Source: Anthropic, anthropic.com/glasswing, April 2026
Project Glasswing is a defensive cybersecurity initiative announced by Anthropic in April 2026 that uses Claude Mythos Preview to find and patch zero-day vulnerabilities in critical software. Anthropic framed the announcement around its assessment that Mythos's cybersecurity capabilities had "crossed a threshold" — that AI models can now "surpass all but the most skilled humans at finding and exploiting software vulnerabilities."
The initiative and partners
The initiative brought together 12 founding partners — AWS, Apple, Broadcom, Cisco, Cloudflare, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks — plus more than 40 additional organizations. Anthropic committed up to $100M in usage credits and $4M in direct donations to open-source security organizations. The consortium spans private companies, open-source maintainers, and critical infrastructure operators.
Cloudflare published a partner-side technical write-up on May 17, 2026, the most detailed external review of Mythos Preview's capability and limitations, covered at Project Glasswing — What Mythos Showed Us (Cloudflare engineering blog, May 17 2026). It documents exploit-chain construction, on-the-fly proof generation, inconsistent organic refusals, and a four-lesson harness architecture, and is the principal partner-side companion to the Anthropic announcement.
On May 18, 2026, Anthropic revised the Glasswing rules to allow partners — including Amazon, Microsoft, Nvidia, and Apple — to share Mythos cybersecurity findings with outside security teams, industry bodies, regulators, government agencies, open-source maintainers, and the public, subject to responsible-disclosure norms. Anthropic described the change as the program having "matured" enough that information should be "shared broadly… for maximum defensive impact." (Source: reuters.com)
Documented vulnerabilities and benchmarks
The announcement documents three examples of what Mythos Preview can do, all stated to be publicly confirmed as patched:
- A 27-year-old OpenBSD vulnerability in a hardened OS used for firewalls and critical infrastructure. It allowed an attacker to remotely crash any machine by connecting to it, and had survived decades of human review.
- A 16-year-old FFmpeg vulnerability in a video codec used by many software applications. The vulnerable line had been hit by automated testing tools 5 million times without detection.
- A Linux kernel privilege-escalation chain, in which Mythos found and chained multiple vulnerabilities autonomously to escalate from ordinary user access to complete machine control.
On the CyberGym evaluation (Cybersecurity Vulnerability Reproduction), Mythos Preview scored 83.1%, against Claude Opus 4.6 at 66.6%, a 16.5 percentage-point gap.
Access and deployment decisions
Anthropic stated its reasoning for restricting the model: "given the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely. The fallout—for economies, public safety, and national security—could be severe." The decision to restrict Mythos reflects the logic of Anthropic's responsible scaling policy (RSP), under which ASL-level thresholds require enhanced safeguards before deployment. Logan Graham, of Anthropic's Frontier Red Team, described the model as "the starting point for what we think will be an industry change point, or reckoning, with what needs to happen now."
Access is not open, but it is broader than purely government-controlled. Anthropic's stated judgment is that private companies controlling critical software infrastructure are better positioned than the government for immediate defensive work, particularly while the Anthropic–Department of War conflict over a supply-chain-risk designation remains unresolved. (Source: Clawed) (Source: washingtonpost.com)
Bruce Schneier's external assessment is that AI is better at finding vulnerabilities than patching them, "because patching often requires more holistic testing and understanding," meaning a well-resourced defensive consortium may not fully offset AI's advantage for attackers. Anthropic has acknowledged this, describing Project Glasswing as "a starting point" that may take years. (Source: washingtonpost.com)
Coordinated-swarm comparison
Anthropic's Frontier Red Team used the program's scanning method as the baseline in an August 2026 experiment testing whether coordination between agents improves on it (Patterns and problems in emerging multiagent systems). The program's approach is described there as pointing individual agents at individual codebases, files, or modules and running them in parallel. Against that baseline, 45 coordinating agents sharing a forum and submitting to an arbiter agent found 266 vulnerabilities over 27 million tokens across 15 open-source projects on Mythos Preview, against 21 over 6.5 million tokens for the independent agents — but roughly half the swarm's findings lay outside the directories the independent agents were assigned, the two methods were comparable on tokens per vulnerability within those directories, and the two sets overlapped on only 12 vulnerabilities. The report characterizes the methods as "largely complementary" rather than one superseding the other.
Geopolitical context
A brief by Caleb Withers (CNAS) frames Project Glasswing as a shift in AI power dynamics: nation-states previously assumed they would broadly access frontier models, but with Mythos restricted to private consortium partners, "that assumption has appeared on shakier ground," leaving select private companies and potentially allied governments in control of the most capable cyber AI tools. (Source: washingtonpost.com) Dmitri Alperovitch (Silverado Policy Accelerator) commented: "This just underscores why it's so vital that we win the AI race so we're continuously ahead of China... if China had a model like this, they would not be using it for defensive purposes."
Relationships
- related: Claude Mythos Preview — Project Glasswing is the primary deployment context for Mythos; benchmark data documented here
- instance-of: Cyber Risk Frameworks — Glasswing as a real-world implementation of frontier-lab cyber frameworks
- related: Autonomous Weapons / Clawed — the Anthropic–Department of War conflict, in which the US government lacks access to Mythos while having designated Anthropic a supply-chain risk
- related: AI Safety Frameworks
- related: Export Controls
- related: Anthropic — $100M commitment and broader policy positioning