It's just pure marketing, and most people are falling for it. The primary issue stems from their definition of "vulnerability". Most C code will be _swimming_ in vulnerabilities depending on how you analyze it (ie function that accepts a pointer but doesn't validate -> potential vulnerability right there). The only thing that matters is if it's de facto exploitable or not.
- They still claim 10000 issues, but they found only one in curl.
- They did not find rsync issues but Claude rather introduced rsync issues.
- Facebook is a member of this cult program but Mythos did not find the account takeover flaw.
- Mythos did not find the issues in Anthropic's own Bun rewrite.
They will not release Mythos because it would be exposed as a fraud before the IPO.