Natto Thoughts

Natto Thoughts

AI & Emerging Tech

Chinese Firm Claims AI-Driven Bug Discovery Near Claude Mythos Scale

Chinese companies could match the capabilities attributed to Claude Mythos within months, according to industry experts, reinforcing existing cyber offense asymmetries

Eugenio Benincasa's avatar
Eugenio Benincasa
Apr 22, 2026
∙ Paid

Note added June 10, 2026

Following Anthropic’s Claude Mythos model release, on April 22 we posted the analysis below examining China’s progress in AI-driven vulnerability discovery and exploitation, with a special focus on Chinese cybersecurity company 360 (a.k.a Qihoo 360).

We believe it remains highly relevant given the ongoing importance of the topic and new developments. From April 28–30, 360’s Vulnerability Research Institute participated in DEFCON Singapore. A blog post by 360 claimed the team used AI agents but that “unlike previous presentations that focused on vulnerability discovery, this demonstration highlighted a key breakthrough in vulnerability exploitation capabilities.” An abstract is available here and in 360’s own blog post. This likely does not involve new vulnerability discovery but novel techniques applied to known ones, given the focus on building a better exploitation primitive – a reusable technique.

More recently, on May 28, 360 published a post claiming its vulnerability discovery intelligent agent is a “hot topic” overseas, citing an alleged English-written excerpt from “Street Insider” (华尔街内参). The Natto Team could not locate such a post on StreetInsider.com or any other English-language media. The post also cited two X posts from alleged influencers. One, reviewed by the Natto Team – from “Shruti” (@heyshrutimishra) on May 20, claiming 360’s model superiority over Claude Mythos – received 31 likes and 5 reshares. The @heyshrutimishra account regularly posts about China’s AI developments, consistently framing them as breakthroughs. This episode illustrates 360’s effort to boost its perceived capabilities through narrative in the face of a cutthroat market and broader US-China tech competition.

The post below offers detailed analysis of 360’s capabilities relative to Anthropic’s Claude Mythos and the implications for offensive capability given China’s structural asymmetries with Western democracies.

“Whoever masters automated vulnerability discovery technology holds the upper hand in cyber offense and defense” – Zhou Hongyi, Chairman and CEO, 360 Digital Security Group (2018)

On April 7, 2026, artificial intelligence developer Anthropic introduced its new general-purpose model Claude Mythos Preview to a restricted partnership of over 40 vetted organizations, including major technology and cybersecurity firms, as part of its defensive security initiative Project Glasswing. The company stated that the Claude Mythos model has identified thousands of high-severity vulnerabilities across widely used software, including major operating systems and web browsers. Crucially, in some cases it can autonomously develop exploits and chain vulnerabilities without human intervention. Anthropic has not released the system publicly, citing the risks associated with such capabilities and the need for further safeguards before deployment at scale.

While independent assessment remains limited and technical details are sparse, governments are already responding: U.S. officials have reportedly briefed financial institutions on AI-enabled cyber risks, while German authorities have warned of significant disruption and the capacity of such systems to transform vulnerability discovery.

Recent developments suggest that similar capabilities are being explored in China. In February 2026, Natto Thoughts described how a team from 360 Digital Security Group (奇虎360, hereafter “360”), which won first place at the 2026 Tianfu Cup, a major Chinese exploit hacking contest,1 had relied extensively on AI-assisted discovery and exploitation, with its team lead stating that AI has evolved “from an auxiliary tool to the core engine of vulnerability discovery.” The team that placed third made similar claims. This raises a central question: have Chinese companies already developed systems with capabilities comparable to those claimed for Claude Mythos, and how might differences in institutional context shape their impact?

This analysis focuses on 360 as a primary case study, given its position as a leading cybersecurity company in China, its strong track record in top-tier vulnerability research, and the relative visibility of its recent AI-related disclosures.2 Recent disclosures describe internally developed multi-agent systems capable of identifying vulnerabilities, supporting exploit development, and automating parts of the research workflow that were previously manual, with claimed discovery at a scale approaching Anthropic’s description of Claude Mythos. Other firms appear to be pursuing similar approaches, though with more limited public information. The analysis then considers how such capabilities could translate into an asymmetric offensive advantage in China’s favor.

User's avatar

Continue reading this post for free, courtesy of Natto Team.

Or purchase a paid subscription.
© 2026 Natto Thoughts · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture