On April 9, 2026, Anthropic revealed that its unreleased Claude Mythos Preview AI model has achieved a breakthrough in autonomous vulnerability discovery. Scoring 83.1% on the Cybergym cybersecurity benchmark, the model identified thousands of zero-day vulnerabilities across all major operating systems and web browsers. Most notably, it uncovered a 27-year-old integer overflow in OpenBSD's TCP SACK handler and a 16-year-old H.264 bug in FFmpeg—flaws that had survived millions of automated tests and multiple human audits.
Capability Leap: From $80K to $20K Cost for Zero-Day Discovery
Claude Mythos represents the largest single-model capability jump in frontier AI history, according to Anthropic. Compared to its predecessor Claude Opus 4.6, Mythos scored 93.9% vs. 80.8% on SWE-bench Verified, 77.8% vs. 53.4% on SWE-bench Pro, and 56.8% vs. 40.0% on Humanity's Last Exam without tools. The model does not require specialized cybersecurity training; its gains come from improved reasoning, multi-step planning, and autonomous agent behavior.
In practical tests, Mythos generated 181 full shell exploits and 29 register control cases against Firefox 147's JavaScript engine, while Opus 4.6 produced only 2 shell exploits. It also built functional Linux kernel privilege escalation chains from user to root, filtering 100 recent CVEs down to 40 exploitable candidates and successfully exploiting more than half. Human validators reviewed 198 vulnerability reports and agreed with the model's severity ratings in 89% of cases, with 98% agreement within one severity level.
The 27-year-old OpenBSD bug: a subtle integer overflow allowing remote attackers to crash any host via malicious packets. Mythos found it after approximately 1,000 runs at a total cost under $20,000. The 16-year-old FFmpeg error had survived over five million automated tests and multiple audits before detection.
Project Glasswing: $100M Credit Pool with 11 Founding Partners
To turn these capabilities toward defense, Anthropic launched Project Glasswing on April 7, 2026, committing up to $100 million in Mythos usage credits for defenders. Founding partners include Amazon Web Services, Apple, Broadcom, Cisco, Crowdstrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks, plus over 40 additional critical software organizations. The company also donated $4 million to open-source security: $2.5 million to Alpha-Omega via OpenSSF and $1.5 million to Apache Software Foundation.
Currently, less than 1% of identified bugs have been fully patched. Anthropic follows responsible disclosure with SHA-3 cryptographic commitments and a 90-plus-45-day window before publishing full details. Already disclosed is CVE-2026-4747, a 17-year-old unauthenticated root remote code execution in FreeBSD's NFS server.
Anthropic acknowledged that AI tools like Mythos lower barriers for vulnerability discovery and exploitation, warning of short-term risks from state actors (China, Iran, North Korea, Russia) and criminal groups. The company plans to embed cybersecurity safeguards in future Claude Opus versions and introduce a cyber-vetting program for verified security professionals. A public report on partner findings and remediated vulnerabilities is expected within 90 days.

