27-05-2026 | Ethical Hackers Warn AI Tools Threaten Their Profession

0 3 min read

Ethical Hackers Grapple with AI’s Rise

In recent weeks, the cybersecurity community has watched as artificial‑intelligence models grow from helpful assistants to potential competitors. At the 2026 Pwn2Own competition in Berlin, champion hacker Valentina "Chompie" Palmiotti—winner of the most lucrative prizes last year—urged fellow hackers to brace for a future where AI like Anthropic’s Claude Mythos could replace the human advantage that has long driven bug‑bounty payouts.

Chompie explained that AI tools have already accelerated her research; she used Claude Code to parse large code bases in minutes, allowing her to secure the $20,000 prize for a Nvidia‑linked system and later a $50,000 win on a Linux platform in rapid succession. Yet she warned that the next generation—Claude Mythos and GPT‑5.5 Cyber—are "strikingly capable" at finding vulnerabilities, citing the model’s record of 1,600 bugs across hundreds of programs. According to Anthropic, Mythos’ findings include "high‑or critical‑severity" flaws that have forced major tech firms to patch critical infrastructure before malicious actors can exploit them.

These developments have reverberated beyond the competition floor. In Ottawa, AI Minister Evan Solomon announced that Canada has joined Project Glasswing, Anthropic’s initiative to give select governments and "top tech companies" early access to Mythos. The program now covers 150 organizations in more than 15 countries, spreading across industries such as healthcare, power, and communications. Solomon reiterated that allowing only "trusted" groups to use the model protects national security, a stance mirrored by the EU and U.S. agencies that have already deployed Mythos preview versions.

Despite the promise of faster discovery, experts argue that the AI tide may tilt the talent balance in cybersecurity. While some, like Orange Tsai, another Pwn2Own victor, see AI as an accelerator that frees human hands, others predict that "lower‑hanging fruit" will dry out, leaving only the best‑qualified attackers with meaningful opportunities. The same breakthrough that aids defenders could also streamline criminal operations if malicious actors gain illicit access to the technology.

Chompie maintains that, in the long run, AI could actually harden online defenses. "If the good guys have the most powerful tools first, we can find and fix holes before the bad guys," she said. "But we need responsible release paths and policy frameworks—otherwise we risk an arms race that leaves ordinary users exposed." Her plea comes at a time when governments worldwide are drafting AI‑specific privacy and cybersecurity legislation, including Canada’s upcoming new AI strategy focused on trust, workforce empowerment, and sovereign compute.

As AI matures, ethical hackers will likely need to pivot from pure vulnerability hunting toward hybrid roles that combine human intuition with machine‑learning insights. Those who adapt may still earn top‑tier bug‑bounty payouts, while newcomers may find their entry point more challenging. The paradigm shift raises critical questions about how we train the next generation of security researchers and how public policy can keep pace with technological evolution.

Loading comments…