MLXIO
a rack of electronic equipment in a dark room
CybersecurityMay 27, 2026· 8 min read· By MLXIO Insights Team

1,600 Bugs: AI Hacking Tools Put Ethical Hackers on Notice

Share

MLXIO Intelligence

Analysis Snapshot

57
Moderate
Confidence: LowTrend: 10Freshness: 95Source Trust: 92Factual Grounding: 90Signal Cluster: 20

Moderate MLXIO Impact based on trend velocity, freshness, source trust, and factual grounding.

Thesis

High Confidence

Chompie’s warning is that AI tools such as Claude Mythos and Claude Code are already accelerating ethical hacking, which could reduce the scarcity value of routine vulnerability research while pushing top hackers toward harder targets.

Evidence

  • Anthropic says Claude Mythos has found 1,600 vulnerabilities across hundreds of software programs, according to the article.
  • Chompie uses tools like Claude Code to work faster in competitions and in her role as a security researcher for IBM X-Force.
  • At Pwn2Own Berlin, Chompie won $20,000 for hacking a system linked to Nvidia and another $50,000 for hacking a Linux-based system after working overnight.
  • Pwn2Own hackers collectively found 47 brand-new hacking methods and were awarded nearly $1.3m.

Uncertainty

  • The article does not specify how many Claude Mythos findings were independently validated or fixed.
  • It is unclear how quickly AI tools will move from assistant role to replacing lower-complexity hacking work.
  • The article does not quantify how AI use is affecting bug bounty prices or researcher earnings.

What To Watch

  • Validation and remediation rates for the 1,600 reported Claude Mythos vulnerabilities.
  • Adoption of AI assistants by top bug bounty hunters and competition teams.
  • Prize, payout, or bounty changes for routine versus complex vulnerabilities.

Verified Claims

Anthropic says Claude Mythos has found 1,600 vulnerabilities across hundreds of software programs, according to BBC Tech.
📎 “Anthropic says Claude Mythos has found ... many flaws across hundreds of software programs, according to BBC Tech.”High
Valentina Palmiotti, known as Chompie, was the most successful individual at Pwn2Own Berlin.
📎 “Valentina Palmiotti, better known as Chompie, was the most successful individual at the annual hacking competition.”High
Chompie won $20,000 for hacking a system linked to Nvidia and later won another $50,000 for hacking a Linux-based system.
📎 “She won $20,000 for hacking a system linked to Nvidia ... another $50,000 by hacking a Linux based system.”High
Chompie uses AI tools like Claude Code to work faster in competitions and in her role as a security researcher for IBM X-Force.
📎 “She uses tools like Claude Code to work faster in competitions and in her job as a security researcher for IBM X-Force.”High
At Pwn2Own, hackers collectively discovered 47 brand new hacking methods and nearly $1.3 million in prizes was awarded.
📎 “hackers collectively discovered 47 brand new hacking methods ... Nearly $1.3m (£970,000) was awarded.”High

Frequently Asked

How many vulnerabilities did Claude Mythos reportedly find?

Anthropic says Claude Mythos found 1,600 vulnerabilities across hundreds of software programs, according to BBC Tech.

Who is Chompie in ethical hacking?

Chompie is Valentina Palmiotti, described in the article as the most successful individual at Pwn2Own Berlin and a security researcher for IBM X-Force.

How did Chompie use AI in hacking competitions?

Chompie told the BBC that AI tools help her win bug bounties, and she uses tools like Claude Code to work faster in competitions and at IBM X-Force.

What did Chompie warn about AI and ethical hacking?

She warned that AI may reduce the amount of lower-hanging fruit in security research, making routine vulnerabilities less available to human hackers.

What is Pwn2Own?

Pwn2Own is a hacking competition run by the ZeroDay Initiative where ethical hackers find vulnerabilities in specific products.

Updated on May 27, 2026

1,600 vulnerabilities is the number that turns Chompie’s warning from a personal anxiety into a market signal: Anthropic says Claude Mythos has found that many flaws across hundreds of software programs, according to BBC Tech.

That claim sits beside a very human scene from Pwn2Own Berlin. Valentina Palmiotti, better known as Chompie, was the most successful individual at the annual hacking competition. She won $20,000 for hacking a system linked to Nvidia, then worked from 6pm til 6am before landing another $50,000 by hacking a Linux based system.

Her warning is not that AI will end ethical hacking tomorrow. It is sharper than that. The work that made elite hackers scarce — testing ideas, probing code paths, drafting exploit logic, and grinding through failure — is becoming software-assisted. MLXIO analysis: if enough of that workflow gets automated, the value of human-only speed gets repriced.


1,600 reported vulnerabilities put human speed under pressure

Chompie told the BBC that AI tools are helping her win bug bounties today. She uses tools like Claude Code to work faster in competitions and in her job as a security researcher for IBM X-Force. That detail matters because the disruption is not theoretical. The top tier is already using AI.

“I competed in Pwn2Own this year because I thought it might be my last chance,” she explained.

She framed the current moment as a “sweet spot” where AI still acts as an aid. But she expects that to change with systems like Claude Mythos and GPT 5.5 Cyber.

“That isn't to say that I think that there's going to be no room for security research or ethical hacking, but I think that a lot of the lower-hanging fruit will start to go away.”

That is the core economic shift. AI does not need to replace an entire hacker to change the market. It only needs to replace enough of the repeatable work to make more people competitive, push routine findings down in value, and force elite researchers toward harder bugs.

This also connects to a broader coding-risk theme we have tracked in Claude Code Exposes the New Coding Risk: Blind Trust: AI can accelerate expert work, but it also raises the cost of bad validation.

$1.3m in prizes shows why automation is financially attractive

Pwn2Own is run by the ZeroDay Initiative and asks ethical hackers to find vulnerabilities in specific products. This year, hackers collectively discovered 47 brand new hacking methods across programs, websites, and software. Nearly $1.3m (£970,000) was awarded.

Those numbers explain why AI-assisted vulnerability discovery is not just a lab curiosity. There is direct money attached to speed, novelty, and proof. Chompie’s own competition rhythm shows the pressure: win once, run back to the hotel, work all night, present again.

“As soon as I won the first prize I ran back to my hotel room to keep working on the other one. I worked from 6pm til 6am and didn't sleep,” she said.

She called that state “zombie hacker mode” — hours of research and testing, powered by energy drinks and adrenaline.

“It's not healthy,” she laughed.

MLXIO analysis: AI changes the math inside that exhaustion. If an assistant cuts the time spent on code review, test generation, exploit drafting, or triage, the same researcher can attempt more paths. The same also applies to less experienced researchers, which may increase competition for lower-complexity bugs.

The upside is real. The flaws found at Pwn2Own were reported to companies so they can fix them before criminals find the same holes. Faster discovery can mean faster defense. But the market effect is uneven: common bugs become less scarce, while complex exploit chains become more valuable.

From all-night hacking to AI-assisted exploit chains

Cybersecurity has seen automation before. Static analysis, fuzzing, scanners, and code-review tools already changed what counted as elite work. They did not eliminate top hackers. They pushed them toward deeper systems knowledge, exploit chaining, and the judgment to separate a real vulnerability from noise.

Mythos-style systems appear different because they combine more of the workflow into one interface. The BBC reports that Anthropic views Mythos as potentially dangerous enough that it can only be released to a select few governments and cybersecurity institutions. That is not how ordinary developer tooling is treated.

Chompie’s concern is that “good or great” hackers may not be enough in this next phase. She pointed to Orange Tsai, another major Pwn2Own winner, as the kind of researcher likely to remain at the top. His team won $375,000 (£278,000) in Berlin by finding extremely complex hacking pathways.

Orange Tsai is less pessimistic.

“For me, AI feels more like a really awesome assistant that helps accelerate my research workflow,” he said.

He added:

“During research I usually come up with many interesting ideas, but unfortunately I still need to sleep, so I can't test everything one by one. AI can finally help free my hands,” he says.

That is the split. Chompie sees a market squeeze. Orange Tsai sees a research multiplier. Both can be true.

The winners and losers will not feel Mythos-style AI equally

Stakeholder Near-term benefit Pressure point
Elite ethical hackers Faster testing and more research paths Harder to stand out on easier bugs
Software vendors Earlier discovery of flaws More reports to validate
Security teams AI-assisted triage and testing Need rules for code access and proof-of-concept handling
Attackers Potential acceleration if tools leak or are copied Existing attacks still often rely on simpler methods

The BBC notes that criminals are already using AI to speed up attacks and, in some cases, create new pathways into systems. But it also reports that the vast majority of cyber-attacks still use long-established methods, including phishing and social engineering.

That distinction matters. Mythos-style AI may raise the ceiling for advanced offensive work, but much cybercrime does not require novel zero-days. The risk is not that every attacker suddenly becomes Orange Tsai. The risk is that more actors can automate parts of a workflow that once required deep training.

Chompie’s own conclusion is more optimistic for defenders than her career warning might suggest.

“I think that the tide is turning against offensive hackers. I think defence stands to gain a lot from the from this capability,” she said.

Her condition is access. The strongest tools need to reach defenders first so they can find and patch holes before criminals do.

This is also why Anthropic’s handling of Claude matters beyond one model. The company’s broader AI race has drawn scrutiny across research and product lines, including MLXIO’s coverage of Anthropic Grabs Andrej Karpathy for Claude AI Race.

Security teams now need policies for AI-generated exploits

For CISOs and security leads, the practical issue is governance. If AI tools can produce vulnerability claims or exploit paths, teams need rules for how those outputs are tested, stored, and disclosed.

Validation becomes central. Organizations cannot blindly accept AI-generated exploit claims. False positives, incomplete proofs, unsafe proof-of-concept code, or mishandled sensitive code can create new operational risk.

Developers may also see secure coding shift from periodic audits toward continuous adversarial testing. That does not mean every AI alert deserves equal urgency. It means teams will need better filters, stronger reproduction standards, and clearer escalation paths.

Aspiring ethical hackers face a harder apprenticeship curve. Basic vulnerability hunting may become less valuable if AI can surface routine flaws quickly. Skills that should hold value include systems thinking, exploit chaining, tool supervision, AI prompt strategy, verification, and responsible disclosure.

MLXIO analysis: the human edge moves from “I can find the bug” to “I can decide which bug matters, prove impact safely, and understand the chain better than the model.”

The next Pwn2Own prize table will test Chompie’s thesis

Chompie’s warning is not really about one champion hacker losing work. It is about offensive capability becoming more abundant while judgment stays scarce.

If AI keeps improving, bug bounty markets and competitions may stratify. Routine findings could become cheaper and faster to generate. Complex chains, unusual systems, and high-impact vulnerabilities may remain premium work for the best researchers.

The evidence to watch is concrete: whether future Pwn2Own contests show more AI-assisted wins, whether prize money concentrates among researchers who can direct AI best, and whether vendors tighten rules around AI-generated submissions.

If humans keep finding the hardest paths that models miss, Orange Tsai’s view gains weight. If lower-hanging bugs disappear faster and more researchers struggle to compete, Chompie’s “last chance” warning will look less dramatic — and more like an early read on where ethical hacking is headed.

Impact Analysis

  • AI tools finding 1,600 vulnerabilities signal a major shift in cybersecurity labor markets.
  • Elite hackers are already using AI, showing the disruption is happening inside the profession now.
  • If AI automates lower-level exploit work, bug bounty economics and security research careers could change quickly.

Human Ethical Hackers vs AI Cybersecurity Tools

AreaHuman Ethical HackersAI Tools like Claude Mythos
Current roleElite researchers like Chompie find and exploit vulnerabilities through skill, persistence, and experience.Tools are already helping researchers work faster and automate parts of vulnerability discovery.
Market impactHuman-only speed and scarcity have historically commanded high value in bug bounties and competitions.Automation could reprice that value by removing lower-hanging vulnerability work.
Near-term outlookChompie says AI is currently in a “sweet spot” as an aid to hackers.Systems like Claude Mythos could eventually take over more of the workflow.

Chompie's Pwn2Own Berlin Prize Wins

Nvidia-linked system hack
$20,000
Linux-based system hack
$50,000
MLXIO

Written by

MLXIO Insights Team

Algorithmic Research & Human Oversight

Powered by advanced algorithmic research and perfected by human oversight. The Insights Team delivers highly structured, cross-verified analysis on emerging tech trends and digital shifts, filtering out the fluff to give you high-fidelity value.

Related Articles

a computer generated image of the letter a
CybersecurityMay 16, 2026

Verizon Tests Anthropic’s Claude Mythos to Spot Cyber Threats Fast

Verizon joins Project Glasswing to test Anthropic’s Claude Mythos AI, aiming to accelerate vulnerability detection across its telecom infrastructure.

3 min read

A security and privacy dashboard with its status.
CybersecurityMay 12, 2026

Hackers Exploit AI Blind Spots—Secure Your ML Models Now

Machine learning models face unique security risks that traditional methods miss. This guide reveals how to protect AI systems from sophisticated attacks.

9 min read

person using laptop computers
CybersecurityMay 19, 2026

How to Build an Effective Penetration Testing Framework for

Enterprises must build repeatable penetration testing frameworks to detect vulnerabilities before hackers strike in 2026.

9 min read

a glass of beer
CybersecurityMay 16, 2026

Microsoft’s MDASH AI Snags 16 Critical Windows Flaws First

Microsoft’s MDASH AI detected 16 critical Windows flaws before hackers, shifting the cybersecurity balance with faster vulnerability discovery.

6 min read

slightly opened silver MacBook
CybersecurityMay 14, 2026

Anthropic’s Mythos AI Sparks Urgent macOS Security Hunt

Anthropic’s Mythos AI exposed new macOS vulnerabilities, pushing Apple into an urgent, unprecedented security investigation.

6 min read

graphical user interface
AI / MLMay 27, 2026

Uber's AI Budget Vanished in 4 Months — Where's ROI?

Uber’s AI bill ran dry in four months, but executives still can’t prove the tools are producing better products or margins.

8 min read

blue circuit board
TechnologyMay 27, 2026

UBS Triples Micron Target as $1T Memory Bet Erupts

UBS’s $1,625 target reframes Micron from memory cyclical to AI infrastructure bet, putting a $1T valuation within reach.

8 min read

a rack of servers in a server room
TechnologyMay 26, 2026

MX Linux 25.2 Ditches Flash for Debian 13.5 Fixes

MX Linux 25.2 focuses on Debian 13.5 updates, cleaner installs, broader hardware support, and refreshed ISOs—not flashy features.

7 min read

a 3d image of a judge's hammer on a black background
AI / MLMay 27, 2026

MiniMax Loses Early Escape in Disney AI Copyright War

MiniMax failed to escape Disney’s AI copyright suit, pushing Hailuo AI closer to discovery over alleged character copying.

6 min read

black and silver sony cassette player
TechnologyMay 27, 2026

May 28 Leak Throws Intel Arc G3 Into Handheld Race

Intel may reveal Arc G3 on May 28, giving MSI and Acer an early shot in the next PC handheld race.

7 min read

Stay ahead of the curve

Get a weekly digest of the most important tech, AI, and finance news — curated by AI, reviewed by humans.

No spam. Unsubscribe anytime.