In April 2026, Anthropic did something unusual.
It announced its most powerful model yet — Claude Mythos Preview — and said it would not release it to the public. Instead, the model went to a small group of trusted partners to fix security flaws in the world's most critical software. That effort is called Project Glasswing.
What is Project Glasswing?
Project Glasswing is a security program Anthropic launched on April 7, 2026.
It gives selected organizations access to an unreleased model, Claude Mythos Preview, for one job: find and fix security vulnerabilities in critical software before attackers find them.
The name is a nod to the glasswing butterfly, per launch coverage — a fitting image for a tool built to find flaws that have been hiding in plain sight for years.
Why this model is different
Anthropic says AI models have crossed a line. They can now beat all but the most skilled humans at finding and exploiting software vulnerabilities.
Mythos Preview was not trained specifically for security. Anthropic says the skill is a side effect of strong coding and reasoning. Before the announcement, the model had found thousands of high-severity vulnerabilities — including some in every major operating system and every major web browser.
What it found
Three examples Anthropic shared:
- A 27-year-old flaw in OpenBSD, one of the most security-hardened operating systems in the world. It let an attacker crash a machine just by connecting to it.
- A 16-year-old flaw in FFmpeg, the video tool built into countless apps. The buggy line of code had been hit five million times by automated testing tools without anyone catching it.
- Several Linux kernel flaws the model chained together on its own to go from ordinary user access to full control of a machine.
Anthropic says these were found almost entirely autonomously, reported to the maintainers, and are now patched.
Why you can't use it
Anthropic is blunt about the risk. A model this good at finding holes in software is dangerous in the wrong hands.
So Mythos Preview will not be generally available. Anthropic says the safeguards needed to block its worst outputs do not exist yet — at Anthropic or, to its knowledge, anywhere else.
The plan is to build those safeguards first, testing them on a future Claude Opus model that is less risky. General access to Mythos-class models is the goal, but only when it can be done safely.
Who gets access, and what it costs
The launch partners are a who's who of critical infrastructure: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks.
Anthropic also gave access to more than 40 additional organizations that build or maintain critical software, so they can scan their own and open-source systems.
Anthropic committed up to $100 million in usage credits for the program, plus $4 million in donations to open-source security groups ($2.5 million to Alpha-Omega and OpenSSF, $1.5 million to the Apache Software Foundation).
After the credit period, partners pay $25 per million input tokens and $125 per million output tokens. Access runs through the Claude API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry.
The program grew fast
In June 2026, Anthropic expanded Project Glasswing to roughly 150 new organizations — about 200 in total, across more than 15 countries.
The new group looks different from the first. Instead of big tech companies, it is heavy on critical infrastructure: power, water, healthcare, communications, and hardware vendors whose code other companies rely on.
By the time of the June 2 expansion, the first partners had used Mythos Preview to find more than 10,000 high- or critical-severity flaws, according to Anthropic.
Anthropic also released Claude Security, a product that scans codebases and suggests patches using its public models like Claude Opus 4.8 — a version of the idea the rest of us can actually use.
The bigger picture
Within 6 to 12 months, Anthropic expects many other AI companies to have Mythos-class models — and some may release them without safeguards.
When that happens, attacks could get faster and more common. Project Glasswing is a bet that defenders should get the head start.
There is an honest catch. Finding flaws is now the easy part. Anthropic itself says the bottleneck has moved to verifying, disclosing, and patching the large numbers of vulnerabilities these models surface.
Bottom line
Project Glasswing is what happens when a model gets too capable for a normal launch: no public release, but a coordinated effort to point it at defense first.
Whether this becomes the standard pattern for frontier models is the real story to watch.
References
All benchmark figures, vulnerability counts, partner quotes, and program details are Anthropic's own, as reported on its official pages below — they are not independently measured by this post.
- Anthropic — Project Glasswing: Securing critical software for the AI era (April 7, 2026): anthropic.com/glasswing
- Anthropic — Expanding Project Glasswing (June 2, 2026): anthropic.com/news/expanding-project-glasswing
- Infosecurity Magazine — Anthropic Launches Project Glasswing to Fix Software Bugs With AI: infosecurity-magazine.com/news/anthropic-launch-project-glasswing
- Infosecurity Magazine — Anthropic Expands Mythos Access to 150 More Organizations: infosecurity-magazine.com/news/anthropic-glasswing-expansion
- TechCrunch — Anthropic scales Claude Mythos to critical infrastructure in 15+ countries (June 2, 2026): techcrunch.com/2026/06/02/anthropic-scales-claude-mythos-to-critical-infrastructure-in-15-countries
Comments & Reactions