Anthropic Drops a 'Nuclear Bomb': AI Vulnerability Detection Surpasses Humans, 12 Tech Giants Unite for Project Glasswing
Anthropic launches Project Glasswing with AWS, Apple, Microsoft, Google, and 8 other tech giants, investing $100M in usage credits and $4M in donations. The core is Claude Mythos Preview, an AI model that surpasses human capability in vulnerability detection, having discovered thousands of critical vulnerabilities including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg flaw.
Published 164 days ago. Content may be outdated.
Anthropic is going all in this time!
Today, they announced the launch of Project Glasswing, partnering with 12 tech giants including AWS, Apple, Microsoft, Google, NVIDIA, and Cisco, with one singular goal: to identify and fix vulnerabilities in the world’s most critical software before the AI era fully arrives.
What’s even more striking is that Anthropic has unveiled an unreleased frontier model called Claude Mythos Preview, whose capability in finding and exploiting software vulnerabilities has surpassed all but the most elite human experts.
Here are the numbers:
- Thousands of critical vulnerabilities discovered, including in every major operating system and browser
- 27-year-old bug (OpenBSD) and 16-year-old bug (FFmpeg) uncovered
- $100 million in usage credits + $4 million in direct donations
- 40+ organizations granted model access
What does this mean? AI can now automate tasks that previously only top security experts could perform—and do it faster with broader coverage.
Why Project Glasswing? The “Tipping Point” in AI Cybersecurity
Anthropic is blunt in their announcement: AI models have reached a tipping point in coding capability where they can surpass nearly all humans in finding and exploiting software vulnerabilities.
This isn’t fear-mongering. Global annual losses from cybercrime are estimated at around $500 billion, and AI is now dramatically lowering the cost, difficulty, and expertise barrier for finding vulnerabilities.
| Traditional Approach | AI Era |
|---|---|
| Requires elite security experts | AI models automate the process |
| Vulnerabilities can hide for years or decades | Rapid scanning discovers legacy issues |
| Manual review has limited efficiency | Massive parallel processing |
| High cost | Significantly reduced cost |
The question is: What if attackers also gain access to this AI capability?
This is the core logic behind Project Glasswing—find and fix vulnerabilities with AI before malicious actors acquire this capability, giving defenders the advantage.
In Anthropic’s words: “For defenders to win, we must act now.”
Claude Mythos Preview: The “Nuclear Weapon” of Vulnerability Detection
Core Capabilities: Autonomous Discovery + Autonomous Exploitation
Claude Mythos Preview isn’t an ordinary code analysis tool—its capabilities can be described as “terrifying”:
| Capability Dimension | Specific Performance | Description |
|---|---|---|
| Autonomous Vulnerability Discovery | Thousands of zero-day vulnerabilities | Fully autonomous, no human guidance needed |
| Coverage Scope | All major operating systems + all major browsers | Windows, macOS, Linux, Chrome, Firefox, Safari all affected |
| Vulnerability Age | Up to 27 years old | Survived decades of human review and millions of automated tests |
| Autonomous Exploit Development | Complex exploit chains | Not only finds vulnerabilities but writes attack code |
Simply put, it doesn’t just tell you where the problem is—it demonstrates how to attack it.
Three Shocking Case Studies
1. OpenBSD’s 27-Year-Old Vulnerability
What is OpenBSD? One of the world’s most security-hardened operating systems, specifically used for firewalls and critical infrastructure.
The result? Mythos Preview found a 27-year-old remote crash vulnerability—an attacker could crash the entire system just by connecting to the target machine.
27 years! This means from 1998 to 2025, this vulnerability was sitting there. Countless security experts reviewed this code, but no one caught it.
2. FFmpeg’s 16-Year-Old Vulnerability
FFmpeg is the foundational library for video encoding/decoding, used by virtually all video software.
Mythos Preview discovered a 16-year-old vulnerability, and here’s the kicker: automated testing tools had executed this line of code 5 million times without ever detecting the issue.
What does that mean? Traditional fuzzing tools ran 5 million times and missed it—AI spotted it at a glance.
3. Linux Kernel Exploit Chain
The Linux kernel powers most of the world’s servers. Mythos Preview not only found multiple vulnerabilities but autonomously chained them together to achieve privilege escalation from ordinary user access to complete machine control.
This “exploit chain” attack is a hallmark skill of advanced hackers—now AI can do it too.
Performance Data: Crushing Advantage
In cybersecurity benchmarks like CyberGym, Mythos Preview’s performance far exceeds Anthropic’s previous strongest model, Claude Opus 4.6.
It has also reached new heights in coding capabilities:
| Benchmark | Description | Performance |
|---|---|---|
| SWE-bench Verified | Real-world software engineering tasks | Highest score |
| Terminal-Bench 2.0 | Terminal operations and system tasks | 92.1% |
| BrowseComp | Browser automation tasks | Higher than Opus 4.6, using 4.9× fewer tokens |
The key point: These coding capabilities directly translate into cybersecurity capabilities. An AI that can write code can naturally find vulnerabilities in code.
What Do the 12 Tech Giants Say?
AWS: “We Analyze 400 Trillion Network Flows Daily"
"At AWS, we build defenses before threats emerge. Our teams analyze over 400 trillion network flows every day for threats, and AI is central to our ability to defend at scale. We’ve been testing Claude Mythos Preview in our own security operations, applying it to critical codebases, where it’s already helping us strengthen our code.”
Microsoft: “The Attack Window Has Collapsed from Months to Minutes"
"When tested against our open-source security benchmark CTI-REALM, Claude Mythos Preview showed substantial improvements compared to previous models. We look forward to partnering with Anthropic and the broader industry to improve security outcomes for all.”
CrowdStrike: “The Window Between Discovery and Exploitation Has Collapsed"
"The window between a vulnerability being discovered and being exploited by an adversary has collapsed—what once took months now happens in minutes with AI. Claude Mythos Preview demonstrates what is now possible for defenders at scale, and adversaries will inevitably look to exploit the same capabilities. That is not a reason to slow down; it’s a reason to move together, faster.”
Cisco: “The Old Ways of Hardening Systems Are No Longer Sufficient"
"AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back. Our foundational work with these models has shown we can identify and fix security vulnerabilities across hardware and software at a pace and scale previously impossible. That is a profound shift, and a clear signal: the old ways of hardening systems are no longer sufficient.”
Linux Foundation: “Open Source Maintainers Finally Have Security Expertise"
"In the past, security expertise has been a luxury reserved for organizations with large security teams. Open source maintainers—whose software underpins much of the world’s critical infrastructure—have historically been left to figure out security on their own. By giving the maintainers of these critical open source codebases access to a new generation of AI models that can proactively identify and fix vulnerabilities at scale, Project Glasswing offers a credible path to changing that equation. This is how AI-augmented security can become a trusted sidekick for every maintainer, not just those who can afford expensive security teams.”
Project Glasswing: $100M + 40+ Organizations
Participation Structure
| Participation Type | Organizations | What They Get |
|---|---|---|
| Core Partners | AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks | Mythos Preview access for defensive security work |
| Critical Software Organizations | 40+ organizations building or maintaining critical software infrastructure | Scan and secure first-party and open-source systems |
| Open Source Security Organizations | Alpha-Omega, OpenSSF, Apache Software Foundation | Direct financial donations (total $4M) |
Financial Investment
| Investment Type | Amount | Purpose |
|---|---|---|
| Model Usage Credits | $100 million | Cover substantial usage across Glasswing participants |
| Open Source Security Donation | $2.5 million | Alpha-Omega and OpenSSF (through Linux Foundation) |
| Open Source Security Donation | $1.5 million | Apache Software Foundation |
| Total | $104 million | - |
Pricing
For participants, Mythos Preview pricing is:
- Input: $25 / million tokens
- Output: $125 / million tokens
Available via Claude API, Amazon Bedrock, Google Cloud Vertex AI, and Microsoft Foundry.
Work Focus Areas
| Task Type | Description |
|---|---|
| Local Vulnerability Detection | Scan codebases for security issues |
| Black Box Testing | Test binary security |
| Endpoint Security | Harden endpoint devices |
| Penetration Testing | Simulate attacks to test system defenses |
90-Day Public Report
Anthropic commits to publicly reporting within 90 days:
- Vulnerabilities fixed (disclosable portions)
- Lessons learned and best practices
- Recommendations for evolving security practices in the AI era
Potential recommendation areas include:
- Vulnerability disclosure processes
- Software update processes
- Open-source and supply chain security
- Secure development lifecycle
- Standards for regulated industries
- Triage scaling and automation
- Patching automation
Why Not Release Mythos Preview Publicly?
This is a critical question. Anthropic explicitly states: they do not plan to make Claude Mythos Preview generally available.
The reason is simple: this model is too dangerous.
It can find vulnerabilities and develop exploit code. If it falls into the hands of malicious actors, the consequences would be catastrophic.
Anthropic’s plan is:
- First use Mythos Preview to help defenders find and fix vulnerabilities
- Simultaneously develop cybersecurity safeguards that can detect and block the model’s dangerous outputs
- Deploy these safeguards in an upcoming Claude Opus model
- Ultimate goal is to enable users to safely deploy Mythos-class models at scale
In Anthropic’s words: “We need to make progress in developing safeguards with a model that does not pose the same level of risk.”
Technical Deep Dive: Why Is Mythos Preview So Powerful?
Core Capability: Agentic Coding + Reasoning
Mythos Preview’s cybersecurity capabilities fundamentally stem from its powerful agentic coding and reasoning abilities.
| Capability Dimension | Description |
|---|---|
| Code Understanding | Deep comprehension of complex code logic |
| Vulnerability Reasoning | Infer potential security issues |
| Exploit Development | Write complex exploit code |
| Autonomous Operation | Fully autonomous, no human guidance needed |
Simply put, it doesn’t just write code—it “reads” code and can spot problems in it.
Coding Capabilities: Comprehensive Leadership
Across multiple software engineering benchmarks, Mythos Preview achieves the highest scores of any model to date:
- SWE-bench Verified / Pro / Multilingual: Real-world software engineering tasks
- SWE-bench Multimodal: Multimodal software engineering tasks
- Terminal-Bench 2.0: Terminal operation tasks (92.1% accuracy)
- Humanity’s Last Exam: Comprehensive capability test
- BrowseComp: Browser automation tasks
These coding capabilities directly translate into cybersecurity capabilities—an AI that can write code can naturally find vulnerabilities in code.
Use Cases: Who Can Use It? How?
| Application Scenario | Target Users | Core Value |
|---|---|---|
| Critical Infrastructure Security | OS, browser, network equipment vendors | Discover and fix core software vulnerabilities |
| Open Source Software Hardening | Open source project maintainers | Give small teams enterprise-grade security capabilities |
| Enterprise Security Operations | Large enterprise CISO teams | Automate vulnerability scanning and penetration testing |
| Financial System Protection | Banks, payment institutions | Protect critical financial infrastructure |
| Cloud Service Security | Cloud service providers | Harden cloud platforms and customer environments |
| Supply Chain Security | Software supply chain stakeholders | Identify third-party component vulnerabilities |
Collaboration with the U.S. Government
Anthropic explicitly states they have been in ongoing discussions with U.S. government officials about Mythos Preview’s offensive and defensive cyber capabilities.
Key points:
- Securing critical infrastructure is a top national security priority for democratic countries
- The U.S. and its allies must maintain a decisive lead in AI technology
- Governments have an essential role in assessing and mitigating national security risks associated with AI models
Anthropic states: “We are ready to work with local, state, and federal representatives to assist in these tasks.”
Final Thoughts: Defenders’ “Last Chance”?
The launch of Project Glasswing marks the entry of cybersecurity into a completely new era.
It’s no longer “human experts vs. human hackers”—it’s “AI defense vs. AI attack.”
The key is: the time window is extremely short.
Anthropic repeatedly emphasizes in their announcement:
- “For defenders to win, we must act now"
- "Frontier AI capabilities are likely to advance substantially over just the next few months"
- "For cyber defenders to come out ahead, we need to act now”
CrowdStrike puts it more bluntly: “The window between discovery and exploitation has collapsed from months to minutes.”
Project Glasswing is essentially a race against time:
- Before malicious actors gain AI vulnerability detection capabilities
- Use AI to find and fix vulnerabilities in the world’s most critical software first
- Give defenders a durable advantage in the AI era
$100 million, 12 tech giants, 40+ critical organizations, thousands of discovered vulnerabilities—behind these numbers is the entire tech industry’s heightened awareness of AI cybersecurity threats.
More importantly, Anthropic isn’t just releasing the model—they’re providing funding, technical support, and best practice sharing. Developers and maintainers can get started immediately, no waiting required.
The AI-era cybersecurity war has begun.
References:
- Anthropic Official Announcement: https://www.anthropic.com/glasswing
- Claude Mythos Preview System Card
- Anthropic Frontier Red Team Blog
Related Links:
- Claude for Open Source Program Application: https://www.anthropic.com/claude-for-open-source
- Alpha-Omega Project: https://alpha-omega.dev/
- OpenSSF (Open Source Security Foundation): https://openssf.org/
More Articles