AI Tools Review
What is Project Glasswing? Securing Critical Software in the AI Era

Insights

What is Project Glasswing? Securing Critical Software in the AI Era

AI Tools Review Editorial TeamApril 11, 2026

    Anthropic covers Project Glasswing in this video.

    1. The Launch of Project Glasswing

    For years, the cybersecurity paradigm has been a losing game for defenders: an attacker only needs to be right once, whilst a defender must be right every time. With the launch of Project Glasswing, Anthropic intends to fundamentally tip the scales in favour of defence using extreme AI reasoning.

    Announced recently, Project Glasswing was formed as a direct response to the capabilities observed within Claude Mythos Preview, Anthropic's most powerful, unreleased frontier model. During safety evaluations, Anthropic engineers realised the model had achieved a level of reasoning where it could autonomously discover and write exploits for critical software vulnerabilities faster than human security teams could intervene.

    Recognising the catastrophic risk if such capabilities proliferated into the hands of bad actors, Anthropic explicitly chose not to release the model to the public. Instead, they siloed it entirely into Project Glasswing, deploying the intelligence purely defensively.

    The project was announced on 07/04/2026. The name is not decorative: the glasswing butterfly, Greta oto, has transparent wings and hides by being seen through rather than by hiding. That is a reasonable metaphor for a class of software flaw that has usually been sitting in plain sight, in public source code, for years before anybody notices it.

    Editor's note

    This article was first published shortly after the launch announcement and has been expanded on 13/09/2026 to cover Anthropic's initial results update of 22/05/2026 and the programme expansion announced on 02/06/2026. Dates are given throughout so you can see which figures belong to which stage.

    2. The 'Tech Leader' Coalition

    Anthropic recognised that discovering vulnerabilities is only half the battle; patching them across the global grid requires immense coordination. To execute this, Project Glasswing launched with an unprecedented coalition of industry competitors:

    AWS
    Anthropic
    Apple
    Google
    Microsoft
    NVIDIA
    CrowdStrike
    Cisco
    Palo Alto Networks
    Broadcom
    JPMorgan Chase
    Linux Foundation

    This consortium is utilising Claude Mythos Preview to ingest and scan their massive proprietary and open-source codebases. AWS, whose vice-president and chief information security officer Amy Herzog notes that the company already analyses over 400 trillion network flows every day for threats, is applying the model to its own critical codebases. Beyond the twelve launch partners, Anthropic extended access to more than forty further organisations that maintain critical software infrastructure.

    The partner statements are notable for how little hedging they contain. Cisco's senior vice-president and chief security and trust officer, Anthony Grieco, framed it starkly: "AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back." Microsoft's Igor Tsyganskiy, executive vice-president for cybersecurity and Microsoft Research, put the operational problem plainly: "The window between a vulnerability being discovered and being exploited by an adversary has collapsed — what once took months now happens in minutes with AI."

    CrowdStrike's chief technology officer, Elia Zaitsev, addressed the obvious objection — that accelerating vulnerability discovery might simply arm attackers faster — with the coalition's central argument: "That is not a reason to slow down; it's a reason to move together, faster." Whether that holds is the open question the rest of this article examines. Google's Heather Adkins, vice-president of security engineering, pointed to the company's own Big Sleep and CodeMender tools as complementary efforts, a reminder that Glasswing is not the only AI-driven vulnerability programme running, merely the largest cross-industry one.

    3. Hunting Zero-Day Vulnerabilities

    The results of the Glasswing initiative have already reshaped the security landscape. In its preliminary weeks alone, Claude Mythos Preview autonomously identified thousands of zero-day vulnerabilities in nearly every major OS and browser currently in existence.

    Notable Early Discoveries

    • 1.OpenBSD Critical Flaw: Mythos uncovered a complex, 27-year-old remote crash vulnerability in what is widely considered the world's most hardened operating system.
    • 2.FFmpeg 16-year Execution Flaw: It caught an exploit inside a video decoding software library that automated static-analysis tools had scanned and passed over 5 million times previously without detecting.
    • 3.Linux Kernel Escapement: Mythos successfully chained together multiple obscure kernel bugs to achieve root escalation on Linux servers entirely autonomously.

    Because Glasswing partners with the Linux Foundation and these maintainers, all vulnerabilities discovered in this initial wave were quietly patched across global infrastructure before any details were made public via cryptographic hashing.

    4. The £75M ($100M) Commitment to Open Source

    Perhaps the most impactful aspect of Project Glasswing is its focus on Open Source maintainers. Historically, enterprise organisations could afford heavy security infrastructure, whilst the critical open-source libraries that held up the web relied on volunteers with limited security budgeting.

    Anthropic is attempting to level this playing field by committing £75 million ($100 million) in free usage credits for the Mythos Preview model strictly for these initiatives. Furthermore, they have donated £3 million ($4 million) in direct cash funding to the Alpha-Omega initiative, the OpenSSF, and the Apache Software Foundation.

    The cash element splits roughly £1.9 million ($2.5 million) to Alpha-Omega and the OpenSSF, routed through the Linux Foundation, and roughly £1.1 million ($1.5 million) to the Apache Software Foundation. Jim Zemlin, chief executive of the Linux Foundation, put the rationale bluntly: open-source maintainers, "whose software underpins much of the world's critical infrastructure", have "historically been left to figure out security on their own".

    This guarantees that the same code-defence capability protecting Apple and Google is placed into the hands of the solo developers maintaining the foundational libraries of the internet. It is also, from Anthropic's perspective, a considerably cheaper way to secure its own supply chain than auditing every dependency itself.

    5. What Claude Mythos Preview Actually Is

    Claude Mythos Preview is not a purpose-built security tool. Anthropic describes it as a general-purpose, unreleased frontier model — the same kind of model it would ordinarily ship to customers, withheld because of what it can do. That distinction matters. The capability being restricted is not a feature someone added; it is an emergent property of a very strong general coding model.

    The published figures make the case. On CyberGym, which measures whether a model can reproduce a known vulnerability from a description, Mythos Preview scores 83.1% against 66.6% for Claude Opus 4.6. On the coding side it reaches 93.9% on SWE-bench Verified, 77.8% on SWE-bench Pro and 87.3% on SWE-bench Multilingual. Set those alongside the 49.0% that the upgraded Claude 3.5 Sonnet managed on SWE-bench Verified in late 2024 — analysed in our Claude 3.5 Sonnet system card deep dive — and the eighteen-month trajectory is the whole story.

    EvaluationClaude Mythos PreviewClaude Opus 4.6
    CyberGym (vulnerability reproduction)83.1%66.6%
    SWE-bench Verified93.9%—
    SWE-bench Pro77.8%—
    SWE-bench Multilingual87.3%—

    Access is deliberately narrow but not technically exotic. Approved partners reach the model through the Claude API, Amazon Bedrock, Google Cloud Vertex AI and Microsoft Foundry — the same four surfaces any enterprise Claude deployment would use. Beyond the initial research phase, Anthropic has said the model is priced at around £19 ($25) per million input tokens and £94 ($125) per million output tokens, several times the rate of its general-release Opus tier. That premium is a gate as much as a price.

    6. The First Month: What the Numbers Showed

    On 22/05/2026 Anthropic published an initial update, and it is a far more interesting document than the launch announcement. Across all partners, the first month produced more than 10,000 high- or critical-severity vulnerabilities. That figure alone is easy to wave at; the open-source breakdown underneath it is what makes the programme legible.

    Scanning more than 1,000 open-source projects surfaced 23,019 candidate findings, of which roughly 6,202 were estimated to be high- or critical-severity. Anthropic then had humans assess a sample: of 1,752 findings reviewed, 1,587 were confirmed genuine, a true-positive rate of 90.6%. Of those validated findings, 62.4% — 1,094 issues — were confirmed high- or critical-severity.

    A 90.6% true-positive rate is the number that should make security engineers sit up. Static analysis tooling has historically drowned teams in false positives, and the resulting alert fatigue is the reason so many scanners end up disabled. Cloudflare, which identified around 2,000 bugs of which roughly 400 were high or critical, reported a false-positive rate better than its human testers. Mozilla found 271 vulnerabilities in Firefox 150. Palo Alto Networks, Microsoft and Oracle all reported accelerated patch volumes.

    "The bottleneck in fixing bugs like these is the human capacity to triage, report, and design and deploy patches for them."

    Anthropic, Project Glasswing initial update, 22/05/2026

    This is the finding that reframes the entire initiative. Anthropic set out to solve discovery and discovered that discovery was never the constraint. Average patch time for a high- or critical-severity bug ran to about two weeks. More tellingly, open-source maintainers asked Anthropic to slow down the rate at which it disclosed findings to them, because they did not have the capacity to absorb them. Handing a volunteer maintainer a hundred valid critical vulnerabilities is not obviously a gift.

    7. How Coordinated Disclosure Works

    Given that Glasswing generates exploitable knowledge at scale, the disclosure mechanics carry more weight than usual. Anthropic operates a two-track model. Where a vulnerability has already been patched, full technical detail is published on the Frontier Red Team blog. Where a fix has not yet shipped, the finding is published only as a cryptographic hash, with the specifics released once the patch is deployed.

    Publishing a hash is a neat piece of design. It lets Anthropic prove, after the fact, that it knew about a specific flaw on a specific date, without giving anyone a usable head start. It also creates an auditable record that the company is not quietly sitting on findings, which matters for a programme whose credibility rests on the claim that it is purely defensive. Anthropic further committed to reporting publicly within ninety days on lessons learned, vulnerabilities fixed and improvements that could be shared beyond the coalition.

    The three named early discoveries remain the most quoted results, and all three were reported to maintainers and patched: the 27-year-old remote-crash flaw in OpenBSD, a 16-year-old vulnerability in FFmpeg that automated tooling had tested some five million times without catching, and a chain of Linux kernel bugs that escalated a standard user account to full system control. The FFmpeg case is the most instructive, because it demonstrates the specific thing a language model does that a fuzzer does not: reason about intent across a codebase rather than probe it mechanically.

    8. The June 2026 Expansion

    On 02/06/2026 Anthropic announced that roughly 150 new organisations would gain access to Claude Mythos Preview, up from around fifty at launch. The expansion is geographic as well as numerical, reaching more than fifteen countries with further growth planned, and it deliberately widens the sector mix beyond big technology and finance into power, water, healthcare, communications and hardware.

    The selection criterion Anthropic describes is blast radius rather than revenue: vendors whose compromised codebases could affect millions of people. Partners themselves estimate that a successful attack on their systems could affect more than 100 million people per organisation. Alongside the expansion, Anthropic released a Claude Security product for general use, committed to scaling its Cyber Verification Program, and said it would work with third parties on open-source vulnerability patching and disclosure — a direct response to the triage bottleneck the May update had exposed.

    "Cheap, fast AI models with powerful cyber capabilities are around the corner. We want Project Glasswing to spur institutions toward operating norms that reflect this reality."

    Anthropic, Expanding Project Glasswing, 02/06/2026

    That sentence is the honest core of the whole programme. Glasswing is not premised on Anthropic holding a permanent capability lead. It is premised on the opposite: that this capability will shortly be cheap and widely available, and that the defenders had better have restructured their processes before it is.

    9. What Glasswing Changes, and What It Doesn't

    What it changes is the economics of finding flaws. A 90.6% true-positive rate on open-source code, achieved at machine throughput, means vulnerability discovery has stopped being the scarce, expensive, specialist activity it has been for thirty years. That is a genuine structural shift, and the OpenBSD and FFmpeg findings show it reaches bugs that decades of human review and automated tooling missed.

    What it does not change is everything downstream of discovery. Triage, patch design, review, release engineering, and the long tail of getting fixes onto real systems all remain stubbornly human and stubbornly slow. A two-week average patch time for critical bugs is respectable by industry standards and hopeless by the standard Microsoft described, where the gap between discovery and exploitation "now happens in minutes". Anthropic's own maintainers asked for less information, not more.

    There is also an unavoidable asymmetry that no coalition can fully close. Glasswing gives defenders a head start measured in months, not years, and it works only for codebases someone has chosen to scan. An attacker with an equivalent model does not need permission, a partner agreement, or a disclosure policy. The bet Anthropic is making is that a well-organised head start, spent on hardening the most consequential software in the world, is worth more than the risk of demonstrating publicly what these models can do. It is a defensible bet. It is not a risk-free one, and anyone reading the partner quotes carefully will notice that none of them claim otherwise.

    For readers tracking the wider programme, we have separate breakdowns of the AWS participation in Project Glasswing and the JPMorgan Chase deployment.

    Frequently Asked Questions

    What is Anthropic's Project Glasswing?
    Project Glasswing is a cross-industry initiative launched by Anthropic alongside tech giants like Apple, Google, and NVIDIA. It dedicates Anthropic's powerful unreleased AI model, Claude Mythos Preview, to proactively hunting and fixing vulnerabilities in critical global software.
    Why is it called Project Glasswing?
    The project is named after the Greta oto, or 'glasswing butterfly.' Its transparent wings represent Anthropic's commitment to transparency, while its ability to hide in plain sight mirrors the hidden nature of zero-day software vulnerabilities.
    How much is Anthropic investing in Project Glasswing?
    Anthropic has committed up to £75 million ($100 million) in API usage credits to participating organisations, alongside £3 million ($4 million) in direct donations to open-source security maintainers.

    Explore more AI tool comparisons

    In-depth reviews, benchmarks and guides to help you choose the right AI tools.

    Browse all reviews
    AI Tools Review Editorial Team

    AI Tools Review Editorial Team Expert verified

    Our editorial team consists of veteran AI researchers, software engineers, and industry analysts. We spend hundreds of hours benchmarking frontier models natively to provide you with objective, actionable intelligence on agentic AI capabilities and cybersecurity landscapes.