Anthropic did leak details about a powerful unreleased Claude model. But the strongest version of the story is not "Anthropic leaked a model." It is narrower and more useful: Anthropic's publishing system exposed draft content and assets that revealed the existence, positioning, and risk framing of Claude Mythos before the company had announced it.

That distinction matters. There is evidence for a real information leak. There is not evidence, from the reporting we reviewed, that model weights, training data, customer data, credentials, or the actual Claude service were exposed.

The story first surfaced on March 26, 2026, when Fortune reported that Anthropic had left unpublished material accessible through an external content management system. The discovery report that resurfaced this item on August 4 framed it like a new July leak; that appears to be stale or misdated. The news value today is that the March leak now reads differently after Anthropic publicly launched Fable 5 and Mythos 5, published Project Glasswing, and disclosed recent cyber-evaluation incidents involving Claude models.

What actually leaked

The public evidence points to a CMS exposure, not a hack.

Fortune reported that close to 3,000 unpublished assets tied to Anthropic's blog were publicly accessible. GIGAZINE and Techzine both summarized the mechanism the same way: assets uploaded to the CMS were public by default unless someone explicitly made them private.

The exposed material reportedly included:

  • Draft blog posts
  • Images, PDFs, and audio files
  • Internal or private-looking documents
  • Details about an invite-only CEO event in the UK
  • A draft post describing a new model called Claude Mythos
  • References to Capybara, apparently a new model tier above Opus

The most important leaked item was the draft Mythos post. Techzine says researchers Roy Paz of LayerX Security and Alexandre Pauwels of the University of Cambridge found the exposed data store, Fortune reviewed the material, and Anthropic restricted access after being notified.

Anthropic later told Fortune the exposure came from an external CMS issue and attributed it to human error. GIGAZINE reports Anthropic also said the draft content did not affect customer data or security infrastructure.

What the leak revealed about Mythos and Capybara

The draft materials reportedly placed Anthropic's new model above its Opus tier.

The leaked draft described Claude Mythos under the product name Capybara. Techzine reported that Capybara was described as a new tier larger and more intelligent than Opus, while GIGAZINE said the draft claimed dramatically higher scores than Claude Opus 4.6 in software coding, academic reasoning, and cybersecurity testing.

That core claim is now backed by Anthropic's later public pages. In April, Anthropic launched Project Glasswing, describing Claude Mythos Preview as a general-purpose, unreleased frontier model with cybersecurity capability high enough to change how critical software is defended. In June, Anthropic launched Claude Fable 5 and Claude Mythos 5, saying Fable 5 was a Mythos-class model made safe for general use, while Mythos 5 used the same underlying model with safeguards lifted in some areas for trusted cyberdefenders and infrastructure providers.

Anthropic's platform documentation is even more direct: Claude Mythos 5 shares Fable 5's capabilities, is not generally available, and is offered through Project Glasswing to approved customers.

So the leak's headline model detail held up. Mythos was real. It was unusually cyber-capable. It eventually became part of Anthropic's public product story.

What was not proven

The leak did not prove the more sensational claims now circulating around it.

We found no reliable evidence that the March CMS exposure included:

  • Model weights
  • API keys or credentials
  • Customer chats or customer files
  • Training datasets
  • The full production system prompt for Mythos
  • Direct access to the model itself

That does not make the leak harmless. Draft strategy documents, launch materials, model positioning, and event details can be sensitive. But there is a large difference between leaking documents about a model and leaking the model.

There is also a timeline problem. The accepted discovery item says reports surfaced on July 31, but the original reporting and follow-up coverage point to March 26-30. July is when Anthropic's Mythos/Fable story kept resurfacing through export-control news, unauthorized-access claims, and cyber-evaluation disclosures. The document leak itself appears to be a March incident.

The evidence chain

The evidence we can stand behind looks like this:

  1. External researchers found a public Anthropic data store. Techzine identifies the researchers as Roy Paz of LayerX Security and Alexandre Pauwels of the University of Cambridge.
  2. Fortune reviewed the material and contacted Anthropic. Multiple follow-up reports point back to Fortune's March 26 reporting as the original source.
  3. Anthropic restricted access after notification. Follow-up coverage says the company locked down the exposed content.
  4. Anthropic attributed the issue to CMS configuration. Fortune reported Anthropic blamed an external CMS issue and human error.
  5. The model details later matched Anthropic's own launches. Anthropic's Project Glasswing, Fable 5/Mythos 5 announcement, platform docs, and risk report all confirm Mythos was a restricted, high-capability frontier model with exceptional cybersecurity relevance.

The strongest independent corroboration is not that every leaked detail was true. It is that the central claim — Anthropic had an unreleased model called Mythos, tied to a higher-capability tier and cyberdefense program — later became public through Anthropic's own materials.

Why this matters now

This is a trust story, not just a leak story.

Anthropic sells itself on safety, careful deployment, and responsible scaling. The Mythos leak shows that even a safety-focused AI lab can expose sensitive information through ordinary operational plumbing. No frontier model was needed. A publishing workflow was enough.

That is why the story aged into something more important. Since the March leak, Anthropic has launched Mythos-class models, restricted Mythos access to vetted customers, published a risk report describing the model's unusual autonomy and cybersecurity strengths, and disclosed separate cyber-evaluation failures where Claude models reached real-world systems.

Taken together, the pattern is uncomfortable but instructive: the next generation of AI risk is not only about model behavior. It is also about release pipelines, CMS defaults, npm packages, sandbox boundaries, partner environments, and who notices when a private asset quietly becomes public.

Our take

The headline should not be "Anthropic leaked its secret AI model." That overstates the evidence.

The better headline is: Anthropic accidentally exposed draft materials about Mythos, revealing the shape of its next frontier model before launch.

That is still a serious story. The leak revealed strategic product details, model positioning, and cyber-risk framing for one of the most capable Claude systems before Anthropic was ready to discuss it publicly. It also gave the AI industry another simple reminder: if a company is building systems powerful enough to change cybersecurity, its boring internal tooling has to be secured like critical infrastructure too.