security
Jun 2, 2026
By Teun
Anthropic expands Project Glasswing to 150 more organizations
Anthropic said it is expanding Project Glasswing, its effort to use Claude Mythos Preview to find software vulnerabilities, to about 150 additional organizations. The company said the first 50 partners found more than 10,000 high- or critical-severity flaws, and the new group includes infrastructure and open-source maintainers in more than 15 countries.
Anthropic is expanding Project Glasswing, its collaborative program to use AI for software security, to about 150 additional organizations. The company said each new participant must meet its security requirements before gaining access to Claude Mythos Preview and related tooling.
The expansion follows several weeks of work with existing Project Glasswing partners, security industry groups, open-source maintainers and the US government, according to Anthropic. The company said the new participants are based in more than 15 countries and many support critical infrastructure.
Project Glasswing began in early April, when Anthropic said about 50 initial partners received access to Claude Mythos Preview. Since then, those partners have been using the model to scan codebases for vulnerabilities. Anthropic said the group has already found more than 10,000 high- or critical-severity security flaws.
The new cohort includes organizations in sectors that were not well represented in the first group, including power, water, healthcare, communications and hardware. Many of the new partners are vendors - companies or nonprofits that maintain software relied on by other organizations around the world, including governments.
Anthropic said the common thread is that a successful attack on these codebases could be catastrophic. For most partners, the company estimates that a major compromise could affect more than 100 million people and have implications for national and global security.
The company said the expansion is part of a longer-term goal to use AI to make software more secure, while also helping the cybersecurity industry adjust to models with stronger offensive and defensive capabilities. Anthropic said it expects that within six to 12 months, other AI companies will have models with similar cyber capabilities, and that some could release them without safeguards against misuse.
That scenario, Anthropic said, could lead to more frequent and less predictable cyberattacks. The company said defenders will need to adapt quickly, and it sees its role as both helping the software industry use better models safely and shifting from simply finding vulnerabilities to helping disclose, fix and deploy patched software.
Anthropic said the first Project Glasswing partners have already begun using Mythos Preview at large scale, sharing findings and best practices and working with third parties to triage results. The company said those methods should be replicated across the millions of organizations and developers exposed to cyberattacks.
To support that, Anthropic recently released Claude Security, a product that uses its latest public frontier models, including Claude Opus 4.8, to scan codebases and suggest patches. It is also making some of the internal tools developed for Project Glasswing available on request to trusted security teams.
Anthropic said it also wants to help build new initiatives, standards and infrastructure for a period in which powerful cyber models are more common. The company said it is discussing with third parties how to scale review and patching for open-source software, and is working on better ways to disclose vulnerabilities to maintainers so they are easier to triage and fix.
The company said the bottleneck in cybersecurity is now verifying, disclosing and patching the large number of flaws that Mythos-class models can surface. In addition to finding bugs, Anthropic said Mythos Preview can be used for patch writing, pre-release checks, penetration testing, automated threat detection and response, and rebuilding legacy code in memory-safe languages.
Looking ahead, Anthropic said it plans to expand Project Glasswing further, including more critical infrastructure providers, maintainers of important open-source software and safety testers, in the US and abroad. It also plans to scale up its Cyber Verification Program, which would give Mythos-class capabilities to more organizations for specific cyberdefense tasks.