
Anthropic's Mythos found a 30-year flaw in OpenBSD. Indian banks and fintechs face machine-speed exploitation risk as regulators form task forces and fintechs seek early access.
Alpha Score of 43 reflects weak overall profile with moderate momentum, weak value, weak quality. Based on 3 of 4 signals — score is capped at 90 until remaining data ingests.
Anthropic's Mythos AI system can autonomously discover and exploit software vulnerabilities at machine speed. For India's deeply interconnected digital financial infrastructure, that capability compresses the timeline between a flaw's discovery and its weaponisation from months to minutes. The country's banks and fintech startups are now racing to adapt defences built for a human-paced threat environment.
Matters
Mythos is not a theoretical model. In controlled testing, it identified a vulnerability inside the OpenBSD operating system that human researchers had missed for nearly three decades. OpenBSD is widely considered one of the most secure operating systems in existence. The implication for financial software stacks is direct: any codebase, no matter how rigorously audited, may contain latent flaws that Mythos-class systems can find and exploit faster than any human team can patch.
Ashok Vaswani, managing director and CEO of Kotak Mahindra Bank, described the shift plainly during the bank's Q4 FY26 earnings call. "The nature of cybersecurity threats was shifting from human-speed attacks to machine-speed attacks," he said. "We will step up efforts to identify any kind of vulnerabilities that we have and fix those vulnerabilities as quickly as possible."
Jaishiv Prakash, director analyst at Gartner, framed the challenge in operational terms. Many banks have mature cyber governance, he noted. They still depend on manual triage, fragmented asset visibility, slow vendor coordination, and legacy technology estates. "Mythos-class systems will punish those weaknesses because they move the contest from human-paced security operations to machine-speed exposure discovery and exploitation."
Over the past decade, India has built one of the world's most expansive digital public infrastructure stacks. Real-time payments through UPI, Aadhaar-linked verification, API-driven banking integrations, and cloud-native financial platforms have created an ecosystem that operates at enormous scale and speed. That same interconnectedness is the vulnerability.
A tool like Mythos does not need to breach a bank's core system directly. It can find a weakness in a third-party payment gateway, a lending API, or an open-source component shared across dozens of platforms. From that entry point, lateral movement into larger financial networks becomes feasible. The entire ecosystem is only as strong as its weakest node.
The OpenBSD find is a concrete benchmark. If a system renowned for security can harbour a flaw for three decades, the probability that commercial banking software contains similar latent vulnerabilities is high. Mythos-class systems can scan codebases at a speed impossible for human teams.
Traditional patch management cycles run on weeks or months. A vulnerability discovered by a human researcher is reported, verified, patched, and deployed over that timeline. Mythos can identify the same flaw and produce an exploit in hours. The window for defence shrinks to near zero.
India's largest banks treat cybersecurity as a board-level issue, according to Gartner's Prakash. Awareness does not equal readiness. Legacy technology estates, fragmented asset inventories, and slow vendor coordination remain common. Axis Bank's chief information security officer Vinay Tiwari described Mythos as a "capability amplifier" that could strengthen systems if used defensively. He warned that evolving risks may surface vulnerabilities in highly interconnected environments, particularly where there is significant reliance on shared software platforms, third‑party providers, or open‑source components without adequate oversight.
Paytm, Razorpay, and Pine Labs are among the fintech players that have reportedly reached out to Anthropic to test Mythos against their own systems. Vijay Shekhar Sharma, Paytm's founder and CEO, told a publication last month: "We had an urgent call with Anthropic to check when they're creating a second list of companies that will get access to Mythos."
Fintech startups operate with lean engineering teams and limited cybersecurity budgets. They are under profitability pressure and rising compliance costs. A dedicated AI-defence capability is expensive. These same startups are deeply integrated into the banking ecosystem through payment gateways, lending APIs, account aggregators, and embedded finance. A breach at a fintech can become a pathway into a bank.
Finance Minister Nirmala Sitharaman called top banks for a high-level security meeting last month, shortly after Mythos's controlled release. She warned of "unprecedented" cybersecurity risks and constituted a panel to assess allied risks. The panel is headed by SBI chairman CS Shetty, who also leads the industry body Indian Banks' Association.
The government is now pushing for faster threat-intelligence sharing between banks, regulators, and cybersecurity agencies like CERT-In. The goal is to reduce the detection-to-response lag that machine-speed attacks exploit.
The most direct countermeasure is to deploy defensive AI systems that can match Mythos's speed. Fintechs like Paytm, Razorpay, and Pine Labs are seeking early access to Mythos precisely to run vulnerability scans before attackers do. Proactive testing, combined with real-time threat-intelligence sharing across the banking network, can compress the window of exposure.
Vinay Tiwari of Axis Bank noted that Mythos could be used as a defensive capability amplifier. The gap between organisations that treat resilience as an ongoing capability and those that rely on periodic checks will widen over time.
Several factors could amplify the threat:
The global frontier AI race is increasingly a battle to secure digital systems before those same systems learn how to break them. India's financial infrastructure, built for scale and speed, is now being tested by a threat that moves at the same velocity. The question is not whether a breach will occur, whether the ecosystem can detect and contain it before it cascades.
For broader context on how risk events affect Indian equities, see AlphaScala's stock market analysis.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.