Anthropic's Unreleased Claude Mythos AI Discovered Decades-Old Linux and OpenBSD Bugs, Launches Project Glasswing

Anthropic's Unreleased Claude Mythos AI Discovered Decades-Old Linux and OpenBSD Bugs, Launches Project Glasswing

N
News Editor 01
2026-07-09 00:28:14
Anthropic’s unreleased Claude Mythos AI scored 83.1% on Cybergym, autonomously discovering thousands of zero-day vulnerabilities including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg bug. The company launched Project Glasswing, a defensive coalition with 11 founding partners and up to $100M in AI usage credits.
AI securityzero-day vulnerabilityClaude MythosProject GlasswingAnthropic

Anthropic on April 7, 2026, publicly unveiled its unreleased frontier AI model, Claude Mythos Preview, which demonstrated extraordinary cybersecurity capabilities during internal testing. According to official disclosures, Mythos autonomously discovered thousands of high-severity zero-day vulnerabilities across all major operating systems and web browsers, including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg bug that had previously evaded human audits and millions of automated tests.

Unprecedented AI Security Capabilities

Mythos achieved 83.1% on the Cybergym cybersecurity benchmark (vs. 66.6% for the previous Claude Opus 4.6), 93.9% on SWE-bench Verified (vs. 80.8%), and 77.8% on SWE-bench Pro (vs. 53.4%). Notably, the model required no specialized cybersecurity training; it leveraged broad advances in reasoning, multi-step planning, and autonomous agent behavior. Given a target codebase in an isolated container, Mythos reads source code, hypothesizes memory safety flaws, compiles and runs the software, employs debuggers like Address Sanitizer, ranks files by vulnerability likelihood, and produces validated bug reports with functional proof-of-concept exploits.

One of the most striking examples: a 27-year-old integer overflow vulnerability in the OpenBSD TCP SACK handler—allowing remote denial-of-service via malicious packets—was autonomously discovered after approximately 1,000 runs at a total cost under $20,000. A 16-year-old FFmpeg H.264 encoding bug survived more than 5 million automated tests and multiple audits before Mythos detected it.

Project Glasswing: A Defensive Coalition

Recognizing the dual-use nature of such capabilities, Anthropic simultaneously launched Project Glasswing, a defensive cybersecurity coalition with 11 founding partners: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. The program offers up to $100 million in Mythos usage credits to defenders for vulnerability discovery and patch development.

Anthropic also pledged $4 million to open-source security: $2.5 million to the Alpha-Omega project via the Linux Foundation's OpenSSF, and $1.5 million to the Apache Software Foundation. The company noted that less than 1% of identified bugs have been fully remediated so far, and is coordinating responsible disclosure with cryptographic SHA-3 commitments for unpatched issues.

Risks and Future Plans

Anthropic acknowledged that state actors (China, Iran, North Korea, Russia) and criminal groups could soon acquire similar capabilities, creating a period of transitional turbulence before defenders fully integrate the technology. Future Claude Opus releases will include safeguards to detect and block dangerous cybersecurity outputs, and a verified cyber vetting program for security professionals is planned. A public report on partner findings and remediated vulnerabilities is expected within 90 days.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.