The big picture: AI has crossed a threshold where it can surpass all but the most skilled humans at finding software vulnerabilities. Project Glasswing puts that power in the hands of defenders first.
Why Project Glasswing Exists
Anthropic's Claude Mythos Preview—a general-purpose frontier model not yet released to the public—has already discovered thousands of high-severity vulnerabilities, including some in every major operating system and every major web browser.
Some of these flaws had survived decades of human review and millions of automated tests. Among the discoveries:
- A 27-year-old vulnerability in OpenBSD that allowed an attacker to remotely crash any machine running the OS.
- A 16-year-old vulnerability in FFmpeg that automated testing tools had hit five million times without ever catching.
- The model autonomously chained together several vulnerabilities in the Linux kernel to escalate from ordinary user access to complete control of the machine.
All of these vulnerabilities have been patched.
Mythos Preview: A New Class of Cyber Capability
At the heart of Project Glasswing sits Claude Mythos Preview, a model that Anthropic describes as a leap in agentic coding and reasoning skills. Its benchmark scores reveal just how significant that leap is.
In Terminal-Bench 2.1 with extended timeout limits, Mythos Preview scored 92.1% — a capability level that Anthropic believes could reshape cybersecurity.
A Coalition of Industry Leaders
Project Glasswing partners include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. They are already using Mythos Preview in their defensive security operations.
From the partners:
"Our teams analyze over 400 trillion network flows every day for threats. We've been testing Claude Mythos Preview in our own security operations, where it's already helping us strengthen our code." — Amy Herzog, VP & CISO, Amazon Web Services
"Joining Project Glasswing allows us to identify and mitigate risk early so we can better protect customers." — Igor Tsyganskiy, EVP of Cybersecurity, Microsoft
In addition to launch partners, Anthropic has extended access to over 40 additional organizations that build or maintain critical software infrastructure.
Supporting Open Source Security
Open source software constitutes the vast majority of code in modern systems. Project Glasswing includes substantial support for this ecosystem:
- $100 million in usage credits for Claude Mythos Preview across Glasswing participants
- $2.5 million donated to Alpha-Omega and OpenSSF through the Linux Foundation
- $1.5 million donated to the Apache Software Foundation
Open source maintainers can apply for access through the Claude for Open Source program.
Access, Pricing, and Availability
Claude Mythos Preview will not be made generally available due to its offensive cyber capabilities. After the research preview concludes, participants will be able to access the model via API at:
- $25 per million input tokens
- $125 per million output tokens
Available through Claude API, Amazon Bedrock, Google Cloud's Vertex AI, and Microsoft Foundry.
Safeguards and the Path Forward
Anthropic acknowledges that security safeguards are not yet sufficient to safely deploy Mythos-class models at scale. Within 90 days, Anthropic will report publicly on what it has learned—including vulnerabilities fixed and improvements made—and collaborate with leading security organizations to produce practical recommendations for security practices in the AI era.
Why "Glasswing"? Named for the glasswing butterfly (Greta oto). Its transparent wings let it hide in plain sight—much like the vulnerabilities discussed—while also allowing it to evade harm, representing transparency in cybersecurity.
The current global financial costs of cybercrime are estimated at around $500 billion every year. With AI-powered attacks becoming inevitable, Project Glasswing represents an urgent attempt to put advanced AI capabilities to work for defenders first.