Anthropic · 2026-05-22 · major
Anthropic's Project Glasswing Initial Update — ~50 Partners Used Claude Mythos to Surface 10,000+ Vulnerabilities, 1,587 Open-Source Flaws Confirmed Valid at a 90.6% True-Positive Rate, Plus Claude Security Public Beta
Anthropic's first Project Glasswing report says ~50 partners used Claude Mythos to surface 10,000+ vulnerabilities, with 1,587 open-source flaws confirmed valid. Claude Security enters public beta alongside a public vulnerability dashboard.

Anthropic's one-month report on its ~50-partner program to find software flaws before AI models can exploit them.
Key specs
| Vulnerabilities found | 10,000+ |
|---|---|
| Oss high/critical flagged | 6,202 |
| Confirmed valid | 1,587 |
| True positive rate | 90.6% |
| Reported to maintainers | 530 |
| Patched so far | 75 |
What is it?
Project Glasswing is Anthropic's coordinated effort with about 50 partners to use its Claude Mythos Preview model to find and fix security flaws in critical software ahead of attackers. This is the program's first public results, covering its opening month.
How does it work?
Partners run Claude Mythos against their own codebases and a sweep of open-source projects. Anthropic's automated scan of 1,000+ projects flagged 6,202 high- or critical-severity issues; independent assessment confirmed 1,587 as valid, a 90.6% true-positive rate. Findings route to maintainers through coordinated disclosure.
Why does it matter?
It is a concrete data point on whether frontier models can do useful defensive security at scale. Maintainers get real fixes (530 bugs reported, 75 patched so far), and security teams can now try the workflow through the new Claude Security public beta and an open vulnerability dashboard.
Who is it for?
security researchers and open-source maintainers
Try it
https://claude.com/product/claude-security