Anthropic Built an AI That Finds Bugs No Human Can. Now Two Governments Are Scrambling.
Anthropic Built an AI That Finds Bugs No Human Can. Now Two Governments Are Scrambling.
On April 7, Anthropic announced Project Glasswing, a controlled-access program built around an unreleased model called Claude Mythos Preview. The model has already found thousands of zero-day vulnerabilities across every major operating system and web browser. Some of those flaws had sat unnoticed for decades. The 27-year-old bug in OpenBSD, an OS trusted to guard firewalls and critical infrastructure, is the one getting the most attention. An attacker could remotely crash any machine running it just by connecting. The fix is now live. The discovery? Entirely autonomous, zero human steering.
There’s also the 16-year-old vulnerability in FFmpeg, the video encoding library that’s essentially everywhere. Automated testing tools had exercised that exact line of code five million times. Not once did they catch it. Mythos Preview did. And then there’s the Linux kernel chain: the model found several separate vulnerabilities and linked them together to escalate from regular user access to full machine control, all on its own.
Why Anthropic Refuses to Release It
This is where the story gets unusual. Anthropic is explicitly not making Mythos Preview generally available. Newton Cheng, who runs Frontier Red Team Cyber at Anthropic, told VentureBeat: “We do not plan to make Claude Mythos Preview generally available due to its cybersecurity capabilities. However, given the rate of AI progress, it will not be long before such capabilities proliferate, potentially beyond actors who are committed to deploying them safely. The fallout — for economies, public safety, and national security — could be severe.”
Read that again. The company that built the model is saying it’s too dangerous to ship. But they’re also saying it’s only a matter of time before someone else builds something equivalent. So the play is: give defenders a head start. Restricted access now, because the alternative — waiting for the bad guys to catch up first — is worse.
Who Gets Access
The Glasswing coalition reads like a who’s-who of critical infrastructure: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks. Twelve launch partners, plus more than 40 additional organizations that build or maintain critical software. Anthropic is putting up to $100 million in usage credits behind the effort, along with $4 million in direct donations to open-source security groups.
The idea is straightforward: let these organizations find and fix vulnerabilities in foundational systems before hostile actors with similar AI tools can exploit them. Anthropic is also publishing cryptographic hashes of unpatched vulnerability details, with plans to reveal specifics only after fixes ship. A responsible disclosure pipeline, but at a scale that’s never been attempted.
US and UK Regulators Respond
On April 11, Reuters reported that US Treasury Secretary Scott Bessent had called a meeting with major Wall Street banks to discuss Mythos Preview’s cyber risk potential. Two days later, the Financial Times broke the story that the Bank of England, the Financial Conduct Authority, and HM Treasury were holding urgent talks with the National Cyber Security Centre. Representatives from major British banks, insurers, and exchanges are expected to be briefed at a regulatory meeting within the next fortnight.
Two governments, two separate regulatory responses, same week. The concern isn’t abstract. If Mythos Preview can autonomously chain Linux kernel exploits, the financial sector’s entire threat model shifts. Banks run on systems that were never designed to withstand this kind of automated offensive capability. The regulators know it.
Revenue, Momentum, and a Very Big Compute Deal
Project Glasswing didn’t land in a vacuum. Anthropic also disclosed that its annualized revenue run rate has surpassed $30 billion, up from roughly $9 billion at the end of 2025. The number of enterprise customers spending over $1 million annually doubled in under two months, now exceeding 1,000. The company simultaneously announced a multi-gigawatt compute partnership with Google and Broadcom. And Bloomberg reported that Anthropic poached Eric Boyd, a senior Microsoft executive, to lead its infrastructure buildout.
That’s the business context: a company growing at extraordinary speed, locking in compute supply, and simultaneously deciding that its most powerful capability should be locked down rather than monetized.
The Uncomfortable Question
Here’s what nobody has a good answer for yet. Anthropic is betting that a controlled, defensive release buys the world enough time to harden its systems before equivalent models become available to adversaries. Maybe that’s true. Maybe they’re buying months, not years. The company’s own words — “it will not be long before such capabilities proliferate” — suggest they know the window is narrow.
The $100 million commitment to Glasswing is real money, and the partner list is impressive. But the fundamental tension doesn’t resolve. You can’t put the capability back in the box. You can only hope the good guys patch faster than the bad guys exploit. For the first time, an AI company is explicitly admitting that one of its models has crossed a threshold where the defensive-offensive balance tips. That admission itself might be the most important part of this story.
For tool-by-tool comparisons, see our AI coding listings and the comparisons section.