Claude Mythos & Project Glasswing: When AI Gets Too Good at Hacking, It Becomes the Defenders' Weapon

    Claude Mythos & Project Glasswing: When AI Gets Too Good at Hacking, It Becomes the Defenders' Weapon

    11. April 2026Updated: June 13, 20266 min read
    Till Freitag

    TL;DR:Claude Mythos Preview finds zero-day vulnerabilities in every major operating system and browser. Anthropic isn't releasing it publicly but deploying it defensively through Project Glasswing. Then, on June 12, 2026, the US government abruptly suspended all global access to Fable 5 and Mythos 5 via export control directive — even for non-US citizens inside the United States. Anthropic disagrees with the decision. According to employee conversations, the real trigger may be workforce composition concerns rather than the alleged jailbreak."

    Till Freitag

    A Model Too Dangerous for Public Release

    On April 7, 2026, Anthropic did something unusual: announced a new frontier model – and simultaneously declared it would not be publicly available.

    Claude Mythos Preview is a general-purpose model that demonstrates one capability changing everything: it can find and exploit software vulnerabilities – better than virtually any human expert.

    This isn't a marketing claim. Mythos Preview has already found thousands of zero-day vulnerabilities – including critical bugs in every major operating system and every major web browser.

    Update: US Government Suspends Global Access (June 12, 2026)

    On June 12, 2026 – just two months after the Glasswing announcement – the US government issued an export control directive to Anthropic. The order demands the immediate suspension of access to Fable 5 and Mythos 5 for any foreign national, whether inside or outside the United States. Anthropic abruptly disabled access for all customers to ensure compliance.

    What the Government Claims

    The US government believes it has discovered a method of "jailbreaking" Fable 5 – bypassing the model's safeguards. Anthropic reviewed the demonstration and found it to be a narrow, non-universal jailbreak that identified a small number of previously known, minor vulnerabilities. Anthropic states that this level of capability is widely available from other models, including OpenAI's GPT-5.5, and is used daily by security defenders.

    Anthropic's Position

    Anthropic disagrees with the decision and is working to restore access as quickly as possible. In an official statement, Anthropic argues:

    "We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people. If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers."

    Anthropic emphasizes that Fable 5 has the strongest safeguards ever implemented for a model – including thousands of hours of red-teaming by the US government, the UK AISI, and internal teams. No universal jailbreak (a method that broadly bypasses all safeguards) has been found to date.

    What This Means

    • Immediate impact: Neither companies nor researchers currently have access to Mythos Preview – not even inside the US
    • Legal precedent: This is the first export control action against a commercial AI model based on an alleged jailbreak
    • Industry-wide signal: If this standard holds, any new frontier model deployment could be similarly interrupted
    • Anthropic's stance: The company is calling for a "transparent, fair, clear, and grounded in technical facts" statutory process for such decisions

    What Anthropic Employees Say

    After conversations with Anthropic staff, another explanation emerges. According to internal sources, the real trigger for the export control action is not primarily the alleged jailbreak – but a concern within the US government about the composition of Anthropic's workforce.

    The claim: Too many non-US citizens are working at Anthropic. The export control directive, in this reading, is less about model safety and more about access control to frontier AI capabilities by foreign nationals inside a US company.

    If this is accurate, it reframes the entire incident. The "jailbreak" justification would then serve as the legal mechanism for a measure whose underlying motivation is geopolitical workforce regulation. Anthropic's public disagreement with the decision and its emphasis on Fable 5's extensive red-teaming by US and UK government agencies would also take on a different light.

    Whether the technical justification or the workforce composition concern is the decisive factor – the result is the same: global access to Fable 5 and Mythos 5 is currently suspended.

    What Mythos Preview Found

    Three examples illustrate the scale:

    1. A 27-year-old vulnerability in OpenBSD – an operating system known for its security. The bug allowed anyone to remotely crash any machine by simply connecting to it.

    2. A 16-year-old bug in FFmpeg – software used in countless applications for video encoding. Automated testing tools had hit this line of code five million times without catching the flaw.

    3. A Linux kernel exploit chain – the model autonomously found and chained multiple vulnerabilities to escalate from ordinary user access to complete machine control.

    The remarkable part: Mythos Preview found most of these vulnerabilities entirely autonomously – without any human steering.

    The Leap Over Opus 4.6

    The numbers are dramatic. On the CyberGym benchmark, Mythos Preview scores 83.1% – compared to 66.6% for Opus 4.6.

    Even more striking is the exploit comparison: in a Firefox JavaScript engine test, Opus 4.6 could develop a working exploit in only 2 out of several hundred attempts. Mythos Preview succeeded 181 times.

    General coding benchmarks tell the same story:

    • SWE-bench Verified: 93.9% (vs. 80.8%)
    • SWE-bench Pro: 77.8% (vs. 53.4%)
    • Terminal-Bench 2.0: 82.0% (vs. 65.4%)

    These capabilities weren't explicitly trained – they emerged as a side effect of improved code, reasoning, and autonomy capabilities.

    Project Glasswing: The Defense Initiative

    Instead of making Mythos Preview public, Anthropic launched Project Glasswing – named after the glasswing butterfly with its transparent wings (symbolizing the initiative's commitment to transparency and vulnerability disclosure).

    The 12 Founding Partners

    Project Glasswing brings together an unprecedented consortium:

    • Amazon Web Services
    • Apple
    • Broadcom
    • Cisco
    • CrowdStrike
    • Google
    • JPMorganChase
    • Linux Foundation
    • Microsoft
    • NVIDIA
    • Palo Alto Networks
    • Anthropic

    Plus over 40 additional organizations that build or maintain critical software infrastructure.

    The Investment

    • $100 million in usage credits for Mythos Preview
    • $4 million in direct donations to open-source security organizations

    Why This Is Strategically Significant

    1. Anthropic Redefines Its Safety Leadership

    Until now, Anthropic's safety narrative has been largely theoretical: Responsible Scaling Policy, Constitutional AI, alignment research. With Glasswing, Anthropic demonstrates a concrete, productive application of safety – one that creates real economic and security value.

    2. The Business Model Shifts

    A model that isn't publicly available but is licensed through controlled partnerships represents a new paradigm. Anthropic becomes the defense contractor of the digital age – with a product so powerful that its controlled deployment is itself a competitive advantage.

    3. The Cybersecurity Landscape Changes Fundamentally

    The core insight from the Frontier Red Team Blog: the same capabilities that make models better at fixing bugs also make them better at exploiting them. This means:

    • Short-term: Attackers could benefit if frontier labs aren't careful
    • Long-term: Defenders will be more efficient, finding and fixing bugs before code ever ships

    The transition period will be turbulent.

    What Companies Should Do Now

    Project Glasswing isn't an abstract research project – it has direct implications:

    Security teams should evaluate how AI-powered vulnerability scanning can be integrated into their workflows. If Mythos Preview finds bugs in every major OS, the next comparable model will find them in your software too.

    CTOs and CISOs need to reassess the threat landscape. The window between vulnerability discovery and exploit has collapsed from months to minutes.

    Open-source maintainers should explore access through the Linux Foundation – the initiative offers enterprise-grade security tools for projects that normally couldn't afford them.

    Our Take

    Claude Mythos Preview and Project Glasswing mark a turning point. Not because a single model delivers impressive benchmarks – but because Anthropic draws the institutional consequence from it.

    Choosing not to release a model because its capabilities are too dangerous, and instead launching an industry-wide defense initiative – that's a move we haven't seen before in the AI industry.

    The question is no longer whether AI will transform cybersecurity. The question is whether defenders are fast enough to leverage the head start that initiatives like Glasswing provide.

    For companies positioning themselves now, this is an enormous opportunity. For everyone else, the clock is ticking.

    TeilenLinkedInWhatsAppE-Mail

    Related Articles

    Claude Mythos Preview: Benchmarks, Exploit Chains, and the Technical Deep Dive
    April 11, 20267 min

    Claude Mythos Preview: Benchmarks, Exploit Chains, and the Technical Deep Dive

    Claude Mythos Preview isn't incrementally better – it's a different category. 93.9% on SWE-bench, 100% on Cybench, and e

    Read more
    A stylized five made of butterflies – visual for Claude Fable 5
    June 9, 20266 min

    Claude Fable 5 & Mythos 5: When AI Shifts from Tasks to Responsibilities

    Anthropic launches Claude Fable 5 and Mythos 5 – SOTA on almost all benchmarks. More interesting than the numbers: The s

    Read more
    Editorial illustration of the Claude Design launch – warm sand-tone background with the rust-orange Claude spark motif, glassmorphic UI panels showing a wireframe, color tokens, and a dashboard mockup, with subtle Adobe-red and Figma-purple accents hinting at the market disruption.
    April 17, 20265 min

    Claude Design Is Here: How Anthropic Labs Wiped $30B Off Figma, Adobe and Wix in a Single Day

    On April 17, 2026, Anthropic launched Claude Design – the first Anthropic Labs product for visual work. Powered by Opus

    Read more
    Claude Opus 4.7 Is Here: What Premium Teams Need to Know About the Tokenizer, xhigh, and Spend Controls
    April 17, 20265 min

    Claude Opus 4.7 Is Here: What Premium Teams Need to Know About the Tokenizer, xhigh, and Spend Controls

    Anthropic just released Claude Opus 4.7. Same price as 4.6, but noticeably better at coding, agents, and visual output.

    Read more
    Chess pieces as a metaphor for the platform conflict between Anthropic and Lovable
    April 14, 20263 min

    Anthropic Is Building an App Builder – And It's Coming for Europe's Vibe-Coding Star Lovable

    Leaked screenshots reveal an integrated app builder inside Claude. What this means for Lovable, the European startup eco

    Read more
    The AI Race in 43 Milestones: The Complete OpenAI vs. Anthropic Timeline
    April 11, 20264 min

    The AI Race in 43 Milestones: The Complete OpenAI vs. Anthropic Timeline

    From GPT-4o to Project Glasswing: Every acquisition, model launch, and product release from OpenAI and Anthropic on an i

    Read more
    OpenAI Buys a TV Show. Anthropic Builds the Future of Software. And Google? It's Playing a Different Game Entirely.
    April 11, 20266 min

    OpenAI Buys a TV Show. Anthropic Builds the Future of Software. And Google? It's Playing a Different Game Entirely.

    OpenAI buys TBPN, a Jony Ive hardware startup, and builds a desktop superapp. Anthropic turns Claude into a Developer OS

    Read more
    Stylized number 5 made of orange ribbons and gears – cover for Claude Sonnet 5Deep Dive
    June 30, 20269 min

    Claude Sonnet 5: Agentic AI Goes Mainstream

    Anthropic ships Claude Sonnet 5 – a Sonnet model that gets close to Opus 4.8 performance at a fraction of the price. Aug

    Read more
    Why 🦞 Became the Secret Handshake of the Agentic AI Movement
    May 19, 20263 min

    Why 🦞 Became the Secret Handshake of the Agentic AI Movement

    How a crustacean became the tribal emoji of the agentic AI scene – from Anthropic memes to X bios full of lobster claws.

    Read more