Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
GPT-5.5: Mythos-Like Hacking, Open to All (xbow.com)
55 points by rs_rs_rs_rs_rs 12 hours ago | hide | past | favorite | 13 comments
 help



They say its mythos like, without actually comparing it to Mythos (fair enough, it's not public) but the bar for a model to be mythos-like has to be that you can produce as many novel and high severity security vulns outlined in the Mythos redteam blog. I haven't seen any other lab produce a report like that yet. The proof is in the pudding.

First you need to get through the safety net. I’ve had many productive gpt5.4 sessions hit a roadblock of “ethicality” and pollute the context with multiple rounds of trying to convince it to continue

These plots are terrible. Why is categorical data connected across categories with lines? Why not just use bar plots?

Like in the "Web Vulns in OSS" plot, white box data for Opus 4.7 is not available, but the absurd linear interpolation across categories implies it should be near 60.


It's just an ad thinly disguised as useful data.

I think the x axis is meant to be time but they screwed it up.

why does this read like an openai ad?

> GPT-5.5 doesn’t just improve — it pulls away

I think it's also self-aggrandizing.


Wasn't it already confirmed that small open-weight models were able to detect most of the same headline vulns as mythos? How is this any different?

No, they are able to detect errors when pointed at them but they have a lot of false positives... making them functionally useless for a large unknown codebase. They also can't build and run an exploit post-identification. Mythos can find vulnerabilities (purportedly) and actually validate them by building and running exploits. This makes it functional and usable for hacking.

i casually asked gemini and codex 200usd subs to find and verify bugs for weeks. it did wrote tests, injected mutations, verified fixes. just promts.

also i had to proxy remote mainnet with localhost to force them to do penetration and dos testing.

mythos is nothing new.


Do you have a source for this? Not doubting it, but I would like to have something concrete the next time the Mythos horse manure is cited.


Discussion:

https://news.ycombinator.com/item?id=47732020

“Small models also found the vulnerabilities that Mythos found” (aisle.com)

1,283 points | 12 days ago | 360 comments




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: