Cybersecurity Looks Like Proof of Work Now

Simon Willison's Blog / 4/15/2026

💬 OpinionSignals & Early TrendsIdeas & Deep Analysis

Key Points

  • The UK AI Safety Institute published an independent evaluation of Claude Mythos Preview’s cybersecurity capabilities, aiming to validate Anthropic’s claims about its ability to identify vulnerabilities.
  • The analysis suggests an economic dynamic where spending more tokens (and thus money) yields better exploit-finding results, effectively turning security review effort into a “proof-of-work”-like competition.
  • If true, the incentive structure shifts toward maximizing token burn to uncover more issues, potentially creating a rough cost equation comparing defender spending vs. attacker exploitation cost.
  • The piece argues this dynamic can increase the value of open source libraries because the security-review tokens spent can benefit all downstream users rather than being consumed per bespoke system.
  • Overall, the post reframes AI-assisted security testing as a resource-driven process rather than purely an accuracy-driven one, with implications for budgeting and incentives in vulnerability management.
Sponsored by: Teleport — Connect agents to your infra in seconds with Teleport Beams. Built-in identity. Zero secrets. Get early access

14th April 2026 - Link Blog

Cybersecurity Looks Like Proof of Work Now. The UK's AI Safety Institute recently published Our evaluation of Claude Mythos Preview’s cyber capabilities, their own independent analysis of Claude Mythos which backs up Anthropic's claims that it is exceptionally effective at identifying security vulnerabilities.

Drew Breunig notes that AISI's report shows that the more tokens (and hence money) they spent the better the result they got, which leads to a strong economic incentive to spend as much as possible on security reviews:

If Mythos continues to find exploits so long as you keep throwing money at it, security is reduced to a brutally simple equation: to harden a system you need to spend more tokens discovering exploits than attackers will spend exploiting them.

An interesting result of this is that open source libraries become more valuable, since the tokens spent securing them can be shared across all of their users. This directly counters the idea that the low cost of vibe-coding up a replacement for an open source library makes those open source projects less attractive.

Posted 14th April 2026 at 7:41 pm

This is a link post by Simon Willison, posted on 14th April 2026.

open-source 301 ai 1960 generative-ai 1740 llms 1707 drew-breunig 20 vibe-coding 83 ai-security-research 14

Monthly briefing

Sponsor me for $10/month and get a curated email digest of the month's most important LLM developments.

Pay me to send you less!

Sponsor & subscribe