Key Takeaways
- Anthropic's Claude Mythos Preview, announced 7 April 2026, found a 27-year-old denial-of-service bug in OpenBSD's TCP SACK implementation, present since 1998.
- Project Glasswing gave roughly 50 partner organisations, including AWS, Apple, Microsoft, Cisco, CrowdStrike, Google and the Linux Foundation, access to Mythos for defensive security work.
- Anthropic backed the programme with up to $100 million in usage credits plus $4 million for open-source security groups, then expanded it in June 2026 to roughly 150 more organisations across 15-plus countries.
- Across the programme, partners reported more than 10,000 high- or critical-severity vulnerabilities; Anthropic says verification, disclosure and patching became the limiting steps.
- Mythos remains unreleased because its vulnerability-finding power is also an offensive risk, so companies should harden systems now and start using tools like Claude for defensive code review.
On 7 April 2026, Anthropic announced it had been testing a new model called Claude Mythos Preview. Anthropic describes it as its most capable coding and agentic model to date; because access is gated, that claim cannot yet be compared through independent public evaluation.
Mythos has not been made publicly available. Instead, Anthropic launched Project Glasswing, a controlled initiative giving roughly 50 initial partner organisations access to Mythos for defensive security work. Partners include AWS, Apple, Microsoft, Cisco, CrowdStrike, Google, JPMorganChase, NVIDIA, Palo Alto Networks and the Linux Foundation.
Update, June 2026: Anthropic has since extended Project Glasswing to roughly 150 additional organisations across more than 15 countries, alongside the original partners. Mythos remains unreleased.
The gated release reflects a dual-use problem: the same capability can support defensive review or offensive exploitation. That makes the quality and limits of the published evidence more important than the superlative attached to the model.
What the Published Evidence Shows
The strongest public evidence concerns cybersecurity. It comes from Anthropic and participating organisations rather than an independent benchmark, but it includes named software projects, disclosed vulnerabilities and a published system card rather than only aggregate capability claims.
Across the programme, partners have found more than 10,000 high- or critical-severity vulnerabilities across major operating systems and web browsers. In one case, it uncovered a 27-year-old bug in OpenBSD — a denial-of-service flaw in the TCP SACK implementation, present since 1998. It sits in a security-focused operating system that human experts have scrutinised for nearly three decades.
Anthropic reports that, within Glasswing, the bottleneck moved from finding vulnerabilities to verifying, disclosing and patching them. That is a consequential operational signal, but it should not be generalised into a universal comparison with human security teams until independent evaluators can test the model across controlled workloads.
This is why Mythos has not been released publicly. The same capability that makes it a powerful defensive tool also makes it a serious offensive risk in the wrong hands. Anthropic committed $100 million in usage credits to Project Glasswing partners, plus a further $4 million to open-source security organisations. Anthropic is using the delay to study how to deploy the capability responsibly.
What Does This Mean for Security Teams?
Most organisations will not get direct access to Mythos in the near term. The practical value of Glasswing is therefore as an early signal about vulnerability-discovery volume, dual-use controls and the capacity required downstream to validate and patch findings.
1. Patch capacity may become the constraint
If comparable discovery capability becomes widely available, finding candidate flaws may become cheaper than triaging and remediating them. Organisations should measure patch latency and ownership now, rather than assume a larger stream of findings automatically improves security.
2. AI-assisted testing needs a verification pipeline
AI agents can run more continuously than periodic penetration tests, but candidate findings still need reproduction, severity assessment, responsible disclosure and remediation. The operating model around the scanner matters as much as the model generating the report.
3. Early access creates an operational learning advantage
Project Glasswing gives participants early experience of that operating model. Whether it produces lower incident rates or stronger compliance outcomes is not yet public, so those benefits should be measured rather than presumed.
4. Security results do not generalise automatically
Security results do not by themselves establish performance across general software engineering. They do, however, justify watching Anthropic's eventual system card, release conditions and independent coding evaluations before making procurement assumptions.
What Should You Do Now?
You do not need access to Mythos to act on what its existence tells us.
Invest in security fundamentals. AI-assisted vulnerability detection will find what has been missed. Organisations with strong patch management, dependency hygiene and infrastructure-as-code practices will respond faster when issues are identified.
Start using AI for defensive security today. Tools available now — including Claude — can review code for common vulnerabilities, analyse dependencies, and help teams think through attack surfaces. This is not a replacement for a security programme, but it is a real accelerant.
Watch the Project Glasswing outcomes. Anthropic has committed to publishing findings from this initiative. The vulnerabilities discovered in open-source software will be disclosed responsibly, and the lessons learned will shape how AI security tooling is designed and deployed going forward.
Think about trust as a competitive advantage. As AI-powered attacks become more capable, customers will increasingly choose vendors whose security posture they trust. Companies that move early on AI-assisted security will be better positioned to demonstrate that trust credibly.
The Bigger Picture
Mythos is useful evidence of a changing security workflow, not yet a product recommendation. Anthropic's controlled release acknowledges the dual-use risk; independent access and longitudinal outcomes will be needed to judge how well the controls and claimed capabilities hold up.
For security leaders, the immediate question is operational: if vulnerability discovery volume rises sharply, can the organisation verify, prioritise and patch findings without creating a new queue of unmanaged risk?
Frequently asked questions
What is Anthropic's Mythos model?
Mythos is a gated research-preview model that Anthropic began testing with security partners in April 2026. Anthropic reports particular strength in coding and vulnerability discovery, but the model has not been released for independent evaluation.
What is Project Glasswing?
A controlled initiative through which Anthropic gave roughly 50 initial partner organisations — including AWS, Apple, Microsoft, Cisco, CrowdStrike, Google and the Linux Foundation — access to Mythos for defensive security work, backed by up to $100 million in usage credits. In June 2026 it expanded to roughly 150 more organisations across 15-plus countries.
Why has Mythos not been released publicly?
Anthropic says the same capability that supports defensive vulnerability discovery also creates offensive risk. The gated programme allows selected partners to test the model while Anthropic studies deployment controls before any wider release.
What should companies do about it now?
You do not need access to Mythos to act. Invest in security fundamentals, begin using available AI such as Claude for defensive code review, watch the Project Glasswing disclosures, and treat security posture as a competitive advantage.
If this analysis is useful, the easiest way to get the next one is by email. Sign up for new-post updates.
← All posts