JPMorgan Chase CEO Jamie Dimon has warned that broad access to Anthropic’s Claude Mythos cybersecurity model would be like “giving ballistic missiles to individuals,” sharpening the debate over whether exceptionally capable AI security tools can remain restricted to vetted defenders.
Speaking at the Pennsylvania Defense and Innovation Summit, Dimon called Mythos-related risk a “real issue,” according to TechRadar and Spanish financial daily Cinco Días. The concern is not that the model is a magical hacking button; it is that a system able to locate flaws, reason through exploit chains, and produce working attack paths could reduce the time, skill, and cost required to compromise vulnerable software.
Anthropic introduced Claude Mythos Preview and its Project Glasswing program on April 7. The company said the unreleased model had found thousands of high-severity vulnerabilities, including flaws affecting major operating systems and browsers, and that it could outperform all but the most skilled humans at finding and exploiting software vulnerabilities.
Project Glasswing initially gave access to 12 founding partners, including Microsoft, JPMorganChase, Google, Apple, Cisco, CrowdStrike, NVIDIA, Palo Alto Networks and the Linux Foundation, plus more than 40 organizations that maintain critical infrastructure or software. Anthropic committed up to $100 million in model-use credits for defensive work.
The program has since expanded. Anthropic said in June that approximately 150 additional organizations would be admitted after meeting its security requirements, with a focus on critical-infrastructure operators and maintainers of widely used codebases. The company says the growing bottleneck is no longer discovering vulnerabilities, but validating, disclosing and patching the volume of findings.
JPMorgan is using Mythos through Glasswing for defensive testing, while its CISO, Pat Opet, has described the project as an opportunity to evaluate next-generation security tooling alongside other major organizations. Anthropic’s current cybersecurity material says the limited-access program now includes Claude Mythos 5, while Claude Fable 5 is presented as a safeguarded version for wider use.
Crypto Briefing’s suggestion that the access debate could itself drive token-market consequences is more speculative. There is no evidence that a particular token, exchange breach, or Windows vulnerability is linked to Mythos.
That makes basic hygiene less optional, not less relevant: keep Windows and third-party applications current, remove unnecessary internet exposure, enforce phishing-resistant MFA for privileged accounts, segment admin access, and treat vulnerability remediation as an operational queue with owners and deadlines.
Microsoft is a Project Glasswing founding partner, but neither Microsoft nor Anthropic has announced a Mythos-specific Windows update for ordinary customers.
Speaking at the Pennsylvania Defense and Innovation Summit, Dimon called Mythos-related risk a “real issue,” according to TechRadar and Spanish financial daily Cinco Días. The concern is not that the model is a magical hacking button; it is that a system able to locate flaws, reason through exploit chains, and produce working attack paths could reduce the time, skill, and cost required to compromise vulnerable software.
A defensive tool with offensive potential
Anthropic introduced Claude Mythos Preview and its Project Glasswing program on April 7. The company said the unreleased model had found thousands of high-severity vulnerabilities, including flaws affecting major operating systems and browsers, and that it could outperform all but the most skilled humans at finding and exploiting software vulnerabilities.Project Glasswing initially gave access to 12 founding partners, including Microsoft, JPMorganChase, Google, Apple, Cisco, CrowdStrike, NVIDIA, Palo Alto Networks and the Linux Foundation, plus more than 40 organizations that maintain critical infrastructure or software. Anthropic committed up to $100 million in model-use credits for defensive work.
The program has since expanded. Anthropic said in June that approximately 150 additional organizations would be admitted after meeting its security requirements, with a focus on critical-infrastructure operators and maintainers of widely used codebases. The company says the growing bottleneck is no longer discovering vulnerabilities, but validating, disclosing and patching the volume of findings.
Why financial firms care
Banks, payment providers and crypto exchanges have obvious exposure: sprawling web-facing systems, high-value credentials, third-party dependencies and a direct path from compromise to fraud or theft. Dimon’s remarks reflect a broader concern that automated vulnerability research may compress the window between a bug’s discovery and real-world exploitation.JPMorgan is using Mythos through Glasswing for defensive testing, while its CISO, Pat Opet, has described the project as an opportunity to evaluate next-generation security tooling alongside other major organizations. Anthropic’s current cybersecurity material says the limited-access program now includes Claude Mythos 5, while Claude Fable 5 is presented as a safeguarded version for wider use.
Crypto Briefing’s suggestion that the access debate could itself drive token-market consequences is more speculative. There is no evidence that a particular token, exchange breach, or Windows vulnerability is linked to Mythos.
The Windows angle
For Windows admins, the story is less about gaining access to Anthropic’s restricted model and more about the changed operating assumption: attackers may soon be able to triage public code, exposed services and known flaws faster than many organizations can patch them.That makes basic hygiene less optional, not less relevant: keep Windows and third-party applications current, remove unnecessary internet exposure, enforce phishing-resistant MFA for privileged accounts, segment admin access, and treat vulnerability remediation as an operational queue with owners and deadlines.
Microsoft is a Project Glasswing founding partner, but neither Microsoft nor Anthropic has announced a Mythos-specific Windows update for ordinary customers.
References
- Primary source: Crypto Briefing
Published: 2026-07-19T23:25:32+00:00
Jamie Dimon warns Anthropic's Mythos access debate signals AI risks for finance and crypto
Jamie Dimon warns Anthropic's Mythos AI model poses cybersecurity risks for finance and crypto, comparing broad access to giving ballistic missiles tocryptobriefing.com - Related coverage: techradar.com
'You're giving ballistic ⁠missiles to individuals with Mythos': JPMorgan CEO Jamie Dimon says Anthropic's AI model poses some serious risks | TechRadar
Anthropic’s Claude Mythos AI is just too powerfulwww.techradar.com - Official source: anthropic.com
Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropic
Claude Mythos Preview is a new general-purpose language model that is strikingly capable at computer security tasks. This post provides technical details for researchers and practitioners who want to understand exactly how we have been testing this model, and what we have found over the past month.www.anthropic.com - Related coverage: techcrunch.com
Anthropic debuts preview of powerful new AI model Mythos in new cybersecurity initiative | TechCrunch
The new model will be used by a small number of high-profile companies to engage in defensive cybersecurity work.techcrunch.com - Related coverage: ibm.com
Anthropic's most powerful AI raises the stakes for cybersecurity | IBM
An AI model that can find decades-old security flaws is now in the hands of major tech companies. Here’s what it means for cybersecurity, open source, and the race between defenders and attackers.www.ibm.com
- Related coverage: theweek.com
Mythos: Anthropic’s new AI model experts fear is unsafe | The Week
Anthropic is not releasing the model to the public over safety concerns and potential hacking possibilitiestheweek.com