Anthropic says Claude Mythos Preview has been used to find more than 10,000 high- or critical-severity vulnerabilities since the launch of Project Glasswing
Last month, we launched Project Glasswing, our collaborative effort to secure the world's most critical software before increasingly capable AI models can be turned against it.
Anthropic
Context & Ripple Effects
Project Glasswing was introduced as a collaborative effort to use Claude Mythos Preview to identify and remediate flaws in critical software, with access initially limited to more than 40 organizations maintaining that software.
The latest reported tally extends Anthropic’s earlier claim that the general-purpose model could uncover severe issues across major operating systems and browsers, turning a benchmark-and-demonstration narrative into an operational security program.
First-order effects
Organizations participating in Project Glasswing now have a substantially larger identified backlog of high- and critical-severity vulnerabilities to validate, prioritize, and patch.
Anthropic gains concrete deployment evidence for Mythos Preview’s use in vulnerability discovery, while retaining a restricted-distribution model rather than making the system generally available.
Second-order effects
Maintainers of widely used software may face increased remediation and disclosure workload as AI-assisted discovery raises the volume of actionable findings.
Other AI vendors and security-tool providers are pressured to demonstrate not only coding benchmarks but reliable, coordinated vulnerability-finding workflows for critical software owners.
Third-order effects
If AI systems consistently expand defensive discovery faster than maintainers can resolve findings, software security will shift toward continuous AI-assisted auditing paired with stronger triage and patch-management capacity.
Restricted access to highly capable cyber models may become a more common deployment pattern as providers balance defensive use cases against the risk that the same capabilities could aid attackers.
The trend: This is one data point in the move from general-purpose coding models being evaluated on benchmarks to being selectively deployed as infrastructure-security tools under controlled access.
Last month we launched Project Glasswing, our collaborative AI cybersecurity initiative. Since then, we and our partners have found more than ten thousand high- or critical-severity vulnerabilities in essential software.
The compute story is cope. The gatekeeping story is cope. Mythos is genuinely much stronger than anything we've seen so far, and if Anthropic simply let it loose instead of starting Project Glasswing there would be millions-billions of dollars in damages.
Here's a key line in this mythos update. This is precisely an example of why engineers don't go away, ever. We've made it far easier to create and find security issues, which means the new bottleneck is our ability to actually review, respond to, and fix the issues. Far from [ima…
Patching these vulnerabilities will make us safer. But the software industry will need to adapt to the volume of vulnerabilities that models like Claude Mythos Preview will be able to find. We discuss this in our initial update on Project Glasswing: https://www.anthropic.com/...
An update on Project Glasswing, as well as some recent evaluation results on Mythos Preview. One of the capabilities my team has been interested in since our initial testing is exploitation. This is an area where we believe Mythos Preview has been a real leap over previous mode…
I don't understand how people are still coping about Mythos. Here's a few benchmarks: SWE-bench Pro: Mythos -> 77.8%, GPT-5.5 -> 58.6% HLE: Mythos -> 56.8%, GPT-5.5 -> 41.4% UK AISI cyber ranges: - “The Last Ones”: Mythos -> 6/10, GPT-5.5 3/10 - “Cooling Tower”: Mythos -> [image]
Anthropic isn't releasing Mythos. The Official reason is that it's too dangerous and could be used to exploit zero-days at scale. Honest poll: how many of you think that if Anthropic had the compute to serve Mythos to everyone, they would still be holding it back? Quite the
Glasswing update: they used mythos to find 10k+ high or critical severity vulnerabilities, cloudflare has found the false positive rate to be better than human testers, and they've used mythos to scan 1k+ OSS projects, finding 6k+ bugs with high or crit severity, and 23k total). …
Anthropic published the first results from the Project Glasswing today. — Participating software companies have been releasing multiple times as many patches as usual. …
What would you count as intelligent? Most recently, it reasoned for 250 pages and proved an important open math result, and found thousands of critical security vulnerabilities in important software. Surely that's at least intelligence within those domains? — www.anthropic.co…