Opus 5 Matches Mythos 5 on Bug Finding, Trails on Exploits

Anthropic released Claude Opus 5, which rivals Mythos 5 at locating software vulnerabilities but performs worse at turning those findings into working exploits.

Anthropic on Friday released Claude Opus 5, a lower-cost model that closely matches the company’s Mythos 5 system at identifying software vulnerabilities but falls short at generating working exploits, Anthropic reported.

The company evaluated Opus 5 using an OSS-Fuzz-based test that measures a model’s ability to locate vulnerabilities in code and then develop exploits with minimal human guidance. According to Anthropic’s results, Opus 5 identifies vulnerabilities at a rate near Mythos 5, while its score for producing functional exploits is substantially lower.

Anthropic said the performance gap reflects a decision not to train Opus 5 directly on offensive cyber operations. The company described Opus 5’s vulnerability-finding improvements as the result of broader capability upgrades rather than focused exploit training.

Opus 5’s safety classifiers are less restrictive than those on Fable 5, with Anthropic estimating roughly 85 percent fewer automated safety interventions. The model is allowed to search source code for weaknesses. Tasks that involve binary-based vulnerability scanning, penetration testing, and exploit generation remain blocked by classifiers.

When a request triggers those protections, the system automatically falls back to the older Opus 4.8 model inside Claude.ai, Claude Code, and Claude Cowork. Anthropic also provides enterprises and researchers enrolled in its Cyber Verification Program access to a version of Opus 5 with fewer restrictions for validation work.

Mythos 5 remains restricted from general release. Anthropic positions Fable 5 as a safeguarded, publicly available counterpart built on the same core architecture. Both Mythos- and Fable-related models were temporarily taken offline last month after the U.S. government raised concerns about their use by foreign nationals; access was later reinstated following adjustments.

Pricing for Opus 5 matches Opus 4.8: $5 per million input tokens and $25 per million output tokens. A faster-response mode is available at double the base price.

Anthropic separates source-level code analysis from more sensitive tasks like exploit generation and offers a pathway for vetted partners to test Opus 5 under looser restrictions for verification work.

Articles by this author