Security1 publisher2 min readPublished
Anthropic hands an unreleased bug-finding model to more than 50 organisations
Project Glasswing gives twelve launch partners and more than forty critical-infrastructure maintainers access to Claude Mythos Preview, which Anthropic says has already found thousands of high-severity vulnerabilities.
The Watch · Security desk

What happened
- Anthropic announced Project Glasswing on April 7, 2026 alongside eleven other organisations, among them AWS, Apple, Google, Microsoft, Cisco, CrowdStrike, JPMorganChase, NVIDIA and the Linux Foundation.
- At the centre of it is Claude Mythos Preview, an unreleased general-purpose model that Anthropic says can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.
- Anthropic says the model has already found thousands of high-severity vulnerabilities, including some in every major operating system and every major web browser.
- Access goes beyond the launch partners to more than forty additional organisations that build or maintain critical software infrastructure, for scanning first-party and open-source code.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Discovery stops being the bottleneck and vendor triage and maintainer hours become it, with $4M of donations standing behind the open-source end of that queue.
- exposure More than fifty organisations now hold working access to a model its own maker describes as writing exploits, which makes the coalition itself the first proliferation surface to worry about.
- decision Operators outside the coalition get no CVE, no indicator and no deadline out of this, so the only thing to plan against is heavier future patch volume.
- precedent Gating an offensive-capable frontier model behind a named consortium and a donation pool sets the template the next lab will be measured against.
Thousands of high-severity findings across every major operating system and browser have to land somewhere, and where they land is a vendor triage queue [3]. The announcement attaches no CVE identifiers and no disclosure dates to any of them [16]. The count itself is the claim, asserting capability rather than identifying a bug outsiders can patch this week.
Up to $100M in Mythos Preview usage credits [7], spread across the twelve launch partners and the forty-plus additional organisations [13], works out at roughly $1.9M of inference each [14]. The direct cash to open-source security organisations is $4M, four percent of the credit line [8][15]. The Linux Foundation is a launch partner [1], and open-source maintainers are the people who will receive the reports the model generates against their code [6]. Credits cover the scanning; the maintainer hours the resulting reports consume are a separate cost.
Everything known about Mythos Preview comes from Anthropic's own account; the model itself remains unreleased [2]. The company says some flaws it found had survived decades of human review and millions of automated security tests, and that the exploits it writes are increasingly sophisticated [4]. The vulnerability count arrives without a benchmark figure or an outside evaluation [19]. Eleven other organisations agreeing to use the model in their own defensive work [5] establishes only that they want the access, a distinct question from whether the capability is confirmed.
The reframing Anthropic argues for is a timing argument. Its position is that defending the world's cyber infrastructure might take years while frontier capability advances substantially over the next few months [10], and that it will not be long before comparable capabilities reach actors not committed to deploying them safely [9]; the announcement names China, Iran, North Korea and Russia among state-sponsored threats [18]. Glasswing's response is to widen access early, which is why the opening move is distribution to more than fifty organisations rather than a controlled internal audit [13]. Whether the defenders' copy lands before an equivalent model is trained elsewhere is the entire bet, and that gap remains unmeasured in anything published so far.
The $500B annual cybercrime figure Anthropic cites carries its own hedge in the same sentence [11], and the ten-years-after-DARPA framing is the company's own [12]. What touches operational planning is duller than either: if these finds are real and go out through normal coordinated channels, monthly operating system and browser bulletins get heavier before they get lighter, and the work that absorbs the increase is regression testing on the receiving end.
What to watch
- Whether any of the thousands of findings surface as CVEs crediting Mythos Preview, which is the first chance outsiders get to check the capability claim.
- Whether Anthropic publishes an evaluation of Mythos Preview's discovery rate rather than a count of findings.
- Whether the 40-plus additional organisations are named, and what the access terms are for a model described as writing working exploits.