Anthropic's Unreleased Claude Mythos Preview Discovers Thousands of Zero-Day Flaws, Launches $100M Project Glasswing

Anthropic's Unreleased Claude Mythos Preview Discovers Thousands of Zero-Day Flaws, Launches $100M Project Glasswing

N
News Editor 01
2026-07-09 11:52:13
Anthropic's unreleased Claude Mythos Preview scored 83.1% on Cybergym, autonomously finding thousands of zero-day vulnerabilities across every major OS and browser, including a 27-year-old OpenBSD bug. The company launched Project Glasswing with 11 founding partners and up to $100M in AI credits to bolster defenses.
AI securityzero-day vulnerabilitiesAnthropicClaudeProject Glasswing

Anthropic revealed the full capabilities of its unreleased Claude Mythos Preview model on April 7, 2026, showcasing an unprecedented ability to autonomously discover and exploit unknown software flaws. The model identified thousands of high-severity zero-day vulnerabilities across every major operating system and web browser, outperforming both human experts and prior AI systems. In response, the company launched Project Glasswing, a defensive cybersecurity coalition backed by up to $100 million in AI usage credits for defenders.

Benchmark Dominance

Claude Mythos Preview scored 83.1% on the Cybergym cybersecurity benchmark, compared to 66.6% for its predecessor Claude Opus 4.6. On SWE-bench Verified, it achieved 93.9% (Opus 4.6: 80.8%), while on SWE-bench Pro it posted 77.8% (Opus 4.6: 53.4%) – a 24-point gap. Even without tools, it scored 56.8% on Humanity's Last Exam, versus 40.0% for Opus 4.6. These gains stem from broader advances in reasoning, multi-step planning, and autonomous agentic behavior, not specialized security training.

Decades-Old Bugs Found in Hours

Operating inside isolated containers, the model reads source code, forms hypotheses about memory-safety flaws, compiles and runs software, uses debuggers like Address Sanitizer, ranks files by vulnerability likelihood, and produces validated bug reports with working proof-of-concept exploits. A 27-year-old integer overflow in OpenBSD's TCP SACK – allowing remote crashes via crafted packets – was found after roughly 1,000 runs at a cost under $20,000. A 16-year-old bug in FFmpeg's H.264 decoder, which had survived over five million automated tests and multiple audits, was caught by Mythos in hours.

Browser tests were particularly telling. On the Firefox 147 JavaScript engine, Mythos produced 181 full shell exploits and 29 register-control cases, while Claude Opus 4.6 managed only two shell exploits. The model also built working Linux kernel privilege-escalation chains, filtering 100 recent CVEs to 40 exploitable candidates and successfully exploiting more than half. Human validators reviewed 198 reports and agreed with Mythos' severity ratings 89% of the time, with 98% agreement within one level.

Project Glasswing: Defense First

Fewer than 1% of the identified bugs have been fully patched. Anthropic is coordinating responsible disclosure, using cryptographic SHA-3 commitments for unpatched issues and following a 90-plus-45-day timeline. Named examples include CVE-2026-4747, a 17-year-old FreeBSD NFS server remote code execution bug granting full root access. To steer these capabilities toward defense before similar tools become widely available, Anthropic launched Project Glasswing on April 7. Founding partners include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. Access is being extended to over 40 additional critical software organizations.

Anthropic committed $4 million in open-source security donations: $2.5 million to Alpha-Omega via the OpenSSF (Linux Foundation) and $1.5 million to the Apache Software Foundation.

Risks and Mitigation

The company acknowledged that AI tools like Mythos lower the barrier for vulnerability discovery and exploitation, highlighting near-term risks from state actors (China, Iran, North Korea, Russia) and criminal groups if similar capabilities spread without controls. Anthropic described a period of “transitional turmoil” before defenders fully integrate the technology. Upcoming Claude Opus releases will include safeguards to detect and block dangerous cybersecurity outputs. A Cyber Verification Program for vetted professionals is planned, and a public report on partner findings and patched vulnerabilities is expected within 90 days.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.