Claude AI Uncovers Thousands of Software Bugs
Anthropic says unreleased Claude Mythos found thousands of software vulnerabilities and will be used via the Glasswing partnership, not released publicly.
Jason Kwon ·

Anthropic said on Tuesday that an unreleased artificial intelligence model called Claude Mythos has detected thousands of previously unknown software vulnerabilities in widely used applications. The San Francisco-based company said it is not planning to publish the model, and will instead work with cybersecurity specialists and the open-source community to apply it as a defensive capability against hacking.
The company described Mythos as the newest version in its Claude model line. According to Anthropic, the system surfaced weaknesses that software developers had not found, including issues that date back 27 years . The announcement framed the findings as evidence that AI systems have reached a level where they can outperform human experts in identifying and exploiting software weaknesses.
Anthropic said that this shift creates risks that extend beyond individual companies, citing potential consequences for economies, public safety, and national security. The company also said the window between a vulnerability being discovered and being exploited has narrowed significantly as AI capabilities advance, increasing the urgency of faster detection and remediation.
To respond, Anthropic said it has launched Glasswing , a collaborative effort bringing together about 40 organizations . Participants include cybersecurity firms CrowdStrike and Palo Alto Networks , alongside technology companies Amazon , Apple , Microsoft , Cisco , and Broadcom . Anthropic said the project is designed to help partners use Mythos to find and address software and hardware vulnerabilities more quickly.
Anthropic said it is contributing an estimated $100 million in computing resources to support Glasswing. The company said this capacity will allow participating organizations to run the model for vulnerability discovery and mitigation at a faster pace than traditional approaches, with the goal of strengthening defenses against cyber threats.
For global markets, the announcement highlights how AI-driven security tools are becoming a larger part of enterprise risk management as digital systems underpin cross-border finance, trade, and critical services. For governments and regulators, Anthropic’s emphasis on national security and public safety underscores why software assurance and coordinated vulnerability response remain central to resilience planning.
Key details remain unclear from the announcement, including which specific applications were affected, how many of the vulnerabilities have been validated or patched, and how Glasswing partners will coordinate disclosure and remediation. Anthropic’s decision not to release Mythos publicly also leaves open questions about access controls and how broadly the defensive benefits can be distributed while limiting misuse.