Anthropic

Project Glasswing: Anthropic's Mythos Hunts Zero-Days

On April 7, 2026, Anthropic launched Project Glasswing with partners incl. AWS, Apple and Microsoft, using the unreleased Mythos Preview model to hunt zero-day bugs at scale.

Project Glasswing: Anthropic's Mythos Hunts Zero-Days — article cover
On this page6 SECTIONS
  1. Mythos Preview: A Model That Hunts Its Own Bugs
  2. Twelve Founding Partners and $100 Million in Credits
  3. What It Has Already Found
  4. Why It Stays Behind Glass
  5. What It Means for Security and Dev Teams
  6. Sources

On April 7, 2026, Anthropic announced Project Glasswing, with a mission statement that needs no translation: secure the world’s most critical software for the AI era. The founding partner list is one of the most remarkable rosters in recent AI news — AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks — plus access extended to more than 40 additional organizations that build or maintain critical software infrastructure.

But the alliance is not the real story. The story is the key it hands out: Claude Mythos Preview, a frontier model that has never been publicly released. Anthropic’s own description of its capability is unusually blunt — at finding and exploiting software vulnerabilities, the model “can surpass all but the most skilled humans.” When offensive capability crosses that line, defense stops being a single company’s problem.

Mythos Preview: A Model That Hunts Its Own Bugs

Glasswing works by pointing the model at the defensive side of the ledger: local vulnerability detection, black-box testing of binaries, endpoint security, and penetration testing across partner environments. The numbers back the positioning — on the CyberGym security evaluation, Mythos Preview scored 83.1%, against 66.6% for the previous-generation Opus 4.6. TechCrunch’s April 7 coverage called it Anthropic’s most ambitious cybersecurity initiative to date.

Even the name is a metaphor. The glasswing butterfly (Greta oto) has transparent wings — the bugs were hiding in plain sight all along, and transparency itself is a form of defense.

Twelve Founding Partners and $100 Million in Credits

This is not a memorandum-grade coalition. Anthropic put real money on the table: up to $100 million in Mythos Preview usage credits, plus $4 million in open-source security donations — $2.5 million to Alpha-Omega/OpenSSF and $1.5 million to the Apache Software Foundation. Fortune’s report highlighted the oddity at the center of the roster: Apple, CrowdStrike, and Google, companies that compete fiercely on most days, appear on the same defensive list.

The commercial model was announced alongside: after the preview period, pricing lands at $25 per million input tokens and $125 per million output tokens, served through the Claude API, Amazon Bedrock, Vertex AI, and Microsoft Foundry. Security capability, in other words, will be distributed through the standard enterprise cloud channels.

What It Has Already Found

Before the announcement, Mythos Preview had already produced receipts: thousands of zero-day vulnerabilities, including some in every major operating system and web browser. Three examples convey the scale. A 27-year-old remote-crash bug in OpenBSD. A 16-year-old flaw in FFmpeg that automated tests had hit five million times without ever detecting. And a Linux kernel exploit chain that escalates from user access to full machine control.

Anthropic committed to publishing a report within 90 days covering lessons learned and vulnerabilities fixed, followed by best-practice recommendations spanning disclosure, patching automation, and supply-chain security.

Why It Stays Behind Glass

Mythos Preview will not be available to general users. The reasoning is straightforward: capabilities like this will eventually proliferate to actors unwilling to deploy them safely, and cybercrime already costs roughly $500 billion a year. Guardrails that block the model’s most dangerous outputs are planned to debut with a future Opus-class model.

The medium-term plan is to hand coordination to an independent third-party body, so public-private defense collaboration does not depend on any single model company. That is a direct answer to the obvious concern about a lab acting as both referee and player.

What It Means for Security and Dev Teams

Three practical consequences. First, defenders have a time-labeled window of advantage: aim the same caliber of bug-hunting at your own estate before adversaries acquire the equivalent. Second, the bottleneck moves from discovery to remediation — when flaws arrive by the thousand, disclosure, triage, and patching must be automated, or discovery just becomes inventory. Third, open-source infrastructure is on the front line: the $4 million in donations points at OpenSSF and Apache, the organizations stewarding the projects where the real patching backlog lives. For product teams, folding security scanning and repair pipelines into agent workflows is no longer a deferrable line item.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL