Anthropic did something unusual yesterday (April 7): it released a new model but is not making it available to the general public.
The model is called Claude Mythos. In its own internal evaluation, Anthropic wrote that it far surpasses any other AI model in cybersecurity capabilities. Then the company decided — not to release it publicly, only to a small group of designated partners for testing.
The project is called Project Glasswing.
Who gets to use it?
The list is impressive: AWS, Apple, Nvidia, Google, Microsoft, Cisco, CrowdStrike, JPMorgan Chase … about 10 tech giants, plus 40 other organizations responsible for maintaining critical infrastructure.
That makes roughly 50 institutions in total. The internet used by billions of people around the world will rely on these 50 institutions to patch vulnerabilities using Mythos.
Anthropic also provided $100 million in model usage credits, free for these partners, and directly donated $4 million to the open-source security community.
What vulnerabilities can Mythos actually find?
Over the past few weeks, Anthropic has already scanned with Mythos Preview:
- Thousands of zero-day vulnerabilities, covering every major operating system and major browser
- A vulnerability in OpenBSD that had existed for 27 years, capable of triggering a remote system crash
- A 16-year-old flaw in FFmpeg that had gone undetected through millions of automated tests
- Multiple Linux kernel vulnerabilities enabling privilege escalation
27 years. That's not bug hunting; that's archaeological excavation.
The FFmpeg vulnerability is even more telling: millions of automated scans missed it, and an AI found it in a few weeks. Traditional security tools should be worried about their own relevance.
Why not release it publicly?
Anthropic has privately warned senior government officials that Mythos makes large-scale AI-driven cyberattacks significantly more likely this year.
As early as a month ago, an accidentally exposed internal draft stated: Mythos currently far surpasses any other AI model in cybersecurity capabilities. That statement now appears not to be boasting, but a serious expression of concern.
Defense and offense use the same capabilities. Mythos can help you find and fix vulnerabilities, but it can also help hackers find vulnerabilities and break in. Anthropic's approach is to give defenders a first-mover advantage — letting large companies and critical infrastructure maintainers patch holes before attackers can exploit them.
Is this strategy problematic?
This is a rather delicate bet.
What's convincing: if Mythos can truly mass-discover vulnerabilities that have gone unpatched for decades, that is indeed groundbreaking on the defensive side. Existing security tools clearly cannot do this, otherwise the 27-year-old OpenBSD bug would have been caught long ago.
But how long can the model of restricting access to 50 institutions hold? Could people inside partner organizations leak it? Will other labs replicate similar capabilities?
The more fundamental question is: Anthropic has already built it. Whether it is made public or not, the capability already exists. Instead of agonizing over whether to release it, the better question is: how many holes can these 50 institutions patch before competitors develop the same capability?
Project Glasswing is less about managing risk and more about racing against time.
Sources: Anthropic debuts preview of powerful new AI model Mythos in new cybersecurity initiative (TechCrunch); CocoLoop, Anthropic is giving some firms early access to Claude Mythos to bolster cybersecurity defenses (Fortune); Project Glasswing: Securing critical software for the AI era (anthropic.com); Project Glasswing: Anthropic announces big tech consortium to test Claude Mythos (IT Pro)