Anthropic announced Project Glasswing, a cybersecurity initiative intended to use an unreleased frontier model to find and help repair vulnerabilities in critical software. The company said launch partners and more than 40 additional organizations that build or maintain important software infrastructure would receive access to Claude Mythos Preview for defensive work.
The program carries two financial commitments. Anthropic said it would provide up to $100 million in model-usage credits across the participating efforts and donate $4 million directly to open-source security organizations. It also plans to share lessons from partner deployments with the wider industry. The announcement describes Glasswing as an initial collaboration rather than a complete answer to software security.
Anthropic tied the project to capabilities it says it observed while testing Mythos Preview, a general-purpose model that has not been publicly released. According to the company, the model found thousands of previously unknown vulnerabilities across major operating systems, web browsers and other software. Anthropic said many were critical and that nearly all were identified without human steering, with the model also developing exploits for a number of them. These performance claims come from Anthropic itself and were not independently validated in the supplied material.
The company said it reported identified flaws to the relevant maintainers. Examples it planned to discuss publicly had already been patched, while details of other unresolved findings would initially be represented by cryptographic hashes and disclosed after fixes became available. That staged approach is designed to document discoveries without immediately publishing information that could facilitate attacks.
Project Glasswing reflects Anthropic's argument that rapidly improving coding models create a dual-use security challenge. The same systems that can lower the expertise and effort required to locate software weaknesses could also help defenders review large codebases, develop fixes and improve new software. Anthropic warned that broad access to powerful vulnerability-finding tools could increase the frequency and severity of attacks if defensive deployment falls behind.
The launch page says partner organizations have already used Mythos Preview for several weeks. Their work is expected to cover both first-party systems and open-source components. Anthropic framed the group as spanning frontier AI developers, software companies, researchers and maintainers, while also saying governments have a role in protecting infrastructure.
The initiative's immediate significance lies in access and remediation rather than a public model release. Selected defenders receive a capability Anthropic considers unusually strong, while disclosure remains coordinated with software maintainers. Whether that produces a durable advantage will depend on the quality of the findings, the pace at which organizations can patch them and how quickly comparable capabilities spread beyond controlled programs.



