Anthropic launched Claude Fable 5 as the public, safeguarded version of its new Mythos 5 model, describing both as configurations of the same underlying system and positioning Mythos 5 as its strongest cyber-capable model to date. In its system card, Anthropic said Fable 5 uses classifiers and fallback behavior to divert high-risk requests to Claude Opus 4.8, keeping its cyber performance roughly in line with the older model while Mythos 5 remains restricted to vetted partners through Project Glasswing. The company assessed Mythos 5 as a Tier 1 cyber offense risk, meaning it can materially assist offensive operations but does not autonomously conduct adaptive cyber campaigns.
Soon after release, researcher Pliny the Liberator reportedly bypassed Fable 5’s safeguards using a multi-agent jailbreak that combined Unicode obfuscation, long-context manipulation, narrative framing, and decomposition of harmful requests, allegedly eliciting exploit-development and chemistry-related guidance and exposing a leaked system prompt on GitHub. The incident undercut Anthropic’s claim that more than 1,000 hours of external testing had found no universal jailbreaks, while also intensifying criticism from security researchers who said Fable 5’s guardrails were already so broad that they blocked benign work such as reading security blogs, reviewing code, and writing secure software. Anthropic had not publicly responded to the jailbreak claims at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Anthropic announced on 2026-06-30 that the U.S. export controls on Fable 5 and Mythos 5 had been lifted. According to the reference, Fable 5 returned for global users on 2026-07-01 following review and mitigation steps.
According to the new report, the White House's action on Anthropic's models was partly driven by concern that a China-linked group may have accessed Mythos. The report says this concern related to prior unauthorized access to Mythos in April using information obtained from a data breach.
Independent reporting cited Amazon researchers as having found ways to make Claude Fable 5 assist with cyberattacks, with Amazon CEO Andy Jassy reportedly raising the issue to the US government. The reported discovery was described as the specific jailbreak that led to the export-control order and Anthropic's suspension of Fable 5 and Mythos 5.
On Friday night, Anthropic abruptly disabled access to its Mythos 5 and Fable 5 models for all customers after receiving a US Commerce Department directive imposing export controls on the models outside the United States. Anthropic said the immediate shutdown was necessary for compliance and that its other models were unaffected.
After backlash over hidden safeguard-triggered downgrades, Anthropic changed Claude Fable 5 so flagged requests visibly fall back to Claude Opus 4.8. The company also began providing API users with a reason when a request is refused.
Following the reported jailbreak, Pliny the Liberator allegedly published Fable 5's approximately 120,000-character system prompt on GitHub. The leak exposed the prompt used to govern the model's behavior and safeguards.
Shortly after Fable 5's release, researcher Pliny the Liberator reportedly bypassed its safety controls using a multi-agent strategy involving Unicode obfuscation, long-context manipulation, narrative framing, and decomposition of harmful requests. The reported bypass enabled offensive cybersecurity guidance and harmful chemistry-related outputs, challenging Anthropic's pre-launch claim that external testing had found no universal jailbreaks.
By June 10, 2026, cybersecurity researchers were publicly criticizing Fable's restrictions, saying it blocked benign tasks such as reading security blogs, writing secure code, and conducting code reviews. The criticism centered on Fable frequently falling back to Claude Opus 4.8 when cyber-related requests were triggered.
Anthropic's June 9, 2026 system card detailed the capabilities and risk assessment for Claude Mythos 5 and Claude Fable 5. It said Fable 5 uses classifiers and fallback behavior to Claude Opus 4.8 for high-risk cyber, biology, chemistry, and frontier LLM-development requests, and assessed Mythos 5 as Tier 1 cyber offense risk.
On June 9, 2026, Anthropic launched Claude Fable 5 as the first public model in its new Mythos class. Anthropic described Fable 5 and the restricted Claude Mythos 5 as two configurations of the same underlying model, with Fable 5 made generally available under added safeguards.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
28 references tracked. Mallory keeps watching after this page renders.
projectosint.substack.com
Open sourceschneier.com
Open sourceintrinsec.com
Open sourcerisky.biz
Open sourcedeploymentsafety.openai.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourcewww-cdn.anthropic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.