A default publishing setting, not an attack
About 3,000 unpublished files sat reachable through Anthropic's content management system, including a draft blog post describing an unreleased model, Claude Mythos, internally referenced under the tier name Capybara. Fortune reported that assets created in the CMS default to public visibility unless a user explicitly restricts them, and Anthropic attributed the exposure to human error in that configuration rather than to an intrusion. [1][2]
Atlas interpretation: The distinction matters for how the incident should be read. Nothing here describes a breach of Anthropic's systems; a default setting made draft marketing copy discoverable, and the copy happened to be about a model the company had not planned to discuss yet. [1]
What the draft said about Mythos
The leaked draft called Mythos "by far the most powerful AI model we've ever developed," reporting markedly higher scores than Claude Opus 4.6 on software coding, academic reasoning, and cybersecurity evaluations, and it warned that the model was "currently far ahead of any other AI model in cyber capabilities." It went on to say Mythos "presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders." [1][2]
Anthropic confirmed the model's existence once the draft surfaced, saying it was "working with a small group of early access customers to test the model," and that its capabilities meant the company intended to be "deliberate about how we release it." It described the model as a "step change" in capability, the same phrase the draft had used. [1]
Atlas interpretation: Every specific capability figure attached to this event, the coding and reasoning scores, the comparison against Opus 4.6, the cyber-capability warning, comes from Anthropic's own unpublished copy, surfaced by an accident rather than a release. Anthropic's confirmation validated that the model exists and matched the draft's characterization of it, but no independent evaluation of Mythos had been published at the time of this leak; that came later, in the Glasswing program's own testing. [1]
A leak about a model nobody could use moved cybersecurity stocks
Cybersecurity stocks fell the next trading day, March 27: CrowdStrike dropped about 7 percent, Palo Alto Networks about 6 percent, Zscaler about 4.5 percent, and Okta, SentinelOne and Fortinet each fell roughly 3 percent. Stifel analyst Adam Borg described Mythos as a tool that could turn an ordinary attacker into the equivalent of a nation-state adversary, and Raymond James' Adam Tindle said the leak underscored how AI-driven vulnerability discovery could outpace traditional defensive strategies. [3]
Atlas interpretation: The trade reflected a draft marketing paragraph, not a benchmark, a release, or a demonstrated exploit chain: no one outside Anthropic had used Mythos when these stocks moved. That the market treated an accidental disclosure of a vendor's own unreleased capability claim as decision-relevant news says as much about how jumpy security-adjacent equities had become around frontier model announcements as it does about Mythos itself; Evercore ISI's Kirk Materne made a version of that point directly, predicting a "long and bumpy bottoming process" until the sector stopped overreacting to model releases generally. [3]
What Anthropic actually did with the model
Anthropic did not rush Mythos to release after the leak. It published its own cybersecurity assessment of a preview version on April 7, reporting more than 10,000 high and critical zero-days found in the preview's first month, including a seventeen-year-old FreeBSD remote root hole it exploited unaided, and restricted access to Project Glasswing, an invitation-only program for critical infrastructure operators, rather than a general release. [1]
Atlas interpretation: That decision, made public eleven days after the accidental leak, is the best available check on the leaked draft's own framing: Anthropic treated the cyber-capability warning in its unpublished marketing copy as a real constraint on distribution rather than a line it walked back once caught saying it. [1]
Sources
- Exclusive: Anthropic acknowledges testing new AI model representing 'step change' in capabilities, after accidental data leak reveals its existence
Fortune · Mar 26, 2026
- Meet Claude Mythos: Leaked Anthropic post reveals the powerful AI model
Mashable · Mar 27, 2026
- Cybersecurity stocks plunge as Anthropic's 'Claude Mythos' leak sparks AI fear
Yahoo Finance · Mar 27, 2026