Anthropic launched Project Glasswing on 7 April with technology, finance, and infrastructure partners. Selected defenders received access to Claude Mythos Preview, an unreleased model that Anthropic said had unusually strong ability to find and exploit software vulnerabilities.
Why access was limited
The same capability can help defenders or attackers, which is why access was restricted. Even for defenders, discovering thousands of possible flaws creates a second challenge: someone must verify each report, contact the right maintainer, prepare a safe patch, and deliver it to users.
Find a possible weakness.
Prove the flaw and understand its reach.
Build, test, publish, and deploy a safe fix.
What ordinary organisations could learn
Most organisations did not need access to the frontier model to apply the lesson. They could improve their software inventory, name an owner for every critical dependency, subscribe to vendor advisories, and make emergency patching a rehearsed process rather than an improvised one.
Key takeaways
- Unsupported software has an exit plan.
- Critical advisories reach the right person.
- Maintainers have a safe contact channel.
- Patch status can be verified by asset, not guessed from an average.
Glasswing made vulnerability discovery look faster. It also made the slow parts of security more visible. Verification, disclosure, repair, testing, and deployment still depended on people and healthy maintenance systems.
