Is it just hype? AI-discovered bugs aren’t actually a treasure trove for crooks, research shows
Now, where’s that wave of cyberattacks?

Image by Cybernews.
- Only 1.3% of AI-discovered vulnerabilities have been confirmed exploited in the wild so far
- Exploitation rate for AI-found flaws roughly matches that of traditionally discovered vulnerabilities overall
- Researchers say AI vulnerability-hunting hype outpaces actual evidence, though risk remains real, not imaginary
AI giants, especially Anthropic, like to claim that the technology’s release into the wild needs to be rationed because attackers will easily weaponize AI-generated bugs. But new research suggests that’s simply not true, at least statistically speaking.
When Anthropic released Mythos in the spring, the firm limited access to it, saying that the model could dramatically turbocharge hacking.
The company warned at launch that Mythos had uncovered thousands of software vulnerabilities – including flaws across every major operating system and browser – and claimed that the fallout from its spread could be severe.
Already back then, human cybersecurity experts were musing that, actually, access to a Mythos-level large language model would not immediately enable hacking operations previously out of reach for bad actors.
For instance, Isaac Evans, founder and CEO of software security firm Semgrep, admitted that Mythos represented “a real technical advance “ but added that the panicked response to its release was “not substantiated by what we actually know about how those capabilities will translate in the field.”
Now, there’s finally some research, and it suggests that the doubters were right. Even if Mythos and similar models have uncovered thousands of vulnerabilities, they’re just as hard to exploit as flaws found by human specialists.
VulnCheck, a cyber threat intelligence platform that provides real-time vulnerability and exploit data, analyzed 1,061 AI-assisted vulnerability discoveries from Anthropic’s Project Glasswing and the Berkeley Vulnerability Research Initiative.
Researchers then cross-referenced the discoveries against its Known Exploited Vulnerability database.
VulnCheck’s vulnerability researcher Patrick Garrity wrote: “Is the rate at which vulnerabilities are being exploited faster? Are vulnerabilities being discovered with AI tools more dangerous? Or are we all feeding into the AI-assisted vulnerability discovery hype cycle?”
AI still appears to increase the volume of vulnerabilities that can be discovered, giving defenders an opportunity to identify and remediate them before attackers do.
The results were telling. Of 1,061 vulnerabilities attributed to AI-assisted discovery, only 14 (1.3%) have been confirmed as exploited in the wild, roughly matching the overall exploitation rate for all vulnerabilities in the first 6 months of the year.
VulnCheck also throws in a helpful, cold reminder that even though Anthropic has reported more than 23,000 “vulnerability candidates” through Project Glasswing, only 126 have resulted in published CVEs, and just one has been confirmed as exploited in the wild.
The conclusion is pretty clear, at least for now, Garrity says: “While AI-assisted vulnerability discovery clearly has value for both attackers and defenders, the data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods.”
Has your password leaked?
“The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today,” Garrity writes.
“That doesn’t mean the risk is imaginary. It means the impact has been real but modest.”
Of course, AI still appears to increase the volume of vulnerabilities that can be discovered, giving defenders an opportunity to identify and remediate them before attackers do.
Besides, the obvious caveat is that “only time will tell whether the rate of exploitation increases as frontier cyber models become more widely available,” VulnCheck says.