💻 techConcept9 views4 min read

What Happened to Project Glasswing?

Project Glasswing is a cybersecurity initiative launched by Anthropic in April 2026, utilizing its unreleased frontier AI model, Claude Mythos Preview, to autonomously discover and help remediate critical software vulnerabilities. The project aims to secure vital global software infrastructure by leveraging advanced AI capabilities for defensive purposes before similar powerful AI tools become widely available to malicious actors. It has expanded to include hundreds of organizations globally, revealing a significant 'patching deficit' where AI-driven discovery far outpaces human remediation capacity.

Share:
⚡

Quick Answer

Project Glasswing is Anthropic's initiative, launched in April 2026, to use its advanced AI model, Claude Mythos Preview, for autonomous vulnerability discovery in critical software. It has identified over 10,000 high- or critical-severity vulnerabilities, exposing a significant gap between AI's discovery speed and human patching capacity. The project has expanded to nearly 200 organizations across various critical infrastructure sectors, with Anthropic committing substantial resources to support remediation efforts and working towards safely releasing Mythos-class capabilities with robust safeguards. As of October 2026, the initiative continues to highlight the challenges of vulnerability management in the AI era, with a low percentage of discovered flaws being patched.

📊Key Facts

Launch Date
April 7, 2026
Anthropic
Initial Partner Organizations
12
Anthropic
Vulnerabilities Identified (first month)
Over 10,000 (high- or critical-severity)
Anthropic
Vulnerabilities Disclosed to Open-Source Maintainers (as of May 22, 2026)
1,596 across 281 projects
Anthropic
Vulnerabilities Patched (as of May 22, 2026)
97 (approx. 6% of disclosed)
Anthropic
Anthropic Commitment (Usage Credits)
$100 million
Anthropic
Anthropic Commitment (Open-Source Donations)
$4 million
Anthropic
Expanded Partner Organizations (as of June 2026)
Approx. 150-200
Anthropic, WION

📅Complete Timeline12 events

1
April 7, 2026Critical

Project Glasswing Launched by Anthropic

Anthropic officially announced Project Glasswing, a cybersecurity initiative giving 12 major technology partners early, restricted access to its unreleased Claude Mythos Preview AI model to find software vulnerabilities.

2
April 7, 2026Major

Anthropic Commits $100M in Credits and $4M in Donations

Alongside the launch, Anthropic pledged up to $100 million in usage credits for Mythos Preview to participating organizations and $4 million in direct donations to open-source security foundations.

3
April 13, 2026Critical

Initial Analysis of Mythos Capabilities and Impact

Early reports and analyses highlighted Mythos's ability to autonomously find thousands of zero-day vulnerabilities, including a 27-year-old flaw in OpenBSD and a 16-year-old flaw in FFmpeg, shifting the attack-defense balance.

4
May 18, 2026Major

Cloudflare Shares Observations from Using Mythos

Cloudflare, a Project Glasswing partner, published insights into their experience using Mythos Preview, noting its ability to construct exploit chains and its emergent guardrails.

5
May 22, 2026Critical

Over 10,000 Vulnerabilities Identified, Low Patching Rate Noted

Within its first month, Project Glasswing identified over 10,000 high- or critical-severity vulnerabilities. However, only 1,596 were disclosed to open-source maintainers, and a mere 97 were confirmed patched, revealing a significant 'patching deficit'.

6
June 2, 2026Critical

Project Glasswing Expands to ~150-200 Additional Organizations

Anthropic announced a significant expansion of Project Glasswing, extending access to approximately 150 to 200 new organizations across more than 15 countries, including critical infrastructure providers in power, water, healthcare, and communications.

7
June 8, 2026Notable

Skepticism Emerges Regarding Novelty of Some Findings

A report questioned the novelty of some flagship discoveries, suggesting they were older, unpatched fixes present in Mythos's training data. Cisco also demonstrated that other frontier models could reproduce similar detection capabilities.

8
June 9, 2026Major

Anthropic Releases Claude Fable 5, Glasswing Participants Upgraded

Anthropic released Claude Fable 5, the first publicly available Mythos-class model with safeguards. Project Glasswing participants were simultaneously upgraded to the unsafeguarded Claude Mythos 5, alongside a US-government collaboration.

9
July 2026Major

Horizon3.ai Joins Project Glasswing

Cybersecurity firm Horizon3.ai announced its participation in Project Glasswing, utilizing Anthropic's Mythos model in its vulnerability research pipelines to discover critical vulnerabilities.

10
August 2026Major

Anthropic Updates Vulnerability Disclosure Ledger

Anthropic updated its Vulnerability Disclosure ledger for the first time since the project's inception, with a small percentage of initial Mythos findings making it into the ledger and fewer than 1% marked as fixed.

11
September 29, 2026Major

Reports Highlight Low Patching Rate Amidst 'Vulnpocalypse'

TechTarget reported that five months into Project Glasswing, DevSecOps teams are struggling with the volume of discoveries, with only about 1% of AI-discovered vulnerabilities being exploited in the wild and a significant bottleneck in human triage.

12
September 30, 2026Major

Horizon3.ai Reports on Mythos Discoveries

Horizon3.ai shared an update on its use of Anthropic's Mythos model within Project Glasswing, detailing its success in finding critical vulnerabilities like the Rejetto HFS RCE.

Follow this story

Get an email when this timeline gets a major update.

🔍Deep Dive Analysis

Project Glasswing was officially unveiled by Anthropic on April 7, 2026, as a groundbreaking cybersecurity initiative designed to address the escalating threat landscape posed by advanced artificial intelligence. The core of the project is Claude Mythos Preview, an unreleased frontier AI model developed by Anthropic, which demonstrated unprecedented capabilities in autonomously identifying zero-day vulnerabilities, developing exploits, and chaining multiple flaws into complex attack paths without human intervention. This capability emerged as a downstream consequence of general improvements in AI's code understanding and reasoning, signaling a significant shift in cybersecurity dynamics.

The impetus behind Project Glasswing was Anthropic's realization that AI models had reached a level where they could surpass even highly skilled human security researchers in finding and exploiting software vulnerabilities. Rather than releasing Mythos Preview publicly, which could have severe consequences for global economies and public safety, Anthropic opted for a controlled, defensive deployment. The initial phase brought together a consortium of 12 major technology partners, including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, to apply Mythos Preview to secure critical software. Anthropic committed $100 million in model usage credits and $4 million in direct donations to open-source security organizations like Alpha-Omega, OpenSSF, and the Apache Software Foundation to support the initiative.

Within its first month of operation, Project Glasswing identified over 10,000 high- or critical-severity vulnerabilities, including long-standing flaws that had evaded human detection and automated tools for years, such as a 27-year-old vulnerability in OpenBSD and a 16-year-old flaw in FFmpeg. This rapid discovery rate exposed a critical 'structural patching deficit,' where AI-powered vulnerability discovery operates at machine speed, while open-source maintainers and remediation processes, often human-driven and capacity-constrained, operate at a much slower pace. As of May 22, 2026, Anthropic had disclosed 1,596 vulnerabilities to open-source maintainers across 281 projects, but only 97 were confirmed patched, representing a mere six percent remediation rate on disclosed findings and less than one percent of the total discoveries.

In late May and early June 2026, Project Glasswing expanded significantly, extending access to approximately 150 additional organizations in over 15 countries, covering critical infrastructure sectors such as power, water, healthcare, communications, and hardware. This expansion aimed to broaden the defensive application of Mythos-class capabilities and help the industry adapt to the new realities of AI-driven cybersecurity. While the project has been lauded as a crucial step towards AI-powered cyber defense, some skepticism has emerged regarding the novelty of certain flagship discoveries, with reports suggesting some were previously known but unpatched issues, and that similar detection capabilities could be reproduced by other commodity open-weight models.

As of October 1, 2026, Project Glasswing continues to operate, with partners like Horizon3.ai joining in July 2026 to utilize Mythos for vulnerability research. The initiative underscores a fundamental shift in cybersecurity: the bottleneck has moved from vulnerability discovery to remediation. The challenge now lies in developing new processes for exploit triage, software updates, supply-chain security, and patching automation that can keep pace with AI's discovery capabilities. Anthropic is working on robust safeguards before a broader public release of Mythos-class capabilities, recognizing the dual-use nature of such powerful AI. The long-term goal is for AI to make all software more secure, but the immediate future involves navigating the immense volume of newly identified vulnerabilities and transforming the entire cybersecurity ecosystem to handle AI at scale.

What If...?

Explore alternate histories. What if Project Glasswing made different choices?

Explore Scenarios
Building relationship map...

❓People Also Ask

What is Project Glasswing?
Project Glasswing is a cybersecurity initiative launched by Anthropic in April 2026. It uses Anthropic's unreleased frontier AI model, Claude Mythos Preview, to autonomously discover and help remediate critical software vulnerabilities in collaboration with leading technology and infrastructure organizations.
What is Claude Mythos Preview?
Claude Mythos Preview is an unreleased, advanced AI model developed by Anthropic. It possesses unprecedented capabilities in autonomously identifying zero-day vulnerabilities, developing exploits, and chaining multiple flaws in software, forming the core technology behind Project Glasswing.
Why was Project Glasswing created?
Project Glasswing was created in response to the discovery that advanced AI models like Claude Mythos Preview could autonomously find and exploit software vulnerabilities at a scale and speed far exceeding human capabilities. Its purpose is to leverage these AI capabilities defensively to secure critical software before similar tools become widely available to malicious actors.
What are the main challenges identified by Project Glasswing?
The project has exposed a significant 'structural patching deficit,' where AI-driven vulnerability discovery far outpaces the human capacity for remediation. It highlights the challenge of fixing thousands of newly identified bugs, especially in open-source projects maintained by volunteer teams.
What is the current status of Project Glasswing as of late 2026?
As of October 2026, Project Glasswing has expanded to nearly 200 organizations and continues to identify thousands of vulnerabilities. However, the rate of confirmed patches remains low, underscoring the ongoing challenge of scaling remediation efforts to match AI's discovery speed. Anthropic is working on safeguards for a broader release of Mythos-class capabilities.