Anthropic's Mythos and rivals could end law enforcement hacking

Anthropic's Mythos and rivals could end law enforcement hacking

A blog post published after this year's USENIX Security conference argues that artificial intelligence is about to make widely used software so secure that U.S. law enforcement and intelligence agencies will lose most of their ability to hack into devices, a shift the author expects to revive political pressure for government backdoors in encryption.

The piece traces the history of the underlying problem. Encryption started locking investigators out of phones around 2010, when Apple began encrypting iPhone storage with a key derived from the user's passcode, followed the next year by end-to-end encrypted text messages. WhatsApp, then a small startup, had gathered 600 million users worldwide by 2014 and nearly a billion by 2016, almost all of them defaulting to end-to-end encrypted messaging and calls. In 2014, FBI Director Comey responded by launching an initiative called Going Dark, meant to start a national conversation about making encrypted communications legible to law enforcement. In 2016, after a terrorist attack left the FBI holding a locked iPhone that Apple refused to unlock, an outside company stepped in and hacked the phone instead, defusing the standoff and, in the author's telling, effectively ending the original Going Dark push. For the decade that followed, agencies relied on purchased hacking tools such as GrayKey for unlocking phones and NSO Group's Pegasus for remote exploitation, while vendors like Apple and Google patched vulnerabilities as fast as they were found, but offensive researchers kept finding new ones.

The author argues that dynamic is about to break. This April, Anthropic announced a model called Mythos that turned out to be unusually skilled at finding software vulnerabilities; the U.S. government briefly blocked its export, but the move turned out to be mostly pointless once OpenAI and the Chinese open-weight labs Z.ai and Moonshot demonstrated comparable bug-hunting ability. Companies are now rebuilding their CI toolchains to run AI-based vulnerability scanning before code ever reaches a human reviewer, and the author expects this to push major, well-maintained software toward running out of remotely exploitable bugs within about two years, describing it as a likely 'ceiling' on the number of useful bugs left to find, while also noting that counting the exact number of bugs in a piece of code is probably uncomputable.

If that forecast holds, the author expects law enforcement and intelligence agencies to face a capability gap unlike anything since 2010, and predicts renewed, more urgent demand for mandated 'exceptional access' backdoors in encrypted systems. The post argues that past pushback against backdoors in the U.S. was driven less by principle than by the fact that agencies could already buy hacking tools instead, and that once that option dries up, pressure on industry to build in backdoors will intensify. The author warns that any such backdoors would likely be required only in the countries that demand them, weakening those countries' own software while leaving it exposed to foreign adversaries, and raises the possibility that other governments could respond by dropping their dependence on U.S. software altogether. The post closes without a proposed solution, with the author saying only that there is hope the right choices get made this time.

Key facts

  • Anthropic's Mythos, announced in April, proved unusually good at finding software vulnerabilities; a U.S. export block on it turned out to be mostly pointless once OpenAI and the Chinese open-weight labs Z.ai and Moonshot showed comparable bug-hunting ability.
  • The author forecasts that within about two years, major well-maintained software will run out of remotely exploitable bugs as AI-based vulnerability scanning gets built into CI toolchains ahead of human review.
  • That would undercut the law enforcement hacking work-around that began in 2016, when an outside company cracked a locked iPhone for the FBI after Apple refused to help, following FBI Director Comey's 2014 Going Dark initiative.
  • WhatsApp had gathered 600 million users by 2014 and nearly a billion by 2016, illustrating how fast default end-to-end encrypted messaging displaced wiretappable calls and texts.
  • The author expects the resulting law enforcement capability gap to revive demand for mandated encryption backdoors, weakening the software of whichever countries impose them and possibly pushing other governments away from U.S. software.

Why it matters

For the first time since around 2010, AI-driven vulnerability hunting could largely shut down the lawful-hacking work-around that law enforcement and intelligence agencies have relied on since the 2016 Apple v. FBI standoff. If well-maintained software genuinely runs out of remotely exploitable bugs within a couple of years, agencies lose a major surveillance capability quietly, with no change in the law, and the author argues that is exactly the kind of shift that tends to trigger a political push for a substitute.

Who it affects

U.S. law enforcement and intelligence agencies, which the post says stand to lose hacking capability; major software vendors such as Apple and Google, who would face renewed pressure to build in exceptional-access backdoors; ordinary users of encrypted messaging and devices, whose security could be weakened by any backdoor that gets mandated; and non-U.S. governments and their users, who the author suggests might respond by dropping their reliance on U.S. software.

How to use it

There is no product here, so the practical value is knowing what to watch. The models doing the vulnerability hunting are named directly: Anthropic's Mythos, OpenAI's models, and the Chinese open-weight labs Z.ai and Moonshot. The trend to track is how fast CI toolchains adopt AI-based vulnerability scanning ahead of human review, since that is the mechanism the author expects to close off the remaining supply of exploitable bugs over the next two years.

How solid is it

This is a single-author opinion and forecasting post on a specialist cryptography blog, written just after USENIX Security, not a study backed by data. The underlying claim that AI models are now competitive at vulnerability discovery is anchored to a real event, the U.S. export block on Mythos, and named labs, but the two-year timeline is the author's own extrapolation. The author explicitly flags that counting the exact number of exploitable bugs in software is probably uncomputable, so the forecast cannot be checked against a hard number. Read it as an informed argument, not a measured trend.

Risks and caveats

The predicted two-year timeline is speculative and could miss in either direction. The author's own downside case, that any mandated backdoor would weaken the software of exactly the country that demands it while foreign adversaries exploit the resulting weakness, is itself a forecast, not an observed outcome. The post ends by admitting the author has no concrete plan to prevent the scenario it describes, only hope that better choices get made this time.

“I'm concerned that AI is going to make software much too secure.”

— the blog post's author