscovered) vulnerabilities, exploiting N-day (known) vulnerabilities, and reverse engineering exploits on closed source software (i.e. with only machine code to work with).
Of concern is not that Mythos is discovering vulnerabilities that could not be discovered by skilled researchers, rather, it allows the search for and application of vulnerabilities to be done at scale, and to potentially put such skills in the hands of less skilled, but malicious actors.
As part of Anthropic’s evaluation of Mythos, thousands of high/critical vulnerabilities were identified and are being disclosed to maintainers and vendors.2 In the interests of security, very few have been publicly discussed in detail, but they will be disclosed in due course.
Project Glasswing (‘Glasswing’) is an Anthropic initiative bringing together users and authors of some of the most critical software (Apple, Google, Linux Foundation, Cisco, etc) to employ Mythos Preview for defensive security.
In due course, the intention is to deploy Mythos-class models, but with built-in safeguards that detect and block nefarious use.
For those not directly involved in the project, it is easy to imagine Mythos as an all-conquering monster about to be released into the community, and it has caught the imagination of the press and regulators.3,4,5 But can we say anything about the likely impact on cyber cat bonds?
How might Mythos impact cyber security?
To frame the question, we first distinguish between 'cause of loss' (the event that caused subsequent disruption, e.g. exploiting a code vulnerability) and 'outcome' (what the disruption looks like, e.g. data destruction, ransom, or exfiltration). In the context of Mythos, we are more focused on the former. The implications may be positive (Mythos has defensive value) or negative (Mythos has offensive risk). Where both are possible, there is a race as to which side gets there first.
Figure 1 lists a selection of causes of loss and then ranks the defensive value and offensive risk of Mythos. While the colour-coding is subjective, it does focus the discussion:
- The impact of Mythos on social engineering attacks and non-malicious events is negligible
- The creation and distribution of backdoors into supply chain software (like SolarWinds6 ) does not seem a likely new cause of loss. Firstly, Mythos has not demonstrated the ability to write deliberately flawed software, whose errors are hard to detect. Secondly, code changes always go through a review process. Currently this may be a human review, but it is easy to contemplate a future review process including LLM review as well
- For software vulnerabilities, abuse comprises two stages - discovery of the vulnerability and writing an exploit. As far as discovery is concerned, existing models remain competent at finding vulnerabilities. The danger seems mostly in the crafting of exploits. Mythos is reported as a step change in terms of 'autonomous exploit development'. Potentially, it puts these skills in the hands of the relatively unskilled
Figure 1: Defensive value and offensive risk of Mythos
_Table_D04.jpg)
Source: Man AHL compilation
Of the many primary causes of loss, it is clear that Mythos is relevant for the malicious code rows (where writing software exploits is involved and, to a lesser extent, discovering them). However, it is important to put this in context:
- Whether found by man or machine, the list of vulnerabilities is long already. In the first half of 2025, 1773 vulnerability discoveries were rated Critical according to the NIST National Vulnerability Database (NVD).14 This is not to diminish the significance of finding new vulnerabilities but, to be clear, society lives with plenty of critical vulnerabilities already.
Fixing bugs is costly, and it may be simply impractical to fix them all. What is important (and likely to become more so) is for developers to prioritise fixes, and users to patch regularly.15 - Writing exploits is undoubtedly a skilled process, and Mythos Preview would allow this to be done at scale. However, reports suggest that even the current time-to-exploit is only circa five days.16 Mythos, in the wrong hands, would make matters worse, but the statistics already look acute.
- It is unclear what standard is used by Anthropic for scoring vulnerabilities, however the classification looks similar to CVSS (Common Vulnerability Scoring System).17 It is worth noting that CVSS is not without its detractors, in that the base score captures the technical properties of a vulnerability without regard to how practical it is to deploy. What we might be missing is the extent to which the multitude of Mythos-discovered vulnerabilities are actionable.18
A similar point is also raised by the UK’s AI Security Institute, in their evaluation of Mythos. They note substantial success in ‘Capture The Flag’ tasks and others, but also that the tests ‘were given network access’. In addition, there was no assumption of defensive tooling, or any assessment of whether such attacks would have set off alarms.19
The decision to form Glasswing gives the coding community a lead against attackers in two ways:
- Temporal: The stated intent is to release Mythos class models with suitable guardrails in due course. It is reasonable to assume that, sooner or later, the guardrails will be broken, or a competitor with a less responsible attitude will release equivalent, unguarded capabilities. In any case, in our view, frontier models probably have no more than a three-to-six-month lead. Glasswing gives the community a head start to fix the most serious vulnerabilities.
- Economic: Anthropic is committing US$ 100m in usage credits to Glasswing. Assuming that identified vulnerabilities get patched, one might imagine that it becomes increasingly expensive (in terms of token costs) to find the next vulnerability. As such, it places an increasing economic hurdle (at least statistically) for attackers to overcome.
It is naïve to assume that Mythos and competitors do not increase the cyber threat landscape. At the very least, attritional losses are likely to increase (exploits arising from Mythos being jailbroken or competitor products). What might be the impact on cyber cat bonds?
Of the six outstanding 144A cyber deals, five (82% by notional) are per occurrence deals. The decision of what constitutes a single occurrence is sometimes delegated to the sponsor rather than effected through a precise legal definition. The latter would be difficult to codify. To illustrate the point, did the two aircraft flown into the Twin Towers of the World Trade Center on 11 September 2001 constitute one or two events? This question ended up being litigated, with the outcomes varying by exact policy wordings.20 The cyber linkage of events is potentially more difficult to define, given potentially multiple steps in an attack. In any case, per occurrence deals and high attachment points mean that we need to see a single event causing insured loss which is an order of magnitude greater than what we have seen to date. As an aside, we note that cat bond risk modellers may not necessarily aggregate losses in the same way that the insured does.
It is conceivable that AI will shift the 'single event' debate. Suppose a single vulnerability is used (by the same attacking group) to separately attack three separate institutions. One might assume that these are three separate events. But now suppose that an AI agent is directed to attack three institutions simultaneously - it seems arguable that this might be considered a single event.
Separate to this discussion is the notion that, in future, AI may become an integral part of corporate processes. Given the relatively small number of vendors, it is possible (indeed, likely) that a systemic supply chain dependence will start to emerge in the same way that exposure to cloud service outages is today. In future, we may see sub-limit endorsements applied to AI services in the same way that they sometimes are applied to cloud outages.
To date, the cat bond market response to the Mythos Preview has been benign. Prices are stable and there has been no selling pressure. It is quite possible that investors are becoming more entrenched in their views. Some will consider that Mythos affects only a few causes of loss; needs to get into the wild before Glasswing and other remediation gets there first; and either the vulnerabilities are orders of magnitude more severe than what we have seen to date, or an army of attacks is regarded as a single event. Others will see Mythos as justification for why they are keeping away from cyber as a peril.
One reason that cyber risk has been attractively priced is that there has been a lack of very severe event history in a rapidly evolving landscape and, as such, cyber risk models have appeared (of necessity) nascent. The emergence of Mythos potentially represents a step change in threat discovery, exploit, and remediation speeds. Effectively, the ‘maturity-clock’ of the risk models is being reset. The end result is likely to be a stronger global infrastructure, but there will likely be a risk of undesirable attacks along the way. We believe that the seniority and terms of existing cat bonds means that they can withstand the coming turbulence.
1. https://red.anthropic.com/2026/mythos-preview/
2. Ibid.
3. https://uk.investing.com/news/economy-news/switzerland-regulator-warns-…
4. https://www.computing.co.uk/news/2026/legislation-regulation/uk-regulat…
5. https://www.reuters.com/legal/government/regulators-monitor-anthropics-…
6. https://en.wikipedia.org/wiki/2020_United_States_federal_government_dat…
7. https://en.wikipedia.org/wiki/Yahoo_data_breaches
8. https://en.wikipedia.org/wiki/2017_Equifax_data_breach
9. https://en.wikipedia.org/wiki/2023_MOVEit_data_breach
10. https://www.reuters.com/article/business/capital-one-to-pay-80-million-…
11. https://specopssoft.com/blog/mgm-resorts-service-desk-hack/
12. https://www.theguardian.com/technology/article/2024/may/17/uk-engineeri…
13. https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages
14. https://securityboulevard.com/2026/03/46-vulnerability-statistics-2026-…
15. https://cybernews.com/ai-news/security-experts-bugs-managing-not-fixing…
16. https://mondoo.com/vulnerability-intelligence/state-of-vulnerabilities-…
17. https://www.first.org/cvss/
18. https://www.theregister.com/2025/10/16/cve_cvss_scores_not_useful/
19. https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-c…
20. https://www.robinskaplan.com/assets/htmldocuments/uploads/pdfs/d42e6cdb…
You are now leaving Man Group’s website
You are leaving Man Group’s website and entering a third-party website that is not controlled, maintained, or monitored by Man Group. Man Group is not responsible for the content or availability of the third-party website. By leaving Man Group’s website, you will be subject to the third-party website’s terms, policies and/or notices, including those related to privacy and security, as applicable.