Timeline

Anthropic expands Claude Mythos 5 security scanning, adds $35m defender fund

Enterprise customers reach the model only through a scanning interface built for the task, not direct access, and the fund pays specifically for patching open-source projects.

  • Security & misuse
  • Money & business
  • Notable

Anthropic extended Claude Security, the vulnerability-scanning tool for Claude Enterprise customers that grew out of the Claude Code Security preview it first showed in February 2026, to run on Claude Mythos 5 — one of the restricted “Mythos-class” models Anthropic launched in June 2026 and has kept off general release because it lacks the safety classifiers built into its public sibling, Fable 5. The tool, which reached public beta for Enterprise customers on an earlier Opus-class model in May 2026, scans codebases and returns vulnerability findings with severity ratings and suggested patches for a human to review.

The access model was built specifically to avoid handing Mythos 5 itself to customers: users interact with a purpose-built interface that runs the model in the background for a defined scanning task and returns only the resulting artefact — a vulnerability report — rather than a general-purpose chat interface onto the underlying model’s full capabilities. Anthropic has used the same mediated-access pattern since Mythos’s original restriction to vetted cyber-defence and biosecurity partners under Project Glasswing.

Alongside the product change, Anthropic launched a $35 million Defender Advantage Fund, paid out in Claude credits, aimed at patching vulnerabilities in widely used open-source projects, automating that patching so it can be repeated across many codebases, and supporting more ambitious defensive work aimed at entire classes of attack rather than individual bugs. The fund extends a broader effort — including Project Glasswing’s own vulnerability-hunting work, which had already surfaced more than 10,000 flaws by May — to distribute frontier capability toward defenders faster than Anthropic judges attackers are adopting it, an argument the company repeated as it expanded cyber-focused access through 2026.

In the commentary

What people were saying around this time — external links, from the record's commentary rail.