AI Safety

Claude Mythos #2: Cybersecurity and Project Glasswing

Anthropic's unreleased AI model discovered critical vulnerabilities in every major OS and browser, sparking a secret patching initiative.

Deep Dive

Anthropic has created a new AI model, Claude Mythos, whose advanced ability to find and exploit software vulnerabilities has led the company to a drastic decision: it will not be released to the public. In a preview phase, Mythos identified thousands of critical, previously unknown zero-day vulnerabilities in foundational software, including every major operating system and web browser. Citing the immense danger of such capabilities being broadly available, Anthropic is instead launching 'Project Glasswing,' a controlled initiative to secure critical infrastructure before a new era of AI-powered cyber threats begins.

Under Project Glasswing, Mythos will be provided to a select group of launch partners and over 40 organizations that build or maintain vital software. The goal is a coordinated, months-long effort to patch the discovered vulnerabilities. Anthropic is committing $100 million in free AI credits to participants and pledges to report progress after 90 days. The move has triggered high-level government concern, including urgent meetings with Wall Street executives over systemic cyber risks, highlighting the model's potential to reshape the balance between cyber offense and defense.

Key Points
  • Claude Mythos identified thousands of zero-day vulnerabilities in every major OS and browser, deeming it too dangerous for public release.
  • Anthropic is launching 'Project Glasswing,' a limited release to partners and critical infrastructure orgs to patch flaws, backed by $100M in credits.
  • The model's capabilities signal a new era of AI-powered cybersecurity, prompting urgent government and financial sector meetings on systemic risk.

Why It Matters

This marks a pivotal moment where AI's power to attack software has outpaced defense, forcing a secret, preemptive race to secure global digital infrastructure.