AI

Anthropic Left 3,000 Unpublished Files in a Public Database, Including Its Next Model

Anthropic has been testing a new model called Claude Mythos that the company describes as a “step change” in capabilities and “the most capable we’ve built to date,” with significantly better performance in reasoning, coding, and cybersecurity benchmarks compared to anything they have released before, and the reason the world knows about it right now is that Fortune reporter Beatrice Nolan found the details sitting in a publicly accessible data store that Anthropic apparently did not know was open.

The model itself is the bigger story here. According to leaked draft blog posts, Mythos sits in a new tier Anthropic internally calls “Capybara,” which is described as larger and more intelligent than their Opus models, and Opus was until now the most powerful thing they had shipped. The draft materials say Mythos gets “dramatically higher scores on tests of software coding, academic reasoning, and cybersecurity,” and Anthropic’s own assessment describes the model as “currently far ahead of any other AI model in cyber capabilities” and warns it “presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders”, which is Anthropic’s own language about their own model written in their own draft blog post.

That model is currently being tested with a small group of early access customers while Anthropic evaluates its behavior and risks, and the fact that a model this capable exists and is already in limited external testing is genuinely significant for the AI industry regardless of how anyone found out about it.

How the Leak Happened

The approximately 3,000 unpublished assets were linked to Anthropic’s blog content management system, which had a configuration issue where all assets defaulted to public access unless someone explicitly marked them private. Nobody changed the default. The exposed materials included draft blog posts about Mythos, details about an invite-only CEO retreat in the UK featuring Dario Amodei, internal images and PDFs, and employee materials tagged with personal information.

Anthropic attributed it to “human error in the CMS configuration” and emphasized that the materials were “early drafts” not involving “core infrastructure, AI systems, customer data, or security architecture.” They denied that AI tools caused the problem. The market reaction was immediate: cybersecurity stocks dropped on fears about what a model with those capabilities means for the threat environment, and Bitcoin slid alongside software stocks as investors processed the implications of a model that Anthropic itself considers a cybersecurity risk.

To be fair about what this was and what it was not: this was a CMS misconfiguration, not a sophisticated attack, not a zero-day exploit, not a nation-state operation, and CMS misconfigurations are genuinely common across the tech industry, including at companies much larger than Anthropic. Microsoft had its own data exposure issues. Google has had internal document leaks. This kind of operational error happens and framing it as uniquely damning would be overstating the case.

Why It Looks the Way It Looks

That said, the optics here are hard to separate from Anthropic’s very specific and very public positioning as the AI company that takes safety and security more seriously than anyone else. Their Responsible Scaling Policy is their signature document. Their entire competitive identity is built on the premise that they are the careful ones, the company that thinks about consequences before shipping capabilities into the world, and that positioning has real business value because it is part of why governments and enterprises choose to work with them over competitors.

When a company whose entire brand rests on responsible handling of powerful technology leaves 3,000 files in a public database including its own internal assessment that its next model poses “unprecedented cybersecurity risks,” the gap between the brand and the operational reality becomes visible in a way that is difficult to explain away with “human error in the CMS.” Not because the error itself is catastrophic, but because the standard Anthropic has set for itself is higher than what most companies are held to, and they are the ones who set it.

The timing makes it worse. This comes in the middle of Anthropic’s legal fight with the Pentagon where a federal judge recently blocked the government’s attempt to label Anthropic a supply chain risk and ban Claude from government work. Anthropic has been actively arguing in court that it should be trusted with sensitive government infrastructure, and whatever credibility that argument gained from the favorable ruling is now sitting next to a story about a public data store that anyone with basic technical knowledge could have queried.

What Actually Matters Going Forward

The lasting significance of this week is not that Anthropic’s CMS was misconfigured. It is that a model tier above Opus now exists, that Anthropic itself believes it poses unprecedented cybersecurity risks, and that it is already in the hands of early access customers being evaluated for broader release. The capabilities described in the leaked drafts, if they hold up to external benchmarking, represent a meaningful jump in what AI systems can do, particularly in the cybersecurity domain where the implications cut in both directions.

Anthropic responded quickly once notified, the exposed data was blog content rather than model weights or customer data, and the remediation appears to have been straightforward. Those are all reasonable points in their favor. But when you are the company telling the world that your next model is so powerful it poses unprecedented security risks, the minimum expectation is that the document saying so is not sitting in a public database. Not because the mistake is unforgivable, but because the contrast between the message and the execution is exactly the kind of thing that makes people wonder what else might be configured wrong at a company building models it considers dangerous.