Quote · All-In with Chamath, Jason, Sacks & Friedberg
Nikesh Arora: Mythos is Real, Analytical SaaS is Dead, and Google can be a $10T company
Where this was said
Claude Mythos found years of vulnerabilities in Palo Alto's code in weeks
At 2:54 · chapter starts 0:47
This is the episode's most electric segment. Nikesh Arora drops a bombshell: Palo Alto, one of the most security-conscious companies on earth, ran Anthropic's Mythos model against its own codebase for six weeks and found vulnerabilities that would have taken five to seven years to uncover through traditional methods — all for a few million dollars in compute costs. [1] — Nikesh Arora "In 6 weeks, we found vulnerabilities which would have normally taken us 5 to 7 years to find." 02:54 He explains that Mythos' 'ultra mode' can chain vulnerabilities together to map entirely new attack paths, a capability that's great for offense but terrifying at scale. Even more alarming: Nikesh estimates that Mythos-level capabilities will be available in open-source or Chinese models within three months. [2] — Nikesh Arora "3 months to open-source Mythos capability: Nikesh Arora estimates Mythos-level AI vulnerability-finding capabilities will be available in o…" 04:30 He notes that models like Llama 4.8 and 5.5 already have similar capabilities, and you don't need to crack the hardest targets — an old industrial OT system is a much easier mark.
Palo Alto Networks ran Claude's Mythos model against its own codebase for 6 weeks and found vulnerabilities that would have taken 5 to 7 years using conventional methods. The cost was in the low millions — and the capability will be in the wild within 3 months.
Claude's Mythos model found vulnerabilities in Palo Alto's codebase in 6 weeks that would have normally taken 5 to 7 years to discover through conventional methods.
Running Claude's Mythos model on Palo Alto's codebase for 6 weeks cost only a few million dollars in compute, with costs expected to fall further.
Nikesh Arora estimates Mythos-level AI vulnerability-finding capabilities will be available in open-source models within 3 months.
AI is supercharging attackers faster than defenders can respond. Every vendor is now showing up at CIOs' doors asking them to patch newly discovered vulnerabilities — while CIOs are simultaneously trying to find and fix their own — and open source remains an unsolved nightmare.