Contents

Claude Mythos: Anthropic Released a Model, Then Hid It

Anthropic released Claude Mythos.

Then hid it.

Not unreleased. Released, and not sold in public.

What the official announcement said

Per the Glasswing announcement and the Red Team post, Claude Mythos Preview found thousands of zero-day vulnerabilities in controlled tests, across major operating systems and browsers, including the Linux kernel.

Examples called out:

  • Bugs in every major browser
  • Linux kernel bugs chained into a full attack path
  • A 27-year-old OpenBSD bug that remotely crashes a machine
  • A 16-year-old FFmpeg bug that automated tests hit five million times without catching

The post calls Mythos Preview an unreleased general-purpose frontier model, then claims that at finding and exploiting software bugs it now beats everyone except the most skilled humans.

The capability is framed as demand-driven. Anthropic says public Claude has already been used to find bugs, write malware, extract sensitive data, and draft targeted ransom notes. So the model shipped, but not in public. Access goes through Project Glasswing, to vetted partners only.

Why this matters

Automated vulnerability discovery is a turning point for AI security.

Research used to depend on a small set of people, time, and luck. A model can now mine zero-days in a controlled environment at a scale people cannot match. Both sides will use it. Defenders can hunt first. Attackers can too.

Anthropic’s choice: only “defenders” get it.

The logic, and what it does not settle

Giving find-and-exploit skill to defenders while locking out attackers sounds reasonable. Three questions the announcement does not answer:

1. Who verifies a “defender”

CrowdStrike and Palo Alto Networks are security companies that also sell products. Knowing the bug first and selling the fix later is a conflict written into the roster.

2. Why these companies

Launch partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. The center is commercial. Independent research labs and academic security teams are not on the opening list. The Linux Foundation is an open-source door, not an application form.

3. Who sets patch priority

A bug that hits billions of devices but misses every Glasswing partner’s revenue — does it get patched first? The post does not say.

About Claude Mythos itself

What can be checked on the record:

  • Access is Project Glasswing. No public retail API. No promise of a store listing.
  • Partner list as above. Up to $100 million in usage credits, plus $4 million to open-source security groups.
  • Credits are for partners, not personal accounts.
  • On CyberGym the vendor reports Mythos Preview at 83.1% and Opus 4.6 at 66.6%. That contrast explains the lock. It is not a result anyone else can buy and rerun.
  • Patched cases get write-ups on the Red Team blog; the rest start as hashes. “Thousands” is not a public scorecard.

Full benchmark tables and a personal price page have not been published.

Further reading