Finding Miscompiles for Fun, Not Profit - by Justin Lebar
newsletter.semianalysis.com · 1,725 words · saved by 1 readers
Or: You don’t need access to Claude Mythos to spend $10,000 in an afternoon.
Finding Miscompiles for Fun, Not Profit Or: You don’t need access to Claude Mythos to spend $10,000 in an afternoon. Justin Lebar May 28, 2026 ∙ Paid 214 8 Share Update June 1: The day after we published, Anthropic released Opus 4.8 and “ultracode” mode in Claude Code. Our preliminary experiments indicate that together these are significantly better at filtering out low-severity bugs, and that the cost per medium-to-high severity bug found is maybe 1/5 (with very large error bars) that of the workflow described in this article. I’ve worked on compilers for ML for the last decade across Google,
saved by
related reading
- Mythos finds a curl vulnerability | daniel.haxx.sedaniel.haxx.se
- Vulnerability Research Is Cooked - Quarrelsomesockpuppet.org
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Earn $200K by fuzzing for a weekend: Part 1 | secret clubsecret.club
- Rewriting Bun in Rust | Bun Blogbun.com
- The LLVM Compiler Infrastructure Projectllvm.org
- How Compiler Explorer Works in 2025 — Matt Godbolt’s blogxania.org
- Composer2.pdfcursor.com
- A friendly introduction to machine learning compilers and optimizershuyenchip.com
- Building a C compiler with a team of parallel Claudes \ Anthropicanthropic.com
- From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code - Project Zerogoogleprojectzero.blogspot.com
- Using LLM-based Verification to Eliminate Bugs in Linux's Network Stackbasis.ai