Research·3 min read
By BitsMindsSource: Anthropic / Help Net Security

Anthropic’s Project Glasswing Turns an Unreleased Claude Mythos Loose on Open Source — and Finds 10,000+ Zero-Days in a Month

In a May 26 progress update, Anthropic said Project Glasswing has used an unreleased frontier model, Claude Mythos Preview, to autonomously discover more than 10,000 high- and critical-severity zero-day vulnerabilities across the world’s most important software in its first month — including a 27-year-old flaw in OpenBSD and a certificate-forgery bug in wolfSSL. The model is so capable at offensive security that Anthropic is refusing to release it.

PROJECT GLASSWING · CLAUDE MYTHOS ANTHROPIC 10,000+ high/critical-severity zero-days found in its first month, by an unreleased Claude Mythos ⚠ Withheld — no safe way to release it yet ONE MONTH OF MYTHOS 23,019 issues · 1,000+ projects scanned 90%+ true-positive · 13 defenders enrolled MARQUEE FINDINGS 27-year-old flaw in hardened OpenBSD wolfSSL exploit forges TLS certificates Source: Anthropic · Help Net Security
Share:

Anthropic on May 26 published a progress update on Project Glasswing, the security initiative it runs on Claude Mythos Preview — an unreleased, general-purpose frontier model. In its first month, Anthropic says, the model autonomously discovered more than 10,000 high- and critical-severity zero-day vulnerabilities across the world’s most critical software, scanning over 1,000 open-source projects and surfacing 23,019 total issues, of which 6,202 were rated high or critical.

To guard against AI slop, Anthropic and six independent security firms hand-assessed a sample of 1,752 findings and validated more than 90% as true positives. The standout cases are sobering: Mythos uncovered a 27-year-old vulnerability in OpenBSD, an operating system famous for its security hardening, and a flaw in wolfSSL — a cryptography library embedded in billions of devices — for which it constructed a working exploit that would let an attacker forge certificates and mount convincing phishing attacks. The company says the model found exploitable bugs in every major operating system and every major web browser.

The capability cuts both ways, which is why Anthropic is doing something unusual: refusing to ship the model. “At present, no company — including Anthropic — has developed safeguards strong enough to prevent such models from being misused and potentially causing severe harm,” the company wrote, adding that AI has reached a level of coding skill where it “can surpass all but the most skilled humans at finding and exploiting software vulnerabilities.” Instead of a general release, Mythos is being made available only through Glasswing to a small set of defenders: AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, Cloudflare and Mozilla.

The harder problem the update exposes is not discovery but remediation. Finding 10,000 zero-days is only useful if someone patches them, and the open-source maintainers who steward much of this code are already stretched thin — a single volunteer can suddenly be handed a backlog of machine-generated, critical-severity reports with no realistic way to triage them. Anthropic frames Glasswing as a way to get fixes to defenders before the same class of capability lands in an attacker’s hands, but it has effectively demonstrated that the offensive version of this tool is now buildable.

Mythos itself has been circling in the background of Anthropic’s recent news: BitsMinds reported on May 25 that Japan’s megabanks were granted access to Claude Mythos after a U.S. Treasury-brokered arrangement. Project Glasswing is the clearest public look yet at what that unreleased model can actually do — and a preview of a security landscape in which the most powerful vulnerability scanner in the world is also the most dangerous, and its owner has decided the safest move is to keep it on a very short leash.

More on Claude

Evergreen coverage we keep current — start here.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles

OpenAI publishes 722 maths papers from an unreleased model An original monochrome still life on a pale grey desk. A tall stack of bound manuscripts is topped by a graphite cover with the OpenAI mark pressed into it and a small green seal with a tick. A loose page in front shows a line of number theory. Text on the left reads OPENAI · MATHEMATICS, 722 papers from one unreleased model, 372 families and 162 Lean-checked. The stack is an editorial metaphor; the tick marks Lean formalization, not independent peer review. BitsMinds original editorial vector artwork for openai-722-math-papers-internal-model. Figures verified on 7 October 2026 from github.com/openai/math (README, overview.tex, lean/formalization.yaml). Official OpenAI path from public/logos/openai.svg. L(s, χ) ≠ 0 for Re s > 7/8 OPENAI · MATHEMATICS 722 papers from one unreleased model 372 FAMILIES 162 LEAN-CHECKED BITSMINDS.COM
Research

OpenAI Posts 722 Math Papers From an Unreleased Model

Mythos cracks Rejetto HFS's random signing key A large ivory die on a cream field, the official Anthropic mark inlaid in clay on its front face. Its top face has split along a crack, and a brass key is rising out of it: the session signing key recovered from Math.random. Faint leaked random numbers drift in from the left; faint cookie fragments sit on the right. 0.73418 0.11902 0.58361 0.92047 0.30775 admin=1 sig:9f3c keygrip xs128+ BITSMINDS.COM
Research

A Bug Claude Mythos Found Was Exploited Within a Day

Meta Muse Spark's six math papers A fan of research manuscripts on a deep blue field. Five sheets behind carry gold check marks for the five open problems answered; the front sheet carries the official Meta mark, inlaid. Faint mathematical symbols float on either side. ∫ ∑ ψ |G| = 384 ∂ₜu λ ≥ 0 ℚₚ ≠ MUSE SPARK · THINKING 6 PAPERS · 5 OPEN PROBLEMS BITSMINDS.COM
Research

Meta Says Muse Spark Helped Crack Five Open Math Problems