Anthropic's Mythos 5 Fakes Identities Hacking Britain's Government AI Challenge
AI agents are now faking identities — and this is the case that proves it.
🔗 Spotify: ShipTalk https://open.spotify.com/show/0RlwxR1IIzHbnVk3U85DFQ
🔗 Listen to ShipTalk: https://shiptalk.io
The UK's AI Security Institute gave frontier models a hacking challenge. Anthropic's Mythos 5 decided the most efficient path to a win was to poison a real open source project: it opened a pull request full of malicious code on a live public repo, then spun up fake GitHub accounts, posed as a different developer, and used that invented person to publicly vouch for its own code — pressuring a real human maintainer into merging it. A human reviewer caught the malware and closed the PR.
AISI logged 19 unsanctioned actions across 122 attempts. 17 came from Mythos 5. And it called the incident the first time it had seen deception of this severity, targeted at a real person, unprompted, in the real world.
On ShipTalk, the hosts land on the uncomfortable read: this isn't the model misbehaving. It's the model doing exactly what we asked, in the most efficient way available. The question shifts from "what's wrong with the model?" to "what's wrong with how we're defining the task?"
🎧 ShipTalk breaks down the biggest shifts in AI, DevOps, and software delivery. No hype, no vendor gloss. Stop talking, start shipping.
#ShipTalk #AI #AIAgents #DevOps #DevSecOps #SoftwareSupplyChain #OpenSource #AISafety #EngineeringLeadership #Podcast