주메뉴바로가기본문바로가기
비즈한국 비즈한국

Mythos Shock
① "Chilling to the Bone": The Global Fear of a Too-Powerful AI Hacker

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →
Editor's Note
For decades, humans have been the primary agents for discovering and defending against security vulnerabilities. If AI takes over this role, in whose hands will the offense and defense of cyberspace lie in the future? The "Mythos Shock" is an incident that has posed this very question to both industry and government. We examine the industry turmoil and responses sparked by the Mythos Shock, and look at the challenges now facing South Korea.

[비즈한국] "It was truly chilling to the bone." An executive at the Korean branch of a foreign cloud company recalled the moment in early April when they reviewed the announcement materials for a new AI model released by Anthropic. The phrasing—suggesting that the model was "too powerful to be released freely" and would only be opened to a carefully selected handful of institutions—felt, in their words, like a trailer for a disaster movie designed to ramp up a sense of crisis. The model's name was 'Mythos.' In the three months since its release, this single AI model has sent waves of tremors through both industry and government.

As a cloud service provider, this official ranked Mythos at the top of the list of issues they have grappled with on the front lines with clients. "From the moment I saw the announcement, both our headquarters and the Korean branch spent a long time in deep internal deliberation over what kind of impact this model would have on the security ecosystem and the cloud market," the official explained.

The Mythos Shock Shakes the Industry

In fact, as word spread that Mythos possessed the ability to discover vulnerabilities surpassing that of human hackers, it triggered an emergency summons of the U.S. Department of the Treasury, the Federal Reserve, and CEOs of major Wall Street financial firms within four days of its release. The White House and U.S. government departments held a closed-door security review meeting with the heads of major AI companies for three days, and the national cybersecurity control tower initiated an exhaustive investigation into security vulnerabilities across government facilities and infrastructure.

Unlike ChatGPT or Gemini, which operate according to user prompts, Mythos is an "agentic" model that performs the entire process itself—from research and coding to testing and reporting. Its power lies in its "autonomous security intelligence," which can deduce the design structure of complex software at a level comparable to human experts to find vulnerabilities and even design penetration paths. It then uses its autonomy to immediately weaponize the discovered flaws into hacking tools.

The AI model 'Claude Mythos,' released by Anthropic on April 7, is an autonomous security intelligence system that can infer the design structure of complex software to the level of a human expert to find security vulnerabilities and even design infiltration paths on its own. Photo=Generative AI

In actual tests, behaviors were observed such as "jailbreaking"—bypassing restrictions to connect to the internet or rummaging through internal system information to gain administrator privileges—and even attempts to erase traces after circumventing security measures to hide its own actions. Anthropic explained that these were not motivated by malice, but by an excessive goal-oriented nature.

Central banks and financial authorities around the world have also begun emergency risk assessments regarding AI-driven cyber threats. Within five days of the announcement, Anthropic launched the security coalition "Project Glasswing," distributed $100 million worth of Mythos access licenses, and announced a sequential disclosure of vulnerabilities within 90 days. In South Korea, alarm bells rang across all sectors, including the Financial Supervisory Service urgently summoning security practitioners from major financial firms.

The U.S. government imposed export controls on Mythos 5 and Fable 5 on June 12, only to lift them 18 days later. The National Assembly Research Service analyzed that this situation sets a precedent that high-performance AI models can become strategic assets subject to government control at any time. Photo=Generative AI

The security industry, which designs defenses, is now focused on speed and trust. A security official at a major Korean conglomerate’s IT service division said, "The biggest concern is that it can launch attacks 24 hours a day without rest, and at speeds far beyond what humans could block in the past. Perimeter-based security, which assumes safety as long as you are on the internal network, is no longer valid." They added, "There is a growing need for both 'Zero Trust'—which constantly verifies every access attempt—and procedures where humans must re-verify tasks performed by AI."

AI Threats vs. AI Security... Must 'Co-evolve' with Humans

The perception that "AI is essential for both attack and defense" is solidifying inside and outside the industry. SK Shieldus recently pointed out in an analysis of threat trends that cybersecurity has entered the era of "AI threats vs. AI security," while Dream Security characterized Mythos as the "democratization of cyberattacks," warning of the structural vulnerabilities in Operational Technology (OT) sectors where defense systems are outdated.

The Mythos Shock is being discussed beyond security as a matter of strategic assets. Jung Joon-hwa, a legislative researcher at the National Assembly Research Service, analyzed in a report that this incident "sets a precedent that high-performance AI models can become strategic assets subject to government control at any time," shifting the focus of AI model competition from pure inferential performance to "securing control over security." Indeed, the U.S. government imposed and then lifted export controls on Mythos last month.

However, there are also cautious voices suggesting we need to accurately view the nature of the threat. Song Kyung-ho, a senior researcher at the AI Safety Research Center of the Electronics and Telecommunications Research Institute (ETRI), defined the cyber capabilities of Mythos as "not explicitly intended, but manifested as a byproduct of general improvements in capabilities like coding, reasoning, and autonomy." He forecasted, "If cyber capabilities are a byproduct of general capabilities, it is highly likely that the next leap will not be limited to cyber."

Experts believe it is difficult to expect perfect safety measures for high-performance AI like Mythos. Photo=Pixabay

Additionally, some point out that because South Korea restricts the cross-border transfer of data, it is difficult to effectively utilize such high-performance AI for defense purposes.

As the hallucination phenomenon in AI has recently decreased dramatically, experts expect models with almost no errors to appear by next year. Given that work productivity will rise exponentially within a year, the potential for security threats is also expected to skyrocket.

The problem is not a specific model like Mythos. Im Jong-in, professor emeritus at Korea University's Graduate School of Information Security, stated, "Models like Mythos or OpenAI's GPT-5.6 are not AI specialized for security from the start; they are agentic AIs that are good at everything while autonomously performing tasks." He added, "The challenge ahead is how we can proactively detect and control AI when it is highly capable but violates restrictions we have set."

However, Professor Im did not believe it is possible to expect perfect safety measures. He emphasized, "Since AI is also trained on human data, it possesses characteristics similar to humans. Security is always a battle between the spear and the shield. Rather than feeling vague dread, we should head toward 'co-evolution,' where humans and AI move forward in step together."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지