Claude Mythos did not create the AI-security asymmetry between attackers and defenders. Mythos made it undeniable. Anthropic's own Frontier Red Team used the model to autonomously discover thousands of high- and critical-severity zero-day vulnerabilities across every major operating system and every major web browser, and it did so at costs that break the historical economics of vulnerability research. In one campaign, Mythos surfaced a denial-of-service vulnerability in OpenBSD's TCP SACK implementation that had survived 27 years of expert review and automated fuzzing, across a total campaign cost of under $20,000. Anthropic held Mythos back from general release and stood up Project Glasswing to help selected defenders patch critical vulnerabilities before that capability leaks.
The honest question for every CISO now is not whether attackers will get Mythos-class capability, but whether the defensive stack will move at the same speed by the time they do. Ethiack built Hackian, an agentic AI pentester, to run continuous adversarial validation on the defender side, with reproducible proof of exploit for every finding at a false-positive rate below 0.5% (Ethiack-reported).
This guide covers what Mythos is, what Anthropic's Red Team actually found, why Anthropic held it back, what it means for the offensive-defensive equilibrium, the four enterprise implications, why Mythos-class capability will diffuse, and what CISOs and boards should do now. Every capability figure is attributed to a named source, primarily Anthropic Red Team's April 2026 publication and the Claude Mythos Preview System Card.
Key takeaways (TL;DR)
Claude Mythos Preview is Anthropic's restricted frontier AI model, released on 7 April 2026 for defensive cybersecurity use only under Project Glasswing. Its capabilities represent a category change in offensive security: autonomous zero-day discovery and exploit development across every major OS and browser, at costs orders of magnitude below equivalent human red-team work. The defender-side answer is machine-speed continuous validation, not slower manual pentesting cycles.
- Mythos made the AI-security asymmetry undeniable: Anthropic's Frontier Red Team used it to autonomously discover thousands of high- and critical-severity zero-day vulnerabilities across every major OS and browser (Anthropic Red Team, April 2026)
- Mythos scored 83.1% on the CyberGym vulnerability reproduction benchmark (up from Claude Opus 4.6's 66.6%) and saturated the Cybench cybersecurity CTF benchmark at 100% pass@1 (Claude Mythos Preview System Card, April 2026)
- On Anthropic's custom Firefox 147 zero-day exploitation benchmark, Mythos developed working exploits 181 times out of 250 attempts, versus Claude Opus 4.6's 2 successes across several hundred attempts
- Mythos identified a 27-year-old vulnerability in OpenBSD's TCP SACK implementation across roughly 1,000 scaffold runs at a total campaign cost of under $20,000; the specific run that found it cost under $50
- Human expert validators agreed exactly with Mythos's severity assessment in 89% of 198 manually reviewed vulnerability reports, and were within one severity level in 98% (Anthropic Red Team, April 2026)
- Project Glasswing is Anthropic's invite-only consortium: 12 launch partners (AWS, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks) plus over 40 additional organisations that build or maintain critical software infrastructure (roughly 50 in total)
- Anthropic committed $100 million in Claude API usage credits to Glasswing plus $4 million in donations to open-source security ($2.5M to Alpha-Omega and OpenSSF via the Linux Foundation, $1.5M to the Apache Software Foundation)
- Mythos-class capability was not designed intentionally; Anthropic states it emerged as a downstream consequence of general improvements in code, reasoning, and autonomy, which means equivalent capability will emerge from open-weight competitors and future frontier releases regardless of Anthropic's controls
- The exploitation window has already collapsed: Langflow's CVE-2026-33017 (CVSS 9.3) was exploited within 20 hours of disclosure with no public proof-of-concept; Marimo's CVE-2026-39987 (CVSS 9.3) was exploited in 9 hours 41 minutes (Sysdig Threat Research Team, April 2026)
- The defensive answer is machine-speed continuous validation: compress patch windows from months to hours, deploy continuous adversarial exposure validation (AEV) on the live application surface, and layer AIDR-style detection for exposures that cannot be patched immediately
The scope of this guide (and where Ethiack fits)
Because this guide is named after Mythos, one clarification is worth stating up front so readers do not carry the wrong assumption through the analysis. Ethiack tests the customer-side application layer, including AI-driven components (chatbots, RAG applications, AI agents deployed on customer infrastructure) and third-party integrations reachable from the customer's surface. Ethiack does NOT test AI models themselves (weights, training data, model internals) or perform product-conformity assessment. Organisations shipping high-risk AI systems under the EU AI Act should pair Ethiack with an AI-system-testing specialist for the model-layer obligation.
Ethiack's role in the Mythos-response stack is defender-side: continuous machine-speed adversarial validation of customer applications so those applications are resilient to whatever Mythos-class capability an attacker deploys against them. Not offensive-AI testing.
What is Claude Mythos?
Claude Mythos Preview is Anthropic's most capable frontier model to date, published on 7 April 2026 with a 244-page System Card and a Frontier Red Team blog post at red.anthropic.com. Two things about the release make it a first in Anthropic's history. First, the model was published without general commercial availability, a decision Anthropic has explicitly tied to Mythos's cybersecurity capabilities. Second, it was the first Anthropic model evaluated under version 3.3 of the Responsible Scaling Policy.
When was Mythos released?
Claude Mythos Preview was announced on 7 April 2026. On the same day, Anthropic launched Project Glasswing as a coordinated defensive initiative. The System Card and the Frontier Red Team's cybersecurity capability post were both published simultaneously, an unusual practice for a model not being offered to the general public.
How is Mythos different from prior Claude models?
The System Card reports that Mythos shows step-change improvements in mathematics, long-context reasoning, software engineering, and cybersecurity compared to Claude Opus 4.6. On specific published benchmarks, Mythos scored 83.1% on the CyberGym vulnerability-reproduction benchmark (up from Opus 4.6's 66.6%) and 100% pass@1 on Cybench, saturating a benchmark that draws from 40 CTF challenges across four major competitions. On Anthropic's custom Firefox 147 zero-day exploitation benchmark, Mythos developed working exploits 181 times out of 250 attempts, versus Opus 4.6's 2 successes across several hundred attempts.
Where does Mythos rank against other frontier models?
The UK AI Security Institute (AISI) published a public evaluation of Mythos Preview's cyber capabilities. AISI reports that Mythos succeeded on 73% of expert-level CTF tasks (a tier of difficulty no model completed before April 2025), and became the first model to complete AISI's 32-step end-to-end cyber-attack range on three of ten attempts. AISI found Mythos comparable to GPT-5.4 on individual cyber tasks but stronger at stringing steps into full intrusions. Mythos outperformed all previous frontier models, including Claude Opus 4.6 and GPT-5, across technical, apprentice, and practitioner levels.
Is Claude Mythos publicly available?
No. Anthropic held Mythos back from general release specifically because of its cybersecurity implications. Access is restricted to Project Glasswing participants, available via the Claude API, Amazon Bedrock, Google Cloud Vertex AI, and Microsoft Foundry, priced at $25 per million input tokens and $125 per million output tokens (Project Glasswing announcement, Anthropic, April 2026).
The Mythos capability data (what Anthropic's Red Team actually found)
Anthropic's Frontier Red Team publication (Nicholas Carlini, Newton Cheng, and colleagues, 7 April 2026) provides the primary evidence for Mythos's cybersecurity capabilities. What follows is a summary of the specific findings, all sourced from that publication and the accompanying System Card.
How the red-team assessment was run
Anthropic's Frontier Red Team used a simple agentic scaffold. An isolated container ran the project under test and its source code. Claude Code with Mythos Preview was invoked, prompted with a paragraph amounting to 'please find a security vulnerability in this program.' Mythos then agentically experimented: reading the code to hypothesise vulnerabilities, running the project to confirm or reject its suspicions, adding debug logic or using debuggers as needed, and finally outputting either that no bug exists, or a bug report with a proof-of-concept exploit and reproduction steps. To increase diversity, Anthropic asked each Mythos agent to focus on a different file; a final Mythos agent then reviewed and confirmed each bug report.
The capability evidence table
The following table summarises the specific findings that Anthropic has published. All values are directly from the Anthropic Red Team publication or the Mythos Preview System Card, both dated 7 April 2026, unless otherwise noted.
The 27-year OpenBSD vulnerability
One case study captures the qualitative shift. OpenBSD is one of the most security-hardened operating systems ever built; it is frequently used in firewalls, routers, and core internet services precisely because it has been scrutinised harder and longer than almost any codebase on earth. In April 2026, Mythos Preview identified a denial-of-service vulnerability in OpenBSD's TCP SACK implementation, an integer overflow condition that allows a remote attacker to crash any OpenBSD host responding over TCP. The bug had been in the code for 27 years, added when OpenBSD introduced SACK in 1998, and survived decades of expert review and automated fuzzing. Mythos found it across roughly 1,000 scaffold runs at a total campaign cost of under $20,000; the specific winning run cost under $50.
The severity-validation programme
Anthropic contracted professional security contractors to manually validate every high-severity bug report before disclosure to maintainers. Across 198 manually reviewed reports, expert contractors agreed exactly with Mythos's severity assessment in 89% of cases, and were within one severity level in 98%. Anthropic states this validation rate provides confidence that its extrapolated 'thousands' figure is grounded, though independent auditing is limited by the fact that Mythos itself is not publicly available.
Why Anthropic held it back: Project Glasswing
Project Glasswing, named after the Greta oto Glasswing Butterfly (an insect that hides in plain sight), is Anthropic's initiative to 'secure the world's most critical software for the AI era.' Its 12 launch partners are AWS, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Access is extended to over 40 additional organisations that build or maintain critical software infrastructure (roughly 50 in total). Partners use Mythos Preview for defensive security work, and Anthropic has committed to sharing what it learns with the wider industry.
Anthropic committed $100 million in Claude API usage credits for Glasswing participants, plus $4 million in cash donations to open-source security ($2.5 million to Alpha-Omega and OpenSSF via the Linux Foundation, and $1.5 million to the Apache Software Foundation). Access is priced at $25 per million input tokens and $125 per million output tokens for participants using the model beyond their credit allocation. The first public report on Glasswing findings is expected in early July 2026.
Anthropic frames the release as 'a watershed moment for security' (their words, cited as their own). The company has stated it does not plan to make Mythos Preview generally available; the model exists specifically to give critical-software defenders a preparation window before equivalent capability becomes broadly accessible.
What Mythos means for the offensive-defensive equilibrium
For nearly a decade the security-research community debated when AI would meaningfully alter the offensive-defensive equilibrium in cybersecurity. The Mythos evidence largely settles that debate. Anthropic itself frames the shift plainly: 'the same improvements that make the model substantially more effective at patching vulnerabilities also make it substantially more effective at exploiting them. Anthropic's Frontier Red Team argues that "the advantage will belong to the side that can get the most out of these tools," and that "in the short term, this could be attackers, if frontier labs aren't careful about how they release these models. In the long term, we expect it will be defenders who will more efficiently direct resources and use these models to fix bugs before new code ever ships." (Carlini, Cheng and colleagues, Anthropic Frontier Red Team, 7 April 2026)
Three specific asymmetries emerge from the Mythos capability data. First, speed: Anthropic reports that Mythos writes exploits in hours that expert penetration testers said would have taken weeks to develop. Meanwhile, most enterprise patch SLAs remain calibrated to a 30-day cycle. Second, scale: Mythos runs as thousands of parallel agents against the same codebase, with each independent attempt costing tens to hundreds of dollars in compute. Human red-team work does not run at that concurrency. Third, cost: Anthropic's OpenBSD campaign, which surfaced a 27-year zero-day plus several dozen other findings, cost under $20,000 in total compute. Equivalent human red-team engagements run to six figures.
The consensus practical answer across analyst coverage of Mythos, from Cloud Security Alliance research notes through independent commentary, is that defensive workflows must shift from human speed to machine speed. Not to replace human judgement, but to match the tempo of AI-assisted offensive capability. Continuous adversarial validation on the live application surface is the mechanism most commonly cited.
Attacker time-to-exploit collapses to hours while enterprise patch SLAs remain at 30 days. Adversarial exposure validation closes the gap at machine speed.The four security implications for enterprises
1. Exploitation windows compress from days to hours
The Langflow and Marimo incidents in March and April 2026 illustrate the shift. Langflow's CVE-2026-33017 (CVSS 9.3), a code-injection vulnerability, was exploited within 20 hours of public disclosure with no public proof-of-concept in existence. Marimo's CVE-2026-39987 (CVSS 9.3), a pre-authentication RCE, was exploited in 9 hours and 41 minutes; the Sysdig Threat Research Team observed a complete credential-theft operation in under three minutes (Sysdig, April 2026). Both attackers built working exploits directly from the advisory description. This exploitation pattern, advisory-driven and PoC-free, is the shape of the new normal, and the CISA KEV catalogue's median time-to-listing has been trending toward days rather than weeks
2. 30-day patch SLAs no longer match the threat model
For decades, most enterprise patch programmes have targeted 30 days from CVE disclosure to production deployment for critical severity vulnerabilities. That target was built for a world where turning a CVE into a working exploit took a skilled researcher days to weeks. Anthropic's N-day exploit demonstrations show Mythos writing a functional Linux kernel privilege-escalation exploit from just a CVE identifier and a git commit hash, at under $1,000 in API cost per exploit, in a matter of hours. Patch SLAs that once looked prudent now look permissive.
3. The AI-service surface introduces attack paths traditional VM does not cover
Enterprise adoption of AI-driven services (customer-facing chatbots, RAG applications, agentic workflows) has grown faster than the security-testing methodology for them. Prompt injection, tool-use hijacking, and RAG-poisoning are attack categories that traditional vulnerability-management taxonomies do not cover cleanly. The exploitation window Mythos exposes for classic memory-safety bugs applies equally, and possibly more sharply, to the AI-service layer, where the attack surface is newer and less-tested. See adversarial exposure validation for the defender-side mechanism.
4. Social engineering scales because personalisation becomes trivial
Mythos-class capability makes personalised spear-phishing content trivial to generate, changing the economics of social engineering. The categorical shift is not that AI models can write phishing emails; earlier models could already do that. It is that the same models that can autonomously discover technical vulnerabilities can also personalise social-engineering pretexts at scale, coordinating multi-channel attack sequences that no human team of similar size could sustain. The implication for enterprise defence is that identity monitoring and identity-aware detection now sit at the same tier of importance as vulnerability patching.
Why Mythos-class capability will diffuse (the structural argument)
The most important sentence in Anthropic's Red Team publication may be the one addressing intent: 'We did not explicitly train Mythos Preview to have these capabilities. Rather, they emerged as a downstream consequence of general improvements in code, reasoning, and autonomy.' If Mythos's cyber capability was not designed, it means the same scaling dynamics that produced it will produce equivalents elsewhere. The 'watershed moment' is not the Mythos release itself; it is the confirmation that frontier scaling produces nation-state-grade offensive capability as a byproduct of general improvement.
Three specific diffusion vectors follow. First, open-weight competitors are already scaling on similar trajectories and will replicate Mythos-adjacent capability at lower cost within months to quarters. Second, adversary scaffolding: attackers can extract Mythos-like uplift from lower-tier models by investing in better scaffolds and prompting strategies, without waiting for equivalent model weights. Third, continued frontier scaling: the next generation of frontier models is already in training, and there is no plausible policy lever that halts progress across all developers simultaneously.
For CISOs, this reframes the risk. The question is not whether Mythos-class capability will reach attackers, but when, and whether the defensive stack will move at the same speed by the time it does. Anthropic's own Project Glasswing framing accepts this reasoning explicitly: Glasswing exists to give critical-infrastructure defenders a preparation window before equivalent capability becomes broadly available.
What CISOs and boards should do now (7-step response)
The following seven-step operational response synthesises Anthropic's own recommendations for defenders with the practical AEV-side framing. Anthropic's Red Team publication contains its recommendations in full; the following combines those with the machine-speed continuous validation architecture that produces the operational evidence CISOs need.
- Adopt frontier language models for defensive work today. Anthropic explicitly notes that currently available frontier models (like Claude Opus 4.6) remain extremely competent at finding vulnerabilities, even if less effective at creating exploits. Companies that have not yet adopted language-model-driven bug-finding tools 'could likely find many hundreds of vulnerabilities simply by running current frontier models' (Anthropic Red Team, April 2026). Waiting for Mythos-class access is not the right call.
- Compress the patch window. Anthropic recommends tightening patching enforcement windows, enabling auto-update wherever possible, and treating dependency bumps that carry CVE fixes as urgent rather than routine maintenance. Measure current patch SLA, target hours-to-days for critical CVEs on internet-facing surface, and automate wherever governance allows.
- Deploy continuous adversarial exposure validation (AEV) against the live application surface. AEV produces exploitability evidence at machine speed, catching what an attacker with Mythos-class tooling could exploit on your specific surface right now, not what a scanner thinks is theoretically possible. This replaces the annual pentest snapshot with a continuous evidence stream mapped to specific assets and dated per finding.
- Layer AIDR-style detection and containment for exposures that cannot be patched immediately. Real-time AI-augmented detection, identity monitoring, and attack-path reconstruction reduce the window between successful exploitation and defender response. The workflow assumes some Mythos-class attacks will land; the goal is minimising blast radius.
- Harden the AI-service surface specifically. Prompt-injection defences, tool-use guardrails, and RAG-poisoning detection are now first-tier controls, not future work. The AI-service layer is where enterprise adoption has outpaced security testing methodology.
- Update third-party and supply-chain risk posture. Mythos-grade adversary tradecraft applies to supply-chain attacks as much as direct vulnerability discovery. Vendor risk assessments should now account for the possibility that any of your vendors' codebases contain Mythos-discoverable vulnerabilities.
- Brief the board. Mythos is a board-level risk category, not a SecOps line item. The narrative for board risk committees needs to cover the capability data, the diffusion argument, the current readiness gap, and the specific capital and staffing requirements to close it.

Common misconceptions about Mythos
Misconception 1: 'Basic hygiene no longer matters'
False. Mythos exploits classic vulnerability categories (memory safety, injection, authentication bypass, race conditions) at machine speed, but the patched systems remain patched. Hardened basics still eliminate the majority of exploitation paths. What has changed is the speed at which unpatched exposures become exploited exposures, not whether patched systems remain safe.
Misconception 2: 'CVSS is dead'
False. CVSS is still the industry-standard severity signal and remains the starting point for prioritisation. What Mythos changes is not the value of CVSS but the value of layering supplementary signals on top: exploit-prediction scoring (EPSS), CISA KEV listings, and, where possible, proof of exploit against the specific environment. CVSS is insufficient, not obsolete.
Misconception 3: 'Manual pentesting is obsolete'
False. Human red teams remain valuable for the deep, creative, business-context scenarios that AI does not handle well: attack chains that require insider knowledge, adversarial reasoning about specific customer workflows, and the judgement calls that scoping a serious engagement requires. What changes is that manual pentesting cannot alone provide continuous evidence at Mythos-class tempo. Manual and continuous now complement each other rather than substituting.
Misconception 4: 'Only AI can defend against AI'
False. Hardened basics plus compensating controls plus rapid patching stop many Mythos-class attacks, especially where the attacker relies on unpatched CVEs against exposed surface. AI amplifies defensive productivity, but the fundamentals of defence-in-depth, least privilege, and network segmentation remain effective. The right framing is 'AI-augmented defence,' not 'AI-only defence.'
Misconception 5: 'Mythos is only about vulnerability discovery'
False. Vulnerability discovery is the most measurable Mythos capability, but the practical implications extend to social engineering (personalised spear-phishing at scale), supply-chain tradecraft (Mythos-scale analysis of dependencies), and coordinated multi-channel campaigns. Enterprise defensive planning must address all three vectors.
Misconception 6: 'We're fine because we're not on Glasswing's list'
False. Being outside the Glasswing consortium is not a safety indicator. The diffusion argument (that Mythos-class capability will reach attackers through open-weight competitors, adversary scaffolding, and future frontier releases) means every organisation with an external surface is in the defensive perimeter, regardless of Anthropic's partner list.
Defensive approaches compared
No single defensive approach fully answers Mythos. The mature response layers several. What follows is a tradeoff-framed summary of the six approaches most commonly cited in Mythos-related analyst coverage.
Adversarial exposure validation (AEV)
Continuous machine-speed validation of what attackers can actually exploit on the live application surface. Solves the 'catch me up to attacker tempo' problem by running validation continuously rather than per-engagement. Where it falls short: does not test AI model internals (weights, training data), does not replace deep manual red-team work on complex bespoke scenarios.
Breach and attack simulation (BAS)
Scripted playbook execution mapped to MITRE ATT&CK for testing control efficacy against known adversary tradecraft. Solves the 'do our controls actually catch the tactics we care about' problem. Where it falls short: BAS runs scripted playbooks, not adaptive exploit discovery, so it cannot surface Mythos-class novel exploit chains that were not in the playbook set.
AI Detection and Response (AIDR)
Real-time AI-augmented SOC triage, investigation, and containment. Solves the 'shrink the window between successful exploitation and defender response' problem. Where it falls short: AIDR is response-side rather than prevention-side; it does not stop the initial compromise, only reduces blast radius after.
Manual pentesting and red team
Deep human-driven testing on specific scenarios. Solves the 'exercise creative adversarial thinking about our specific environment' problem. Where it falls short: slow relative to Mythos-class velocity; engagement-bounded; cannot provide continuous evidence between tests.
Coordinated vulnerability disclosure (CVD)
Receives external vulnerability reports through a structured process. Solves the 'give responsible researchers a channel and give ourselves ground truth on what is being found in our software' problem. Required by the EU Cyber Resilience Act. Where it falls short: reactive, not proactive; complements AEV rather than substituting.
Compensating controls
Identity monitoring, network segmentation, exception governance, and blast-radius reduction. Solves the 'reduce risk while patch cadence catches up to reality' problem. Where it falls short: does not close the vulnerability, only reduces its exploitability; requires disciplined governance to prevent exception debt from accumulating.
How Ethiack helps enterprises defend at machine speed
Applying the scope guardrail from earlier in this guide: Ethiack tests the customer-side application layer, including AI-driven components (chatbots, RAG applications, AI agents on customer infrastructure) and third-party integrations reachable from the customer's surface. Ethiack does NOT test AI models themselves or perform product-conformity assessment. Within that scope, Hackian, the agentic AI pentester, runs continuous adversarial exposure validation on the customer surface. Every validated vulnerability lands with reproducible proof of exploit; there are no black-box outputs the defender has to trust unverified. Ethiack's false-positive rate below 0.5% (Ethiack-reported) makes the output actionable at engineering tempo, and CEGID moved from checklist-based annual pentesting to autonomous ethical hacking with Ethiack, reporting €12M+ in risk prevented across 2,000+ assets in 20+ companies (Ethiack-reported).
The platform is designed for regulated European institutions and processes on EU compute (engine servers in Belgium). Compliance reporting is mapped to DORA, NIS2, ISO 27001, and the EU AI Act Article 15 via Ethiack compliance reporting. This positioning matters for eurozone banks navigating the ECB's AI Cybersecurity Action Plan and its 31 October 2026 supervisory response deadline, and for essential and important entities under NIS2 needing continuous exposure evidence.
In the Mythos-response stack, Ethiack sits on the continuous defender-side validation layer. Not an offensive-AI product. Not a model-layer testing product. A machine-speed defensive validation product that gives CISOs the continuous evidence stream their board, auditor, and supervisor now expect.
See what a Mythos-class adversarial test finds on your AI services
Ethiack runs continuous adversarial validation on your application surface, including AI-driven components, with reproducible proof of exploit and EU compute. Book a demo aligned to your machine-speed defence plan, or run a free external test to see the surface as an attacker would.
Frequently asked questions about Mythos
What is Claude Mythos?
Claude Mythos is Anthropic's restricted frontier AI model, released as Claude Mythos Preview on 7 April 2026. It shows step-change improvements in mathematics, long-context reasoning, software engineering, and cybersecurity compared to Claude Opus 4.6. It is not publicly available; access is limited to Project Glasswing, an invite-only consortium of 12 launch partners plus over 40 additional organisations (roughly 50 in total).
What are the security implications of Claude Mythos?
Mythos demonstrates that frontier AI can autonomously discover thousands of high- and critical-severity zero-day vulnerabilities across every major OS and browser (Anthropic Red Team, April 2026). The implication is a category change in the offensive-defensive equilibrium: attackers can move at machine speed with sub-$1,000-per-exploit economics, while most enterprise patch SLAs remain at 30 days. The defender-side answer is machine-speed continuous validation.
Is Claude Mythos publicly available?
No. Anthropic held Mythos back from general release specifically because of its cybersecurity capabilities. Access is restricted to Project Glasswing, an invite-only consortium of 12 launch partners (AWS, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks) plus over 40 additional critical-infrastructure organisations (roughly 50 in total).
What is Project Glasswing?
Project Glasswing is Anthropic's invite-only industry consortium for Claude Mythos Preview. Named after the Greta oto Glasswing Butterfly, its purpose is to help selected defenders find and fix vulnerabilities in critical software before Mythos-class capability leaks to attackers. Anthropic committed $100 million in Claude API usage credits plus $4 million in donations to open-source security (Anthropic, April 2026).
How many vulnerabilities did Claude Mythos find?
Anthropic reports thousands of high- and critical-severity vulnerabilities discovered during Mythos Preview evaluation, with responsible disclosure ongoing. Human expert validators agreed exactly with Mythos's severity assessment in 89% of 198 manually reviewed reports and were within one severity level in 98% (Anthropic Red Team, April 2026). Over 99% of the vulnerabilities found have not yet been patched, limiting public disclosure.
Can Claude Mythos write working exploits?
Yes. On Anthropic's Firefox 147 zero-day exploitation benchmark, Mythos developed working exploits 181 times out of 250 attempts, versus Claude Opus 4.6's 2 successes across several hundred attempts. Mythos also scored 83.1% on the CyberGym vulnerability reproduction benchmark. It has autonomously written full RCE and privilege-escalation exploit chains across FreeBSD, Linux, and multiple web browsers (Anthropic Red Team, April 2026).
What was the 27-year OpenBSD vulnerability Mythos found?
Mythos identified a denial-of-service vulnerability in OpenBSD's TCP SACK implementation, an integer overflow that allows a remote attacker to crash any OpenBSD host responding over TCP. The bug had survived 27 years of expert review and automated fuzzing. Mythos found it across roughly 1,000 scaffold runs at a total campaign cost of under $20,000; the specific winning run cost under $50 (Anthropic Red Team, April 2026).
Will Claude Mythos capability leak to attackers?
Consensus across analyst coverage is that Mythos-class capability will diffuse regardless of Anthropic's controls, through open-weight competitors already scaling on similar trajectories, through operator scaffolding on lower-tier models, and through continued frontier scaling. Anthropic itself states Mythos's cyber capability emerged as a downstream consequence of general improvements in code, reasoning, and autonomy, which means equivalent capability is not Anthropic-specific.
How should CISOs respond to Claude Mythos?
Compress the patch window from months to hours where governance allows; deploy continuous adversarial exposure validation (AEV) against the live surface; layer AIDR-style compensating controls; harden AI-service surfaces specifically; update supply-chain posture; adopt current frontier models for defensive work today; and brief the board on readiness gaps. Anthropic's own defensive recommendations (April 2026) provide the operating template.
What patch cadence works in a Mythos world?
Anthropic's N-day demonstrations show Mythos writing functional Linux kernel privilege-escalation exploits from just a CVE identifier at under $1,000 in API cost. That collapses the historical patch-timing window: enterprises should target hours-to-days for critical CVEs on internet-facing surface, enable auto-update wherever possible, and treat dependency bumps that carry CVE fixes as urgent rather than routine.
How does Mythos compare to GPT-5 for cybersecurity?
The UK AI Security Institute (AISI) tested Mythos against previous frontier models on cyber CTF challenges. Mythos succeeded on 73% of expert-level CTF tasks and became the first model to complete AISI's 32-step end-to-end cyber-attack range. AISI found Mythos comparable to GPT-5.4 on individual cyber tasks but stronger at stringing steps into full intrusions (AI Security Institute, April 2026).
Is the Mythos threat about vulnerability discovery, social engineering, or both?
Both, and neither exclusively. Mythos-class capability accelerates vulnerability discovery and exploit development (Anthropic Red Team, April 2026), makes personalised spear-phishing content trivial to generate, and enables supply-chain tradecraft at scale. Enterprise defence must address all three vectors, not treat Mythos as a memory-safety story alone.
Does Ethiack test Claude Mythos or other AI models?
No. Ethiack tests the customer-side application layer, including AI-driven components (chatbots, RAG apps, AI agents on customer infrastructure) and third-party integrations reachable from the customer's surface. Ethiack does not test AI models themselves (weights, training data, model internals). For model-layer testing, pair Ethiack with an AI-system-testing specialist.
How does adversarial exposure validation help against Mythos-class attackers?
AEV runs continuous adaptive AI-driven attacks against the live application surface, producing reproducible proof of exploit for every finding at a false-positive rate below 0.5% (Ethiack-reported). It is the defender-side counterpart to Mythos-class offensive capability: machine-speed validation of what an attacker with Mythos-class tools could exploit in your specific environment right now.
