Anthropic said its restricted Claude Mythos Preview model has uncovered more than 10,000 high or critical software vulnerabilities in a single month, a pace patching teams cannot match.
Project Glasswing Reveals 10,000 Flaws
The figure comes from an initial progress report on Project Glasswing, a cybersecurity initiative Anthropic launched in April to harden critical software before frontier AI can be turned against it. The company deployed the unreleased model to roughly 50 trusted partners.
Most partners reported finding hundreds of serious bugs in their own code, with several seeing detection rates jump more than tenfold.
Cloudflare scanned its critical systems and surfaced about 2,000 flaws, 400 of them rated high or critical. Mozilla fixed 271 vulnerabilities in Firefox 150, more than ten times what the same team produced for the previous release using an earlier Claude model.
To test the model on a wider field, Anthropic pointed it at more than 1,000 open-source repositories, where it flagged 23,019 issues, with 6,202 estimated as high or critical severity.
Also Read: XRP Eyes $1.50 Breakout As Exchange Supply Tightens
Why Mythos Findings Worry Researchers
Six independent security firms reviewed 1,752 of those high or critical reports and validated 90.6% as genuine, undercutting skeptics who expected a wave of false positives.
One discovery stood out for its reach. Mythos identified a certificate-forgery flaw in the wolfSSL cryptography library, logged as CVE-2026-5194, and built a working exploit that could spawn fake banking sites no browser would warn against.
The bottleneck has now shifted. Discovery is no longer the hard part. Patching is.
A serious bug takes about two weeks to fix on average, and some open-source maintainers have asked Anthropic to slow its disclosures so they can keep pace. Anthropic also warned that no company, including itself, has built safeguards reliable enough to stop malicious use of a Mythos-level model.
Project Glasswing began in April with Anthropic committing up to $100 million in model credits and roughly $4 million for open-source security work, betting that hardening code now gives defenders an edge before similar capabilities spread without controls.
Read Next: Bitcoin Rally Hits A Ceiling As Sellers Guard $77,050 Resistance





