Dossier · Ongoing

Claude Mythos and Project Glasswing

Anthropic's unreleased Claude Mythos Preview and the Project Glasswing partner program: what it finds and who verifies the findings.

In April 2026 Anthropic announced Claude Mythos Preview, a model able to find software vulnerabilities on its own, and instead of releasing it publicly handed it to what are now around 200 partner organizations under Project Glasswing. This dossier tracks what the model surfaces: first a record number of reported CVEs, later cryptographic attacks on the post-quantum scheme HAWK and a shortened AES variant.

The thread running through the strand is verification rather than discovery. In both cases the researchers involved report that assessing the model’s output takes far more time and expertise than producing it – and that independent confirmations remain the exception. How standardization bodies, maintainers and security teams handle that shift is still open.

Timeline

  1. AI Bug-Hunting Sends Number of Reported CVEs Soaring

    Epoch AI logs a CVE record for June 2026: 3.5x more critical vulnerabilities since Claude Mythos and OpenAI's Daybreak began hunting bugs.

  2. Claude Mythos finds new attacks on HAWK and AES-128

    Anthropic's model cut the computational cost of attacking the post-quantum scheme HAWK in 60 hours; deployed systems remain secure.

  3. VulnCheck: Attackers exploit only 1.3 percent of AI vulnerabilities

    An analysis by VulnCheck shows AI-discovered security vulnerabilities are not attacked more often than traditionally found weaknesses.

  4. Anthropic's Claude Security Now Runs on Mythos 5

    The AI model Mythos 5, previously reserved for partners, now automatically scans company code for vulnerabilities – initially only for enterprise customers.