# ShipHero CEO Aaron Rubin Says Claude Mythos Beat His Pentest Firm for $10K

> Source: <https://startupfortune.com/shiphero-ceo-aaron-rubin-says-claude-mythos-beat-his-pentest-firm-for-10k/>
> Published: 2026-08-23 11:20:32+00:00

*Anthropic's Claude Mythos is not a normal code scanner. It is a controlled security model that changes what you should expect from a serious vulnerability review.*

The easy mistake is to treat Claude Mythos as another AI coding feature with sharper teeth. It isn't. Anthropic built it to find and reproduce software vulnerabilities, then kept access behind Project Glasswing because the same capability that helps defenders can also help attackers move faster.

That is the useful story. If you run a software company, the question isn't whether AI will replace every penetration tester next quarter. It is whether your current security budget still makes sense when frontier models can search large codebases overnight and produce findings a human team has to validate the next morning.

ShipHero shows why this matters for companies outside the security industry. Aaron Rubin is the founder and chief executive of ShipHero, a warehouse management software company whose own site says its platform powers more than $15 billion in annual GMV and handles one in every 80 U.S. ecommerce packages shipped through its WMS. The company also raised $50 million from Riverwood Capital in 2021, according to ShipHero's funding announcement. That's not a garage project. It is the kind of operational software business where a missed access control bug or bad API assumption can become a real customer problem very quickly.

## What Mythos Actually Does

Anthropic announced Claude Mythos Preview on April 7, 2026, as part of Project Glasswing. According to Anthropic's own research post, Mythos found a 27-year-old bug in OpenBSD's TCP SACK handling, a 16-year-old flaw in FFmpeg, and exploit paths in the Linux kernel during its testing. The company said Mythos also turned Firefox 147 JavaScript engine flaws into working shell exploits 181 times in a benchmark where Claude Opus 4.6 managed two.

[Harvey Built Its Own Legal AI Model Instead of Renting One From OpenAI](https://startupfortune.com/harvey-built-its-own-legal-ai-model-instead-of-renting-one-from-openai/)

Harvey, the legal AI startup valued near $15.5 billion, has launched Tenet, its first proprietary model, built on a customized Kimi K3 base and post-trained on attorney-generated case files. The model ships inside a broader Harvey II relaunch that also introduces a Memory feature for law firms. - [why legal AI startups build their own models](https://startupfortune.com/harvey-built-its-own-legal-ai-model-instead-of-renting-one-from-openai/) - [how law firms fine-tune AI with case files](https://startupfortune.com/harvey-built-its-own-legal-ai-model-instead-of-renting-one-from-openai/)

Those numbers should make you pause. They don't prove the model is magic, and they don't mean every output is ready to ship as a bug report. They do prove that the old line between automated scanning and expert vulnerability research is getting thinner.

Anthropic has not made Mythos a public free-for-all. Project Glasswing started with launch partners including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks, then extended access to more than 40 additional organizations that build or maintain critical software. Anthropic also committed up to $100 million in usage credits and $4 million in donations to open-source security groups.

That controlled rollout is the point. A model that can find subtle memory corruption bugs in old infrastructure code can help maintainers patch problems before attackers find them. The same model, in the wrong hands, can compress the time between bug discovery and working exploit. You don't need to dramatize that. The risk is plain enough.

## The Price Pressure Comes Next

The harder question for founders is not whether Mythos is impressive. It is what happens to the economics of security testing when a model can do a first pass across a large codebase at machine speed. Traditional penetration testing still has a role, especially for business logic, permissions, authentication flows and the messy places where software meets real users. A good human tester notices things a model may not understand because the flaw is in the workflow, not the syntax.

But a founder should be blunt about the trade. If you are paying five figures for a scheduled engagement that takes weeks to start, and a frontier model can surface credible leads in hours, your security process has to change. The best answer is not to fire the red team. It is to make the red team better armed.

Frankly, the weak version of this story is the one where AI is sold as a cheap replacement for judgment. Don't buy that. A pile of automated findings is only useful if someone can separate real vulnerabilities from noise, decide severity, reproduce the bug, patch it, and check that the fix did not break something else.

For companies like ShipHero, the real pressure is operational. Warehouses, brands and third-party logistics operators depend on software to move orders through picking, packing and shipping. If that software leaks data or lets one customer see another customer's workflows, the damage is not theoretical. It lands in support queues and contracts - and it costs trust that's hard to win back.

[Etched's AI chip valuation doubles to $21 billion in a single month](https://startupfortune.com/etcheds-ai-chip-valuation-doubles-to-21-billion-in-a-single-month/)

AI chip startup Etched raised $700 million at a $21 billion valuation, double what it was worth a month earlier, after Jane Street tested and bought its transformer-only Sohu inference hardware. The jump caps an eight-month run from a $5 billion valuation in December to $21 billion in August. - [AI chip startup valuation doubles in one month](https://startupfortune.com/etcheds-ai-chip-valuation-doubles-to-21-billion-in-a-single-month/) - [Etched's transformer-only chip attracts Jane Street investment](https://startupfortune.com/etcheds-ai-chip-valuation-doubles-to-21-billion-in-a-single-month/)

Mythos makes one thing clear: vulnerability hunting is becoming faster, cheaper and more uneven. The companies that benefit will be the ones that treat AI as part of a serious security loop, not as a receipt they can wave around after one dramatic scan.

**Also read:** [OpenAI's AI Models Broke Out and Hacked Hugging Face, So It Built Daybreak](https://startupfortune.com/openais-ai-models-broke-out-and-hacked-hugging-face-so-it-built-daybreak/), [Vertiv stock loses $12 billion in a week as bond yields rattle AI bets](https://startupfortune.com/vertiv-stock-loses-12-billion-in-a-week-as-bond-yields-rattle-ai-bets/), and [Alibaba Seeks $10 Billion Hong Kong Share Sale to Fund Its AI Spending Spree](https://startupfortune.com/alibaba-seeks-10-billion-hong-kong-share-sale-to-fund-its-ai-spending-spree/)
