Two months after the limited release of Anthropic’s Mythos, banks and financial services companies are scrambling to patch cybersecurity vulnerabilities as Mythos-class models expose weaknesses.
“We have to make sure that we’re secure, we’re prepared, we’re doing the best we can not to have vulnerabilities exposed,” Chief Executive Chuck Robbins said during cybersecurity and IT company Cisco’s fiscal fourth-quarter earnings call on Aug 12.
Mythos is accelerating Cisco’s renewed focus on cyber investment into its networks, routing and wireless services, Robbins said.

Financial institutions have many concerns regarding Mythos and no concrete solutions, James White, vice president of growth and market strategy at fintech Engage Fi, told FinAi News, adding that Mythos-class tools make breaking into internal systems a cakewalk.
Other Mythos class models include ChatGPT 5.6, DeepSeek V4, and Grok 4.6.
“It can have a domino effect because every bank is connected to another through one or another technology,” White said. “Everyone individually and collectively needs to up the standards of cyber defense.”
Only a select group of banks and financial institutions have access to Mythos, according to White House’s Project Glasswing launched in March. They were told to discover and patch vulnerabilities ahead of wider release.
Agentic AI attacks in the past two months include:
- Mythos and OpenAI’s GPT-5.6-Sol attempted to manipulate human checkers into approving malicious code by developing fake personas, lying and hiding evidence, according to a report from the UK government’s AI Security Institute on Aug. 4;
- OpenAI models broke out of a sandboxed test environment, breached AI-driven coding platform Hugging Face‘s production infrastructure and stole credentials;
- Mythos escaped a cybersecurity evaluation and published working malware to coding platform Python Package Index, executed on 15 real systems; and
- Mythos discovered coding flaws in common cryptographic algorithms, the backbones of cybersecurity systems, according to a July 28 release.
ALSO READ: Nvidia: Open-source models allow banks to build their own intelligence
Increased speed, low barrier to entry
The industry is most concerned how quickly vulnerabilities can be exploited, Douglas Buan, chief information security officer at Wind River Payments, told FinAi News.
“It’s happening not soon, but right now,” Buan said, adding that in “the wrong hands, [the models] are like a magic wand for an attacker to get into an environment.”
When attacks move at machine speed, the entire economics of cyber-risk changes for banks, Radi El Haj, chief executive of cybersecurity company RS2, told FinAi News.
“Traditionally, there has been a time buffer between discovery, disclosure, patch development and deployment,” he said. “That buffer is already under pressure, but advanced AI systems compress it further.”
AI tools make it easier for people to commit fraud, Kim van Lavieren, chief technology officer at cybersecurity platform Dawnguard, told FinAi News.
“You used to build malware by hand, which takes a long time, takes a lot of expertise, and now anybody with access to these tools can build these exploits extremely fast.”
Cybersecurity teams undervalued
Cybersecurity experts have long asked that security not to be an afterthought in software system development, but budget constraints, timing and lack of awareness have restricted investment, Matt Sekerke, a fellow at the Institute for Applied Economics at Johns Hopkins University, told FinAi News.
Sekerke described Mythos as “turning on the light” for cybersecurity teams that have been searching for vulnerabilities in the dark.
“Cybersecurity just hasn’t been recognized as a discipline as much as it should be; so here we are,” Sekerke said. “The pendulum is in favor of the adversaries at this point.”
Potential for helping banks
While Mythos-class models threaten core software systems, they also allow banks and fintechs to strengthen their defenses and rebuild faulty software systems, Dawnguard’s van Lavieren said.
That is the goal, Nicholas Lin, head of product for financial services at Anthropic, previously told FinAi News. “We’re really hoping for Mythos to help our bank customers get ahead of more vulnerabilities, which is precisely what it was designed for.”
Cisco’s Robbins said that clients are looking forward to the “impending Mythos effect,” forcing companies to update their systems and develop more robust cybersecurity frameworks.
Register here for the FinAi Lending Summit, set for Oct. 7-8 in Las Vegas. This inaugural event will include speakers from Fifth Third and Capital One as well as a fireside chat with Piermont Bank founder and Chief Executive Wendy Cai-Lee.





