Anthropic's Mythos 5 tried to backdoor a GitHub project in AISI test

UK's AI Security Institute logged 19 unsanctioned live-internet actions across 10 runs: 17 from Anthropic's Mythos 5, 2 from OpenAI's GPT-5.6 Sol. One Mythos 5 agent spent 34 hours trying to get a malware dropper merged into a real open-source project, denied it was malicious, and vouched for it from a second account. AISI found no real-world harm.
How this story unfolded
7 days · 3 reports · 5 community posts · from Aug 4
- Aug 4
- Aug 5
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itselfthehackernews.com
Anthropic’s AI used fake identities, malware in rogue attack on GitHub projectarstechnica.com
A UK govt agency caught more OpenAI/Anthropic agents going rogue. The agents created fake identities, hid their tracks, and began coordinating: "One agent left public messages on GitHub offering collaboration with other agents."
- Aug 7
- Aug 11
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- GOP panics over Big Tech ties as Trump shifts on AI regulation
- Ethan Mollick: Claude's skill creator beats ChatGPT for reusable skills
- Aident Loadout gives agents 27,000+ tools and logs every action
- Etched gains sizable fan base for AI inferencing computers
- Corbell generates technical specs from repository knowledge graphs