The third concern cuts to the core of the “defense-first” thesis itself. CrowdStrike’s Zaitsev and Palo Alto’s Lee Klarich both argue that adversaries will develop equivalent capabilities regardless, so the right move is to accelerate defenders. That logic is defensible but not closed. Capable state actors may already have models approaching Mythos-class performance, or they may be years away. The timeline assumption embedded in “move faster together” carries enormous strategic weight — and Anthropic hasn’t published it.
None of this makes Project Glasswing a bad idea. It makes it an incomplete answer to a problem that will outlast any single initiative. The organizations that treat Glasswing as a complete solution will be wrong. Those who treat it as the opening move in a longer defensive buildout are closer to right.
Frequently Asked Questions
What is Anthropic’s Claude Mythos Preview model?
+
Claude Mythos Preview is Anthropic’s most capable and currently unreleased frontier AI model, built with advanced agentic coding and reasoning capabilities that enable it to autonomously discover and exploit software vulnerabilities at scale. It outperforms Claude Opus 4.6 on every major coding and cybersecurity benchmark — including a 93.9% score on SWE-bench Verified — and has already found thousands of high-severity zero-days across every major OS and browser.
Why isn’t Claude Mythos available to the public?
+
Anthropic determined that Mythos’ cyber capabilities are sufficiently advanced that general public release would materially increase the risk of large-scale AI-assisted cyberattacks. This makes Mythos the first frontier AI model explicitly withheld from public access for safety reasons. Access is restricted to vetted Project Glasswing partners for defensive vulnerability discovery while Anthropic develops safeguards sufficient for broader deployment.
What is Project Glasswing and who is involved?
+
Project Glasswing is Anthropic’s gated-access initiative that allows a curated coalition of technology, security, and critical-infrastructure organizations to use Claude Mythos Preview for proactive vulnerability discovery and patching. Partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, plus more than 40 additional organizations. Anthropic is also committing up to $100M in compute credits and $4M in open-source security donations.
How does Claude Mythos find zero-day vulnerabilities?
+
Mythos uses advanced semantic code understanding combined with agentic tool-use to analyze codebases autonomously, reason about developer intent, and identify flaws that pattern-matching tools miss. In documented cases, it found a 16-year-old FFmpeg vulnerability that had survived 5 million automated fuzz test passes, and chained together multiple Linux kernel flaws into a privilege escalation path — all without human steering at each step.
How does Claude Mythos compare to Claude Opus 4.6?
+
Mythos substantially outperforms Opus 4.6 across all measured dimensions: 93.9% vs 80.8% on SWE-bench Verified (code bug fixing), 83.1% vs 66.6% on CyberGym (vulnerability reproduction), and 82.0% vs 65.4% on Terminal-Bench 2.0 (agentic tool use). The CyberGym gap is the most significant for security practitioners — a +16.5 point difference suggests a qualitative shift in autonomous exploit capability.
What immediate steps should security teams take?
+
In the near term: audit your open-source dependencies for vulnerabilities Mythos has flagged (watch for CVE disclosures tied to Glasswing), tighten patch SLAs to account for compressed exploitation windows, and evaluate AI-augmented code scanning for your CI/CD pipeline. For a full framework, see the 30/90/365-day playbook in this article.
Is Claude Mythos a risk to financial institutions specifically?
+
Yes, in a specific way. JPMorganChase joined Glasswing partly in response to concerns about systemic financial risk from AI-accelerated cyberattacks. Anthropic proactively briefed government agencies on this risk before the public announcement. Financial institutions face both the direct technical threat (AI-found zero-days in banking infrastructure) and a regulatory risk as central banks and financial supervisors assess whether AI-enabled cyber events require new systemic risk frameworks.
What are the main criticisms of Project Glasswing?
+
Three main criticisms have emerged: (1) Access concentration — Glasswing primarily benefits large tech companies and financial institutions, leaving smaller organizations and non-US entities without early access or guidance; (2) Patch capacity bottlenecks — AI-generated vulnerability reports may exceed the human capacity to triage and fix them, creating disclosure liability without corresponding security improvements; (3) Timeline assumptions — the “move faster together” thesis assumes adversary development timelines that Anthropic hasn’t made public.
What is Anthropic’s relationship with CoreWeave and why does it matter here?
+
On April 10, 2026, CoreWeave and Anthropic announced a multi-year GPU infrastructure agreement to support Claude’s production deployment at scale. CoreWeave reported $5.13B in 2025 revenue with $12B+ guidance for 2026. This matters for Mythos specifically because frontier vulnerability discovery at scale requires significant compute — the infrastructure commitment signals that Anthropic is building for sustained operation of Mythos-class workloads, not a single demonstration run.
When might Mythos-class AI become more broadly accessible?
+
Anthropic has not published a timeline. Their stated plan is to expand Mythos-class access once safeguards are sufficiently mature to prevent misuse. Given the pace of capability development across the industry, most security analysts expect either Anthropic to widen Glasswing eligibility, or competing labs to approach similar capability levels, within 18–36 months. The more important question may be governance readiness, not model access.