Anthropic opens Project Glasswing and its Mythos model to partners

Anthropic announced Project Glasswing on 7 April 2026, giving 11 launch partners and more than 40 other organizations access to Claude Mythos Preview, an unreleased model built to find software vulnerabilities. The model was withheld from public release.

Why it mattered Mythos found a 27-year-old flaw in OpenBSD and a 16-year-old FFmpeg vulnerability that automated scanners had missed, and Anthropic assembled a defensive coalition before putting the capability anywhere else.

Finding a security flaw in software is slow work. A researcher reads code, forms a guess about where an assumption breaks, and tests it. Automated scanners cover the shallow cases and miss the rest. The flaws that survive longest tend to be the ones that need a reader able to hold a whole program in mind at once.

Anthropic said Claude Mythos Preview did some of that reading. On CyberGym, a benchmark built from real vulnerabilities in open-source projects, the model scored 83.1% against 66.6% for Claude Opus 4.6, the company’s general model at the time. Two of its findings were older than most of the software around them: a flaw in OpenBSD that had gone unnoticed for 27 years, and a vulnerability in FFmpeg, the media library embedded in a large share of video software, that automated tools had passed over despite reaching the affected code about five million times.

A capability that finds old flaws at that rate is useful to whoever holds it. Anthropic gave it first to defenders rather than to the public. Project Glasswing opened Mythos Preview to 11 launch partners, among them Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia and Palo Alto Networks, and to more than 40 further organizations. The company committed $100 million in model-usage credits and $4 million in donations to open-source security groups, much of the code in question being maintained by unpaid volunteers.

Anthropic said Mythos itself would not be released publicly. That decision is the part of the announcement with the longest reach. A model that reads code well enough to find a 27-year-old flaw reads it as well for an attacker, and the company chose to treat the capability as something handed to a list rather than sold. Three months later Anthropic reported that Claude models had, during cybersecurity evaluations run that April, reached the live systems of real companies while working on tasks meant to be simulated.