In short
The episode asks whether money is still safe in bank accounts as AI gets more powerful. It centers on Anthropic’s unreleased model Claude Mythos and the U.S. response: in April, Treasury Secretary Scott Bessant and Fed Chair Jerome Powell met bank CEOs to ensure digital vault security after Anthropic’s announcement.
Guest
Michael Moore, who leads Anthropic’s cybersecurity products; he says Mythos can identify thousands of software vulnerabilities and chain multiple minor flaws into dangerous exploits, like breaking gate, door, and lock. Anthropic limited early access via Project Glasswing (JPMorgan Chase; Reuters later reported Bank of America). Anthropic also launched Claude Security to help patch bugs. Professor Rachel Greenstadt (NYU) warns AI-assisted “vibe coding” could create new classes of bugs.
Notable examples
a 27-year-old internet infrastructure bug found by AI; Y2K as a patching analogy; U.S. intelligence warnings about state and ransomware threats.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOUnderstanding Claude Mythos and Its Capabilities
1:02 to 2:15
Explore the features and concerns surrounding the AI model Claude Mythos.
“This is The Indicator from Planet Money.”
Concerns Over AI's Potential Threats
2:15 to 3:08
Discussion on how Claude Mythos could exploit vulnerabilities and the risks involved.
“But when Anthropic was testing Claude Mythos, people in the company, like Michael Moore, started getting concerned.”
Industry Responses and Project Glasswing
3:08 to 4:30
Explanation of Anthropic's Project Glasswing and how banks are managing risks.
“This was to allow them to fix their software before Mythos had a wider release.”
Critiques of AI Models and Security Solutions
4:30 to 5:52
Examination of the criticism surrounding AI and its role in software security.
“That sounds like a very challenging proposition because there are so many, I don't know, companies and banks and all kinds of people who use software all around the world.”
The Future of Cybersecurity in an AI Era
5:52 to 8:01
Analysis of the ongoing cat-and-mouse game between hackers and security experts.
“You know, it's almost like a company that creates this new skeleton key that can break in anywhere is now selling new locks.”
Conclusion and Reflections on AI's Impact
8:01 to 9:18
Final thoughts on the implications of AI in cybersecurity and the future outlook.
“There are AI models available out there that are already roughly as capable as Claude Mythos.”
Transcript
Automatic transcript. May contain errors.0:00NPR.
0:11In April, Treasury Secretary Scott Besant and Federal Reserve Chair Jerome Powell called a special meeting with bank CEOs. They wanted to make sure banks were keeping their digital vaults secure in an age of rapidly advancing AI. They were responding to the AI company Anthropic's announcement. The AI company said it had a new model that was so state-of-the-art, so clever, so dangerous, that it couldn't yet release it to the wider public. Anthropic called the model Claude Mythos. Michael Moore heads up the company's cybersecurity products. He says the new model could identify thousands of software vulnerabilities.
0:51What that means is someone who was writing the software at some point didn't quite do something right. And that left a door kind of ajar. And an attacker can get in through that door. This is The Indicator from Planet Money. I'm Darian Woods. And I'm Waylon Wong. Today on the show, is our money still safe in our bank accounts? We learn about the double-edged sword of increasingly capable AI. And we ask whether Claude Mythos' unique capabilities are just a myth. Or a meef.
1:50find out what actually works when nothing goes as planned. Listen to Work Life with Molly Graham. The new AI model, Claude Mythos, is in some ways a typical language model. It wasn't fundamentally different from a chatbot chained to answer general questions or write lines of code like Anthropik's other Claude models or ChatGPT. It hasn't been trained specifically for cybersecurity. So it could write poetry, limericks, or give you a new recipe for the best chocolate chip cookies. But when Anthropic was testing Claude Mythos, people in the company, like Michael Moore, started getting concerned. It showed a really advanced capability of chaining together individual vulnerabilities into an exploit that was potentially really dangerous.
2:35When Michael says chaining together individual vulnerabilities, he means that Mythos could find multiple lines of code that, on their own, weren't hugely problematic, but together could leave the software exposed. It's like if a thief could break into your apartment block's front gate and your building's front door and your apartment unit's lock. It was the first time that if we just were to release the model out into the public, we were concerned that the scale of AI would allow offensive actors to actually go break into systems at an unprecedented rate. So Anthropic gave special access to Mythos to only a small group of companies.
3:12This was to allow them to fix their software before Mythos had a wider release. Anthropik called it Project Glasswing. We wanted to make sure that we gave a good head start to avoid a large swath of incidents that could impact all of us. At first, there was only one named financial institution given early access, JPMorgan Chase. Reuters then reported that Bank of America was two. That's two out of America's 4 ,000 banks. Should people be worried about their life savings potentially disappearing from their bank accounts? I'm really excited to see the conversations that are happening and the work that's being done to patch as many vulnerabilities as possible so that it doesn't come to a moment of strong concern for most people.
3:58Hopefully, it's a little bit kind of like what Y2K turned out to be, which was really not much. But that was because a lot of work went into making sure it didn't happen. And I'm really excited to see the industry making those kind of moves right now. Were you worried in 1999 about the Y2K bug, Whalen? I was more concerned with partying like it was 1999. Yeah, those were the priorities. And of course, with the computer programmers and technicians working all over the globe, we didn't actually have to worry about much in the end. Yes, but can they really do the same thing with their AI models like Mythos?
4:30That sounds like a very challenging proposition because there are so many, I don't know, companies and banks and all kinds of people who use software all around the world. So how logistically can a company like Anthropic warn the world ahead of the model getting into the wrong hands? Yeah, so there's really two things that we can do. We wanted to talk publicly about the power of the model and the safety concerns of the model. But the second thing we wanted to do was make sure that there was a good, quick path for as many people to patch vulnerabilities as possible. Mythos can chain together a lot of vulnerabilities.
5:09You think of it literally like a chain. If you break just one link in that chain, the exploit doesn't work anymore, right? This drive to help patch up the world's software is partly why Anthropic released its next product. Later in April, Claude released a special tool just for finding and fixing software vulnerabilities. It's called Claude Security. At this moment, it's not based on that cutting-edge Claude mythos model. But Michael points out that even using slightly less state-of-the-art AI models can still find a lot of bugs, which can then be fixed. This makes sense, but a skeptic might say this is convenient timing.
5:47What do you say to critics who might argue that Anthropic is creating the problem it's charging people money to solve? You know, it's almost like a company that creates this new skeleton key that can break in anywhere is now selling new locks.
6:05It's a good question. I think there's a couple of things there. Cloud security is really about looking at code bases that have been around for decades. One of the things that we found and we discussed in our Mythos blog was actually a bug that has been around for 27 years in a key piece of internet infrastructure. Those kind of bugs are the things that we expect AI to find in the future, and that's why patching them using AI is so important now. As we move and continue to evolve as an industry and more code is written by AI, we definitely expect the security of the industry to get better. It's something that we work on very strongly to continue to make sure our models are writing secure code.
6:44I'm sure our other peer labs do as well. And by using best practices like cloud security, for instance, we can assure that we're finding all of the bugs that we can before things get into production and before things impact end users. But other cybersecurity experts aren't as confident. Rachel Greenstadt is a computer science professor at New York University. She points out that less experienced developers are vibe coding software, as in just typing instructions to get the chatbot to build the programs for them. People are able to write much more complex things much quicker that they don't understand, that the AI doesn't understand.
7:18And this is an opportunity for whole new classes of bugs. Now, there has always been a cat and mouse game between more sophisticated hacking and tools that help with cybersecurity. This year, the U.S. intelligence community noted that actors from China, Russia, Iran, North Korea, and ransomware groups continue to pose critical threats to U.S. networks and infrastructure. So maybe this is just another chapter in that game. Or maybe Claude Mythos is different. I mean, it's excellent marketing, right? You know, this idea that there's this new model and it's so dangerous that only some people can have it and so on.
7:55That said, the vulnerabilities it's finding are real. But we've seen this sort of thing before. There are AI models available out there that are already roughly as capable as Claude Mythos. In fact, an open model found that bug that Michael had talked about, that 27-year-old bug lurking in an old operating system. OpenAI has since released a model publicly that actually seems to match Mythos and what it can do. We asked Michael at Anthropic about that. How is Anthropic thinking about other companies putting out similarly powerful tools? Yeah, well, we can't obviously speak to models or things that we haven't tested from other labs.
8:38What I can say is, again, I am optimistic that the moves that we are making at Anthropic right now are fostering these conversations, and so many people are out there patching vulnerabilities. And we hope that users using whatever models they have access to go and do the same. And we hope that that's us. But if it's not, it's most important that the vulnerabilities are patched and meaningfully increase the security of the cyber world. To Rachel, we are in a new, faster era. But not one that brings challenges that are fundamentally different from what we've tackled before. It's neither the case that the angels have appeared nor the case that the sky is falling, as far as we know.
9:17Okay. That's relieving to hear. How are you feeling, Waylon? I'm feeling like we should party like it's 1999. Party like it's 2026.
9:33This episode was produced by Cooper Casper Kim with engineering by Jimmy Keely. It was fact-checked by Sierra Juarez. Kicking Cannon edits the show and The Indicator is a production of NPR.
9:49This message comes from Insperity. Providing HR services and technology from payroll, benefits, and HR compliance to talent development. Learn more at insperity.com slash HR matters.
From the publisher
The Indicator has a weekly newsletter! Sign up now: npr.org/indicatornewsletter
Related episodes:
Fighting AI with AI
How AI might mess with financial models
For sponsor-free episodes of The Indicator from Planet Money, subscribe to Planet Money+ via Apple Podcasts or at plus.npr.org. Fact-checking by Sierra Juarez. Music by Drop Electric. Find us: TikTok, Instagram, Facebook, Newsletter.
See pcm.adswizz.com for information about our collection and use of personal data for sponsorship and to manage your podcast sponsorship preferences.
NPR Privacy Policy




