Anthropic launches Project Glasswing and Claude Mythos Preview
Twelve launch partners including AWS, Apple, Cisco, Microsoft, NVIDIA and the Linux Foundation got gated access; Anthropic committed $100m in usage credits and $4m to open-source security groups.
- Security & misuse
- Safety & alignment
- Models & capabilities
- Major
Anthropic launched Project Glasswing, a coordinated effort to run its unreleased Claude Mythos Preview model against critical software on behalf of a coalition of infrastructure and security companies rather than releasing the model itself. Twelve launch partners were named: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks and Anthropic itself, with access later extended to open-source maintainers.
The mechanism was defensive rather than a product release: partners submitted their own codebases for Mythos to scan for vulnerabilities, rather than being given the model to use freely. Anthropic backed the effort with $100 million in usage credits for participating organisations and $4 million in direct grants to open-source security groups, including the Alpha-Omega project and the Apache Software Foundation. Palo Alto Networks said it used the model to find “complex vulnerabilities that prior-generation models missed entirely.” Access to the underlying model remained gated throughout: Anthropic priced API use at $25 per million input tokens and $125 per million output tokens for partners, but did not offer it through its consumer products.
By the end of May, reporting on the programme’s progress said Mythos had been run against more than 1,000 open-source projects, flagging 23,019 issues, of which 6,202 were rated high or critical severity; of a sample of 1,752 assessed findings, Anthropic said over 90% were confirmed as genuine. By early June the partner list had grown to roughly 150 organisations across more than 15 countries.
The launch set a template — a capability withheld from general release but shared through a vetted industry consortium — that drew comparisons to how other labs had handled dangerous-capability findings, and put pressure on competitors developing similar coding and cybersecurity models to disclose comparable evaluations before their own releases.