Anthropic Says Partners Using Claude Mythos Found at Least 129,000 Verified Software Vulnerabilities in Four Months, 33,000 of Them Critical or High, and Expects the True Impact to Be “At Least Five Times Higher” — as It Opens the Restricted Model to Three Tiers of Vetted Security Teams
On Oct 6, 2026 Anthropic launched an expanded Cyber Verification Program and put numbers on what its restricted Claude Mythos models have found: partners in Project Glasswing uncovered at least 129,000 verified software vulnerabilities between April and July 2026, drawn from 33 partner reports, and Anthropic's own open-source scanning found a further 5,500 between April and October. More than 33,000 of the verified vulnerabilities have so far been rated critical or high severity, up from the 'more than 10,000' Anthropic reported when it expanded Glasswing on Jun 2. Anthropic says it expects 'the true impact to be at least five times higher'. The program now has three tiers: Defense Access (security teams at companies, nonprofits, universities and government bodies, plus individual researchers with a track record of reported vulnerabilities), Red Team Access (in-house and government red teams and penetration-testing firms; no individuals) and Specialized Access (the fewest cyber blocks, for a limited set of organizations reviewed in depth with the US government). Each tier includes Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1 and new models going forward, with reduced blocking classifiers. Project Glasswing, launched Apr 7 with 12 partners including AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, Nvidia and Palo Alto Networks plus more than 40 other organizations, and widened to about 150 more organizations in more than 15 countries on Jun 2, is folded into the program. The catch is Anthropic's own June sentence: releasing Mythos broadly would need safeguards against misuse of its cyber capabilities 'that we (and, to our knowledge, all other AI developers) have yet to develop'. October's answer is vetting rather than safeguards, and a vulnerability count the company itself calls a fivefold undercount. Reuters has reported, from a draft prospectus, that Anthropic is preparing an IPO that could value it above $2 trillion.

Receipts
- Primaryhttps://www.anthropic.com/news/cyber-verification-program
- Alsohttps://www.bloomberg.com/news/articles/2026-10-06/anthropic-expands-access-to-latest-ai-models-for-cyber-firms
- Alsohttps://siliconangle.com/2026/10/06/anthropic-folds-project-glasswing-into-an-expanded-three-tier-cyber-verification-program/
- Alsohttps://www.cybersecuritydive.com/news/ai-anthropic-claude-mythos-project-glasswing-expand/821714/
- Alsohttps://www.anthropic.com/news/expanding-project-glasswing
- Alsohttps://www.cnbc.com/2026/06/02/anthropic-mythos-ai-project-glasswing.html
- Alsohttps://www.anthropic.com/project/glasswing
- Alsohttps://www.hpcwire.com/aiwire/2026/04/09/anthropic-unveils-project-glasswing-as-claude-mythos-targets-software-vulnerabilities/