Invest2 publishersIndependently confirmed2 min readPublished
Anthropic lets a vetted group run offensive tests on grid and bank defences with Claude Mythos
Anthropic will let verified organisations run "high risk offensive testing" with Claude Mythos 5.1 and its other top models, alongside the US government. Access goes to a select group, so whoever draws up the vetting list now decides which defenders can use the company's strongest cyber model.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Bloomberg's account of the statement lists Claude Opus 5.5 and Claude Sonnet 5.5 alongside Mythos 5.1, and extends access to new models as they are released.
- The testing is aimed at the safety systems that protect critical infrastructure, with power grids, banks and flight operating systems given as examples.
- Crypto Briefing places the programme inside Project Glasswing, a coordination with the US government to find and fix cybersecurity vulnerabilities.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint Security teams outside the verified group cannot use these models for offensive testing, so the strongest defensive tool is open only to those who pass the vetting.
- precedent Because access covers models not yet released, the vetting list becomes the standing route for future Anthropic cyber releases, so a place on it is worth more than a single trial.
- decision Operators of grids, banks and flight systems that want their defences attacked by the strongest model now have to find a verified tester or go without.
- contradiction Crypto Briefing names the model as Claude Mythos 5 while Bloomberg's account says Mythos 5.1, leaving it unsettled which release the government coordination covers.
The operative word in Anthropic's statement is "verified" [2]. Crypto Briefing describes the approach as controlled access to the company's high-level models [6], and the testing runs in collaboration with the US government [1]. So the capability is handed out by approval.
The cap on numbers is deliberate. Crypto Briefing reports that only a limited number of organisations are being let in [4]. Whatever the programme earns, that cap means Anthropic is not booking the volume it would get from offering offensive testing to every security buyer who asked.
Crypto Briefing tied the move to valuation, writing that "market activity reflects an upward trend in expectations for Anthropic's valuation" [10]. That is a claim about expected price. Anthropic did not disclose how many organisations qualify or what they pay, so the cash the programme brings in cannot yet be estimated.
The first way this goes is that the list stays short and leans toward security vendors, the group Bloomberg's headline calls US cyber firms [5]. Those vendors then sell the testing on to the grid and bank operators who do the actual defending. In that case a place on the list is a licence to sell, and its value goes to the firms that hold one. A second path runs through the phrase "new models moving forward" [3]. If each release widens the roster, verification becomes a routine onboarding step and the scarcity fades. The third depends on rivals. Crypto Briefing names Z.ai's GLM-5.3 as competition [9], and if any comparable model offers the same offensive testing with no gate, the rationing holds back only the defenders who follow the rules.
I think the first path is the likeliest over the next few releases. Both gates in Bloomberg's account, verification [2] and collaboration with the US government [1], favour established American security firms with the paperwork to pass them. The case against that view is in the statement's own framing: this is an expansion of access [1], and a company that has widened the circle once can widen it again. The view would be wrong if Anthropic published criteria that grid and bank operators can meet directly, or a roster on which those operators outnumber the vendors.
What to watch
- A published roster or eligibility criteria for verified organisations, showing whether grid and bank operators qualify directly or only through security vendors.
- Whether Anthropic's next model release reaches outside testers through the same verified channel, as the statement's "new models moving forward" language implies.
- Any disclosure of access fees or contract terms for Glasswing participants, the figure needed to size what the programme earns.