Anthropic launched Project Glasswing with a $100 million commitment in model usage credits to help major tech partners and open-source maintainers patch critical software vulnerabilities. Powered by the unreleased frontier model Claude Mythos Preview, the initiative aims to neutralize high-severity zero-day flaws before malicious actors can exploit them. The defensive security coalition includes Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks.
Autonomous Bug Hunting Across Major Operating Systems
According to Anthropic's disclosures, Claude Mythos Preview achieved an 83.1% success rate on the CyberGym vulnerability reproduction benchmark, compared to 66.6% for Claude Opus 4.6.
During initial testing, the model found high-severity zero-day flaws across major operating systems and web browsers. Notable findings that have since been patched include:
- 27-year-old flaw: A remote crash vulnerability discovered in OpenBSD that allowed attackers to disrupt machines simply by connecting to them.
- 16-year-old bug: A flaw in FFmpeg located in a code segment that automated testing tools had previously executed 5 million times without detecting.
- Linux kernel exploit: Identification and chaining of multiple vulnerabilities to achieve full root privilege escalation on Linux servers.
A Coalition of Tech Leaders and Open-Source Maintainers
Anthropic extended access to more than 40 additional organizations that maintain essential digital infrastructure. Beyond the $100 million in model access credits, Anthropic committed $4 million in direct cash donations to open-source security organizations, aimed at maintainers who lack dedicated security teams.
Partner companies have already integrated the model into active security workflows. Microsoft verified model performance improvements using its internal CTI-REALM benchmark, while AWS reported using Mythos Preview to harden core cloud systems against potential network threats.
Critical Security Risks and Proliferation Caveats
Anthropic flagged a fundamental caveat: the same mechanics that let Mythos Preview repair broken code can be weaponized to generate exploits if similar capabilities proliferate to bad actors. Anthropic also noted that while building cyber defenses across global infrastructure may take years, offensive AI capabilities are advancing on a monthly basis — raising the risk that automated bug hunting could outpace organizations' ability to deploy patches.