Daniel Stenberg, who created cURL, says Anthropic’s “Mythos” bug-hunting effort did not produce meaningfully more or better results than existing AI code-analysis tools, despite strong public hype. Stenberg reports that he was told he could try Mythos through Anthropic’s Project Glasswing program, but he did not receive direct access to the model. Instead, another party with access ran Mythos against cURL’s codebase and sent him the resulting report.

The scan targeted a recent cURL master-branch commit and initially listed five items described as “confirmed security vulnerabilities.” Stenberg says he expected a much longer set of issues. After his cURL security team reviewed the items, they reduced the findings to one confirmed vulnerability. He adds that three of the remaining items were false positives related to known or documented cURL limitations, and a fourth item was assessed as a non-security bug.

Stenberg says the single confirmed issue is low severity and is expected to result in a low-severity CVE to be published alongside the upcoming cURL release 8.21.0 in late June. He concludes that so far there is no evidence Mythos finds deeper or more advanced problems than other tools, characterizing the hype as primarily marketing.