Anthropic launched Project Glasswing with AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks to use the unreleased Claude Mythos Preview for defensive security work, extending access to over 40 more organizations that maintain critical software. Anthropic committed up to $100M in usage credits and $4M in donations to open-source security groups, and reports Mythos Preview found thousands of high-severity vulnerabilities, including in every major operating system and browser.
It is a large, restricted-access defensive deployment of a model its developer does not plan to make generally available, pending safeguards for Mythos-class models.
Key facts
As stated in the sources, with where to find them.
- Anthropic commits up to $100M in Mythos Preview usage credits and $4M in direct donations to open-source security organizations.Introduction
- Examples of findings patched by the time of the announcement: a 27-year-old remote crash bug in OpenBSD, a 16-year-old FFmpeg flaw in a line automated tools had hit five million times, and chained Linux kernel privilege escalation.Section 'Identifying vulnerabilities and exploits with Claude Mythos Preview'
- CyberGym vulnerability reproduction: Mythos Preview 83.1% vs Claude Opus 4.6 66.6%.Same section, benchmark table
- For many unpatched findings, Anthropic published cryptographic hashes of details to reveal after fixes.Same section
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.