Research·4 min read
By BitsMindsSource: Horizon3.ai

A Bug Claude Mythos Found Was Exploited Within a Day

Horizon3 used Anthropic’s Claude Mythos to find a critical flaw in the Rejetto HFS file server: its login cookies were signed with a key from Math.random(), which Mythos showed could be rebuilt from twelve logins. Attackers were using the bug the day after the write-up. Users should update to HFS 3.2.1.

Mythos cracks Rejetto HFS's random signing key A large ivory die on a cream field, the official Anthropic mark inlaid in clay on its front face. Its top face has split along a crack, and a brass key is rising out of it: the session signing key recovered from Math.random. Faint leaked random numbers drift in from the left; faint cookie fragments sit on the right. 0.73418 0.11902 0.58361 0.92047 0.30775 admin=1 sig:9f3c keygrip xs128+ BITSMINDS.COM
Share:

A critical vulnerability found with Anthropic’s Claude Mythos was being exploited in the wild the day after it was made public. The bug, CVE-2026-61500, is in Rejetto HFS, a popular free HTTP file server, and lets an unauthenticated attacker forge an administrator login and then run code on the host. Horizon3.ai researcher Zach Hanley published the details on 30 September. By the next evening, VulnCheck’s canary servers had recorded an attacker on a China-hosted IP address going after vulnerable machines in the US and Japan, The Register reports.

The fix is already out. HFS versions 3.0.0 through 3.2.0 are affected, the vulnerability record shows, and version 3.2.1 closes the hole along with other security flaws. The CVE record itself dates from July, so the patch was available well before Horizon3 explained how the attack works; the servers hit last week were ones that had not been updated. Anyone running the 3.x server on an internet-facing machine should update now.

Twelve logins to an admin cookie

The flaw is a textbook mistake with an unusually elegant exploit. HFS signs its session cookies with a key generated by JavaScript’s Math.random(). In V8, the engine behind Node.js, that function runs on an algorithm called xorshift128+, which is fast but not built for secrets: anyone who sees a handful of its outputs can work out its internal state and then calculate every number it has produced or will produce. On its own, that is a theoretical weakness. What made it exploitable is that HFS also handed raw outputs of the same generator to unauthenticated users during login.

Horizon3’s exploit chains the two. It enumerates the admin username through an unauthenticated endpoint, starts a dozen logins to collect leaked random values, and feeds them to Microsoft’s Z3 constraint solver to recover the generator’s state. From there it steps the generator backwards to the value it produced when the server started, which is the cookie-signing key. With the key, the attacker signs a valid administrator cookie and uses HFS’s own server-code setting to execute code. Horizon3 says three to five consecutive outputs are enough for the solver.

What Mythos actually did

Horizon3 runs a vulnerability research system of specialised agents working in parallel, and the finding came from a cryptographic-analysis agent driven by Mythos. The company says the humans supplied the harness and the initial direction, and that Mythos found the chain without follow-up prompting. The part Hanley singles out is the connection. Mythos, he wrote, “didn’t just flag the insecure PRNG in isolation”: it noticed the separate leak, saw that the two facts formed a chain, and worked out that the leak gave exactly the observations needed to rebuild the state. Horizon3’s researchers add that turning an SMT solver on a real-world crypto weakness is not something they would normally have prioritised.

That is a different kind of result from the bulk numbers usually attached to Mythos. Anthropic’s Project Glasswing has put the model to work across open source, and The Register counts 286 CVEs credited to Mythos and Glasswing so far. This one required reasoning across two code paths and a piece of number theory, which is closer to what a skilled human cryptanalyst does.

The day-one problem

The less comfortable lesson is the speed. This is only the second Anthropic-linked vulnerability known to have been exploited in the wild, but the window between a public write-up and real attacks was about a day, and the write-up itself was detailed enough to rebuild the exploit. VulnCheck saw four more attempts on Friday, from US proxy addresses. As AI models find more bugs and describe them more clearly, the time defenders have to patch is shrinking at the same moment the volume of disclosures is rising. Anthropic itself warned on 1 October that open models are close behind Mythos at writing exploits, so a bug like this one may soon not need a restricted model to find. For HFS users, the response is simple: run 3.2.1 or later, and do not leave the admin interface reachable from the internet.

More on Claude

Evergreen coverage we keep current — start here.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles

Meta Muse Spark's six math papers A fan of research manuscripts on a deep blue field. Five sheets behind carry gold check marks for the five open problems answered; the front sheet carries the official Meta mark, inlaid. Faint mathematical symbols float on either side. ∫ ∑ ψ |G| = 384 ∂ₜu λ ≥ 0 ℚₚ ≠ MUSE SPARK · THINKING 6 PAPERS · 5 OPEN PROBLEMS BITSMINDS.COM
Research

Meta Says Muse Spark Helped Crack Five Open Math Problems

arXiv's manuscript meter: two submissions per month On a burgundy desk, a tall, uneven stack of manuscripts and loose research sheets meets an imagined cream-and-burgundy submission meter bearing the official arXiv wordmark. A large physical counter reads 2 / MONTH, PER SUBMITTER. On the other side, a shallow brass-and-ivory tray holds exactly two illustrated manuscript sheets. Paper diagrams, fold corners, a retaining arm and a slim desk pen make the scene tactile. The meter is an editorial metaphor for the limit of two submissions per calendar month by the person uploading them, across all subject areas. The sheets are not represented as peer-reviewed or approved; rejected submissions also consume the monthly quota. The separate limit of three active submissions is not depicted, and the large stack is symbolic of submission volume rather than one person's active moderation queue. Original vector illustration for BitsMinds, 2 October 2026. arxiv-caps-submissions-two-per-month-ai-papers. Self-contained SVG with the project arXiv logo; no raster art or external resources. 2 / MONTH PER SUBMITTER SUBMISSIONS BITSMINDS.COM
Research

arXiv Caps Submissions at Two a Month as AI Papers Pile Up

GLM-5.3 · OPEN BITSMINDS.COM
Research

Anthropic: Open GLM-5.3 Nearly Matches Mythos at Exploits