https://hacks.mozilla.org/2026/05/behind-the-scenes-hardenin...
So while Mythos certainly is real I think you could do the same with Deepseek pro, GPT 5.5 etc...
This new post makes it pretty clear that this was all bolted on-top of their existing fuzzing infrastructure, and really just used to get more and better initial hits that a very skilled team is looking at. I assume Anthropic was giving them a very good deal on inference for the positive PR, but I believe these other reports and suspect Mozilla did not really need them.
When I hear that "we found X bugs using some new tool", where the standard for bugs is low and doesn't neccessarily require user impact in realistic scenarios, I think to myself- duh! You went looking for bugs, of course you found them.
For a sufficiently complicated product, in my experience, you don't have to look far.
That's the "'No Way to Prevent This,' Says Only Nation Where This Regularly Happens" of unsafe languages.
There are huge swathes of problems we know how to categorically prevent, but some people won't do it because they're more comfortable believing it was never preventable than accepting any culpability for not preventing it previously.
The skill required to find then create zero days is quickly approaching the floor.
Then they loop over a codebase like this. This way you always point a model at a 'known' bug. And I assume a smaller context window helps with quality.
Not entirely sure it's obviously proprietary.