Claude Mythos has created quite a buzz with its cybersecurity concerns, but a prominent cybersecurity expert has said that those risks might be overblown. George Hotz — the hacker who famously jailbroke the iPhone and PlayStation 3, and now serves as President of autonomous driving startup comma.ai — took to LinkedIn to challenge the safety narrative being pushed by the two biggest names in frontier AI. His provocation was blunt: “What if I release one zero day a day until a big new model is released? Will this finally make OpenAI and Anthropic shut up about ‘cybersecurity risk’?” The Argument: It’s Not Hard, It’s Not Incentivized Hotz’s core claim is that software vulnerabilities are far easier to find than AI labs would have the public believe — and that the scarcity of zero-days in the wild is a function of legality, not difficulty. “The reason there aren’t zero days everywhere is cause nobody seriously looks,” he wrote. “Because hacking other people’s shit with them is illegal and criminals are usually not very skilled, or they would choose a different line of work.” His prescription is direct: “Want more zero days to be found? Make hacking legal. Until then, don’t try to claim it’s hard, it’s just not incentivized.” He also took a swipe at the economics of AI-assisted vulnerability research. Reports had surfaced that finding exploits via AI was costing around $20,000 in token usage — a figure Hotz dismissed outright, saying he’d do it for less if not for bug bounty restrictions. Context: The Claude Mythos Rollout Hotz’s post lands in the middle of a charged moment for Anthropic. The company recently unveiled Claude Mythos, its most capable model to date — one it declined to release to the general public, citing its unprecedented ability to identify and exploit