Artificial Intelligence

Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits

Binary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5.

Anthropic

Anthropic on Friday rolled out Claude Opus 5, pitching it as a cheaper alternative to its top-tier Fable 5 model. In terms of cybersecurity, the new model is nearly as good as the AI giant’s most capable system, Mythos 5, at spotting software vulnerabilities, but remains well behind it in turning those findings into working exploits.

The difference comes from Anthropic’s own OSS-Fuzz-based evaluation, which measures how well a model can locate and then exploit vulnerabilities with minimal human steering. According to the company, Opus 5 identifies vulnerabilities at a rate close to Mythos 5, but its exploit-development score trails considerably. 

Anthropic frames this as a deliberate outcome, noting that it has avoided training Opus 5 directly on offensive cyber tasks. The gains it does show, the company says, are a byproduct of broader capability improvements.

Opus 5’s safety classifiers are tuned to be less restrictive than those on Fable 5, with Anthropic expecting roughly 85 percent fewer interventions. 

The model is permitted to search for vulnerabilities directly in source code, but binary-based vulnerability scanning, penetration testing, and exploit generation remain blocked. Requests that trip those classifiers fall back automatically to the older Opus 4.8 model inside Claude.ai, Claude Code, and Claude Cowork.

Enterprises and researchers enrolled in Anthropic’s Cyber Verification Program can get a version of Opus 5 with those restrictions loosened further.

Mythos 5 also remains withheld from general release, while Fable 5 is described as the safeguarded, publicly available counterpart built on the same underlying model. Both models were taken offline by Anthropic last month due to the Trump administration’s concerns over their use by foreign nationals. The restrictions were later lifted.

Advertisement. Scroll to continue reading.

Pricing for Opus 5 holds at $5 per million input tokens and $25 per million output tokens (same as for Opus 4.8), with a faster-response mode available at double the base rate.

Related: Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

Related: CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

Related: OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review

Related Content

Artificial Intelligence

The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents.

Artificial Intelligence

Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone.

Artificial Intelligence

You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you...

Artificial Intelligence

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.

Vulnerabilities

Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.

Artificial Intelligence

OpenAI says its AI models went rogue, as CISOS call the incident a watershed moment, warning that autonomous AI threat models have officially crossed...

Artificial Intelligence

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.

Artificial Intelligence

Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version