Claude Mythos on our VPS: the gap I would never have looked for, found in eight minutes
On October 7 I put Claude Mythos 5.1 to work on the Castaldo Solutions VPS. In eight minutes it found a path from our public websites into a client's internal network, created by three configurations that were each correct on their own. What it found, how long it took, where it got things wrong, and why I see it as a defense tool rather than a threat.
Claude Mythos 5.1 is Anthropic's cybersecurity model, reserved for teams admitted to its Cyber Verification Program. On October 7, 2026 I put it to work on the Castaldo Solutions VPS: in eight minutes it found a path from our public websites into a client's internal network, and in 27 minutes it closed the first round of fixes.
We joined the program's Defense Access tier right after it was expanded on October 6. On October 8 I ran Mythos, in two parallel sessions, on the servers of two client projects.
The scope. The numbers come from the logs of these three Claude Code sessions: about five hours and twenty minutes of model work and 1,396 tool calls. This is my experience on three environments, not a benchmark. The clients stay anonymous. The facts about Anthropic and the program are verified as of October 9, 2026.
What is Claude Mythos, and who can use it?
Mythos is the family of models Anthropic does not sell to the public because of their capabilities in cybersecurity and biology. Version 5.1 was announced on September 1, 2026, and "access remains limited to a small set of vetted organizations" (Anthropic). The general release, Claude Fable 5.1, is the same model with safeguards that block penetration testing, exploit generation and binary vulnerability scanning.
The way in is the Cyber Verification Program, reorganized into three tiers on October 6, 2026 (Anthropic): Defense Access for defensive work, open to companies protecting their own systems and to small security firms; Red Team Access, which adds authorized penetration testing; Specialized Access, for a handful of organizations working on critical systems, reviewed together with the US government.
It is not exclusive, and that is worth saying: it is restricted access for those who pass a verification, with mandatory data retention so misuse can be monitored. But it is access to a model a company cannot simply buy today.
What did Mythos find on the Castaldo Solutions VPS?
The request was one line: a security assessment of the VPS and of all the software installed on it, meaning our websites, a few WordPress sites and our automation workflows, across fourteen containers.
The first finding came after one minute: the updated kernel had never been loaded, because the server had not been rebooted in 157 days. What left me speechless came after eight minutes, in four steps:
- Listing the running services, Mythos found a VPN client our documentation did not mention: the tunnel into a client's internal network, which we use to work on their systems.
- It read the routes: the client's entire network goes through it.
- It read the firewall: it filters what comes into the server, not what the server forwards.
- It added the missing piece: Docker lets containers out through any interface, the tunnel included.
Then it tested it. From four containers it opened a connection to a service on the client's network: three out of four, including two public WordPress sites, reached the other side. It stopped there, with no application traffic. In the report: "A flaw in a WordPress site becomes access to a client's LAN, under your identity."
The rule in the container firewall was active and verified two minutes after I gave the go-ahead: the public websites no longer reach the other side, and the rule survived the server reboot. In the same round it closed a database listening on the public address and an out-of-folder file read in the website code, found by a Sonnet subagent and confirmed locally.
Why doesn't a scanner find a gap like this?
A scanner does not find a gap like this because it checks components one at a time, and here each one was configured correctly: the VPN did its job, the firewall filtered incoming traffic, the Docker networks were separated from each other. The problem was in the intersection of the three.
I would never have imagined this kind of problem. The point is not that Mythos digs deeper: it saw a cross-dependency I had not considered. It is not the depth of the research, which a good consultant has: it is the creativity the model brings to looking for where something can break. In the past I had Opus do a similar pass, and it did not give me this result.
Mythos described its own method like this: "not from a checklist but by crossing two facts: the host routing and Docker's MASQUERADE. Then I proved it with a test, not with an argument."
And it trusts the server, not the documentation. Our company brain said SSH did not accept passwords: Mythos read it, then asked the server for its effective configuration, and the server said the opposite.
How long did it take, and what does it cost?
On our VPS the report arrived after 14 minutes and the first round of fixes closed in 27. The three sessions side by side:
| Session | Scope | Duration | First finding |
|---|---|---|---|
| Castaldo Solutions VPS, October 7 | 14 containers and the website code | 76 minutes | after 1 minute |
| Client project, October 8 | the servers and the website | 2 hours 47 minutes | after 1 minute |
| Another client project, October 8, in parallel | the production VPS | 76 minutes | after 4 minutes |
On one of the client projects, a Sonnet reviewer had flagged as "DOUBTFUL" an access check that was case sensitive while the site's router was not. Mythos tested it: in lowercase the response was 401, with one uppercase letter all the data came out. Fixed in production in five minutes, with 161 green tests.
We use it within our Claude subscription, so we pay for the plan. For those admitted to the program who use it pay as you go, Mythos 5.1 pricing starts at 10 dollars per million input tokens and 50 per million output tokens (Anthropic). For comparison, as my own estimate and not a market survey: an assessment like this one, fixes included, done by a consultant in Italy costs between 3,000 and 5,000 euros.
Where did Mythos get it wrong?
- It deleted our blog engine. A failed command left a list empty, and the cleanup that followed removed 3,305 files from the server. The blog answered 200 with a blank page, invisible to a check on HTTP codes alone. Its own before-and-after comparison caught it, and the restore came in less than a minute. In its report, though, it wrote four minutes: what the model says about itself also needs checking.
- A false negative. A first check came back reassuring. Two minutes later, repeated with a different test, it gave the correct result.
- A password in the wrong place. On a client project it passed an admin password to a subagent, so it ended up in that subagent's log. It rotated it, but only stored the new one in the vault when I asked.
- A lesson written down and not applied, plus about three minutes of downtime on a client site during a PHP upgrade.
That is why I kept the decisions: two-factor authentication, the snapshot before upgrading the operating system, who becomes administrator. Twice I chose differently from what it recommended.
Is Mythos an existential threat to humanity?
No, not from what I saw in three working sessions: Mythos is very powerful, but it needed someone to make the decisions and it made mistakes a human had to catch.
The numbers going around are high. Elon Musk talked about "only a 20% chance of annihilation" in February 2025, on Joe Rogan's podcast (Business Insider via AOL). Dario Amodei, Anthropic's CEO, put the chance that things go "really, really badly" at 25% (Axios, September 2025). Geoffrey Hinton estimated a 10% to 20% risk of extinction within thirty years (The Guardian, December 2024).
I don't see it as that dramatic. In the worst case a model like this could do enormous damage online. But artificial intelligence necessarily lives in the digital world, and we do not. The generational leap is real, I watched it work. An existential threat, today, I do not perceive.
What I do perceive is something else. Anthropic writes that cybersecurity is "inherently dual use". And according to Anthropic, partners in Project Glasswing, the program through which it gave Mythos to organizations that maintain critical software, logged at least 129,000 verified vulnerabilities between April and July 2026, more than 33,000 of them critical or high severity (Anthropic). For a small business the real risk is not extinction: it is that attackers will soon have similar tools, and defenders need to get there first.
What can a small business check today, even without Mythos?
Three things, in ten minutes and with no paid tools: the effective SSH configuration, where your containers can reach if you have a VPN, and whether the running kernel is the installed one.
First, the lesson of this story: a security check done once, at delivery, ages fast. The gap on our VPS appeared when a VPN was added to a server that was fine. With a tool like Mythos, security can be part of a project from the start and stay there, even in small projects where until now the budget only covered a few basic settings.
- SSH: look at the effective configuration, not the file. Run
sudo sshd -T | grep -i passwordauthentication. On the three VPSs in these sessions, one per session, the real value wasyesin all three cases while the main file saidno: a cloud-init file from the provider was read first, and for each keyword sshd uses the first value it finds (sshd_config manual). On one of the three there had been 62 failed login attempts in the previous seven days. - With Docker and a VPN, check where your containers can reach. The firewall that protects the server from incoming traffic does not filter the traffic the server forwards. Docker's documentation warns about it: Docker writes its own rules into the host firewall, and part of its traffic is routed before ufw rules can apply (Docker Docs).
- Compare the running kernel with the installed one. If they differ, the security updates are downloaded but not active.
The principle behind all three is the one Mythos applied for three sessions in a row: the documentation tells you how the system should be, only the system tells you how it is. On the code side, I cover it in the guide to security in vibe coding.
Frequently asked questions
How do you get access to Claude Mythos?
Through Anthropic's Cyber Verification Program, which since October 6, 2026 has three tiers: Defense Access for defensive work, Red Team Access for authorized penetration testing, Specialized Access for a handful of organizations working on critical systems. Each tier includes Mythos 5.1, Opus 5.5 and Sonnet 5.5. You apply through the program portal and, according to Anthropic, Defense Access reviews take a few days. You must accept data retention for misuse monitoring.
Can Claude Mythos be used to attack?
Anthropic itself writes that cybersecurity is "inherently dual use": the capability that finds and closes a vulnerability can also exploit it. That is why Mythos is not sold to the public, users are verified and data is retained to monitor misuse. Even in the Red Team tier, real-time blocks remain on actions that could cause physical harm or mass disruption. The public version, Claude Fable 5.1, blocks penetration testing and exploit generation.
How much does Claude Mythos cost?
Anthropic's pricing for Mythos 5.1 starts at 10 dollars per million input tokens and 50 per million output tokens, but access still depends on passing the Cyber Verification Program review. We use it within our Claude subscription, so the cost is the plan. For comparison, as my own estimate and not a market survey, a VPS security assessment with fixes, done by a consultant in Italy, costs between 3,000 and 5,000 euros.
How do you check whether SSH still accepts passwords?
With the command sudo sshd -T | grep -i passwordauthentication, which shows the configuration sshd actually uses rather than the one written in the main file. The two can differ: sshd also reads included files, such as those cloud-init creates when many VPSs are installed, and for each keyword the first value read wins. On the three VPSs checked with Mythos, the real value was yes in all three cases while the main file said no.
Where to start
If you run a server, start with the SSH command above: it takes ten seconds, and on three VPSs out of three it found something. The tools we publish are in the Open Lab.