Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a3fed06aab102da2

Jump to content

// Workers AI · dad joke modeWhat did Claude Mythos say to his myth-understanding friend? "You myth me

From Wikipedia, the free encyclopedia
(Redirected from Project Glasswing)
Claude Mythos
DeveloperAnthropic
ReleaseApril 7, 2026; 5 months ago (2026-04-07)
Stable release
Claude Mythos 5.1 /
September 1, 2026; 23 days ago (2026-09-01)
Type
LicenseProprietary
Websitewww.anthropic.com/glasswing Edit this on Wikidata

Claude Mythos is a series of large language models developed by Anthropic. It is the most complicated set of models in the Claude product line. The first model in the series was Claude Mythos Preview. Anthropic did not release the model to the public, citing the model's ability to find software vulnerabilities.[1] Starting in April 2026 under the name Project Glasswing, some companies were given access to Claude Mythos to scan for security vulnerabilities in critical software. The public had mixed reactions to the announcement of Claude Mythos Preview.[2]

In June 2026, Anthropic publicly released Claude Fable 5, a "Mythos-class" model made available for general use with a set of safeguards, alongside Claude Mythos 5, a restricted-access version of the same underlying model with those safeguards lifted in some areas. According to Anthropic, the two models are identical apart from their safeguards; when Fable 5's classifiers flag a request relating to cybersecurity, biology and chemistry, or model distillation, the response is instead handled by the less capable Claude Opus.[3][4] Mythos 5.1 and Fable 5.1 were released in September 2026.

According to industry estimates reported by the Financial Times, Mythos has approximately 8 trillion parameters, while Fable 5 has approximately 5 trillion parameters.[5]

Leak

[edit]

The existence of a model named Claude Mythos had become publicly known on March 26, 2026 due to leaked blog post drafts.[6] Anthropic later acknowledged the development of Mythos to Fortune, and said that the model presented significant risks to cybersecurity.[7] According to Axios, Anthropic had issued a warning about Mythos's capabilities to government officials that month.[8]

Models

[edit]

Mythos Preview

[edit]

Anthropic publicly disclosed Mythos on April 7.[9] The company stated that it had no plan to release Mythos to the public.[10] It instead launched Project Glasswing, with a consortium of companies using Mythos to find and fix software vulnerabilities. Over forty companies were granted access, including Microsoft, Apple, Google, Amazon Web Services, the Linux Foundation, Cisco, Nvidia, and Broadcom.[11] That day, several unauthorized users gained access to Mythos, according to Bloomberg News.[12]

Reportedly, a few users in a private Discord channel gained access to Mythos the same day it was announced, using details from the recent Mercor data breach.[12] The NSA has also used Mythos, despite the fact that the DoD, its parent organization, had blacklisted Anthropic after a dispute.[13] In April 2026, the Chinese government requested access to Mythos, but was rebuffed.[failed verification][14]

On June 2, Anthropic expanded access to its Claude Mythos cyber-security model, making it available to 150 organizations in more than 15 countries.[15]

In its May 28, 2026 announcement of Claude Opus 4.8, Anthropic stated it expected to make "Mythos-class" models available to all customers within weeks of the announcement, pending the development of additional cybersecurity safeguards.[16]

Mythos 5 and Fable 5

[edit]

On June 9, Anthropic released Claude Mythos 5 as a preview via Project Glasswing alongside a version of Mythos with extended safeguards titled Fable 5.[17]

On June 12, the U.S. government sent Anthropic a letter prohibiting access to both Mythos 5 and Fable 5 to any non-U.S. national whatsoever, regardless of their location, due to national security concerns.[18] As a result, Anthropic revoked access to both models for all customers.[18]

On June 26, Anthropic started to restore access to Mythos to some U.S. organizations.[19][20]

On June 30, Anthropic announced that the U.S. Department of Commerce had lifted restrictions on both Fable 5 and Mythos 5, and that access to the models would be restored the next day.[21][22][23] Anthropic included temporary access to Fable 5 for all of its subscription plans from July 1 until July 19, extending the promotional period several times. On July 20, Fable 5 was made a standard feature of Anthropic's higher-tier subscription plans.[24]

On September 1 2026, Anthropic released Claude Mythos 5.1 and Claude Fable 5.1.[25]

Specifications and capabilities

[edit]

Claude Mythos Preview is a large language model designed to fix vulnerabilities within software.[26][2] The UK AI Security Institute tested Claude Mythos with a cyber range. Claude Mythos ranked highest, with Claude Opus 4.6 coming in second, followed by a tie between GPT-5.4 and GPT-5.3 Codex.[27] According to industry estimates reported by the Financial Times, Mythos has approximately 8 trillion parameters, while Fable 5 has approximately 5 trillion parameters.[5]

Reported vulnerabilities

[edit]

Anthropic stated that Mythos had found vulnerabilities in "every major operating system and every major web browser" in its testing.[28] An independent security researcher cast doubt on these claims, as no independent verification of these numbers can be found outside of promotional documents.[29] As the researcher notes, the peer-review-ready report produced by Anthropic admits that Claude Opus 4.6 was, in fact, the model which found the bugs before handing them off to Mythos for exploitation. The Firefox bugs reported were not found in Firefox, but in an environment intended to mimick the application with reduced security features. Furthermore, the Anthropic tests found that, while Mythos was able to achieve full code execution in 72.4% of cases, Claude Sonnet 4.6 outperformed the larger model when removing the two most exploitable bugs. When those bugs are removed, Mythos was only able to achieve full code execution in less than 5% of cases. Anthropic stated that "almost every successful run relies on the same two now-patched bugs."[30]

Another independent test found that one of the headline vulnerabilities identified by Mythos was also identified by 8 out of 8 tested open-source models, one with only 3.6B active parameters and costing 11 cents per million tokens.[31]

Two weeks after the limited release, Mozilla announced that it had found and patched 271 security vulnerabilities in Firefox using Mythos Preview.[32][33] On May 14, 2026, employees at Calif.io announced they had used Mythos to create a memory corruption exploit affecting Apple M5 chips.[34]

Responses

[edit]

Media response

[edit]

Thomas Fraise, writing for The Conversation, argued that Mythos could ruin nuclear deterrence.[35] Brett J. Goldstein, writing for The New York Times, argued that the model puts individuals and smaller teams at a "cybersecurity disadvantage".[36]

Industry response

[edit]

Financial response

[edit]

Hours after Anthropic publicly revealed Mythos, U.S. secretary of the treasury Scott Bessent and Federal Reserve chair Jerome Powell convened financial executives to issue a warning on Mythos's capabilities.[37] Several banks began testing Mythos at their behest, including JPMorgan Chase, Goldman Sachs, Citigroup, Bank of America, and Morgan Stanley.[38] The Bank of Canada summoned major lenders to a similar meeting the following day.[39] Mythos was scheduled to be discussed by the Bank of England's Cross Market Operational Resilience Group and CMORG AI Taskforce meetings.[40]

European Central Bank president Christine Lagarde praised Anthropic for limiting access to Mythos.[41] In response to European banks that were not given access to Mythos, Mistral AI began developing its own model.[42]

Governmental responses

[edit]

On April 14, 2026, Bloomberg reported that the United States Department of the Treasury was seeking access to Claude Mythos.[43] On April 16, the White House and Anthropic held a meeting about Mythos.[44] On May 13, a bipartisan group of 32 US Representatives wrote to the Office of the National Cyber Director (ONCD) on revisiting the U.S.'s federal cybersecurity policy.[45][46]

On April 23, Nirmala Sitharaman, chair of India's Ministry of Finance held a meeting of banks and government officials to discuss potential new cybersecurity threats following the release of Mythos.[47]

At a joint public-private meeting hosted by Japan's Financial Services Agency on April 24, participants agreed to form a work-group to counter potential threats caused by Mythos.[48]

After an April meeting with officials from Anthropic, Evan Solomon, the Canadian minister of artificial intelligence and digital innovation, praised Anthropic for limiting access to Mythos.[49]

Several meetings with banks were held by the Australian Prudential Regulation Authority in response to Mythos.[50]

In April 2026, Anthropic declined to provide access to Claude Mythos after allegedly receiving a request from a member of a Chinese think tank at a conference in Singapore. The Chinese Embassy in the United States stated that it was not familiar with the request and denied that the request was related to the Chinese government.[14]

Project Glasswing

[edit]

In April 2026, using the name Project Glasswing, Anthropic provided access to Claude Mythos for select companies and organizations in order to scan for security vulnerabilities in critical software. In May 2026, the project expanded access from 50 to 200 organization in power, water, healthcare, communications and hardware.[51][52] The company said in May that its first 50 Glasswing partners had found over 10,000 high or severe critical vulnerabilities.[52] According to security researcher Patrick Garrity, only 10% of discovered flaws had been disclosed and less than 1% had been fixed as of September. Garrity also describes a large discrepancy in what Mythos considers a high severity vulnerability (90% of bugs) compared with closer to 60% for project maintainers.[53] Jai Vijayan, writing for the security magazine Dark Reading, says that there exists a bottleneck in validating and remediating bugs, since this is done largely by humans.[53]

References

[edit]
  1. "What is Claude Mythos and what risks does it pose?". BBC News. April 18, 2026. Archived from the original on June 3, 2026. Retrieved May 30, 2026.
  2. 1 2 Metz, Cade; Conger, Kate Conger (May 12, 2026). "Is Anthropic's New A.I. Really That Scary? It Depends Whom You Ask". The New York Times. ISSN 0362-4331. Retrieved May 17, 2026.
  3. "Claude Fable and Claude Mythos 5". Anthropic. Retrieved July 30, 2026.
  4. Capoot, Ashley (June 9, 2026). "Anthropic releases Mythos-like AI model to the public two months after private rollout rocked Wall Street". CNBC. Retrieved July 20, 2026.
  5. 1 2 ByteDance targets mega AI model that could match Mythos scale, FT reports, retrieved August 17, 2026
  6. Nolan, Beatrice (March 26, 2026). "Exclusive: Anthropic left details of an unreleased model, an upcoming exclusive CEO event, in a public database". Fortune. Archived from the original on March 27, 2026. Retrieved April 7, 2026.
  7. Nolan, Beatrice (March 26, 2026). "Anthropic acknowledges testing new AI model representing 'step change' in capabilities, after accidental data leak reveals its existence". Fortune. Archived from the original on May 15, 2026. Retrieved May 18, 2026.
  8. VandeHei, Jim (March 29, 2026). "AI's looming cyber nightmare". Axios. Archived from the original on May 19, 2026. Retrieved May 18, 2026.
  9. Roose, Kevin (April 7, 2026). "Anthropic Claims Its New A.I. Model, Mythos, Is a Cybersecurity 'Reckoning'". The New York Times. Retrieved May 18, 2026.
  10. McMillan, Robert (April 7, 2026). "Anthropic Set to Preview Powerful 'Mythos' Model to Ward Off AI Cyberthreats". The Wall Street Journal. Archived from the original on May 22, 2026. Retrieved May 18, 2026.
  11. Newman, Lily (April 7, 2026). "Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything". Wired. Archived from the original on May 22, 2026. Retrieved May 18, 2026.
  12. 1 2 Metz, Rachel (April 21, 2026). "Anthropic's Mythos Model Is Being Accessed by Unauthorized Users". Bloomberg News. Archived from the original on May 22, 2026. Retrieved May 18, 2026.
  13. "Scoop: NSA using Anthropic's Mythos despite Defense Department blacklist". Axios. April 19, 2026. Archived from the original on May 28, 2026. Retrieved April 22, 2026.
  14. 1 2 Volz, Dustin; Barnes, Julian E.; Frenkel, Sheera; Mickle, Tripp (May 12, 2026). "China Sought Access to Anthropic's Newest A.I. The Answer Was No". The New York Times. ISSN 0362-4331. Retrieved May 12, 2026.
  15. Murgia, Madhumita (June 2, 2026). "Anthropic to expand Mythos access to more than 15 countries". The Financial Times.
  16. "Introducing Claude Opus 4.8". www.anthropic.com. Archived from the original on May 30, 2026. Retrieved June 6, 2026.
  17. Nickel, Dana; Miller, Maggie (June 9, 2026). "Anthropic releases a less-powerful version of its most advanced model". Politico. Retrieved June 10, 2026.
  18. 1 2 Capoot, Ashley (June 13, 2026). "Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive". CNBC. Archived from the original on June 29, 2026. Retrieved June 13, 2026.
  19. Albergotti, Reed; Smith, Ben (June 26, 2026). "Exclusive: US releases powerful Anthropic model Mythos to some US companies". Semafor (website). Retrieved June 27, 2026.
  20. Cai, Sophia; Haslett, Cheyenne (June 26, 2026). "Trump administration partially lifts Anthropic's AI export ban". POLITICO. Retrieved June 27, 2026.
  21. AnthropicAI [@AnthropicAI] (June 30, 2026). "We've received notice that the Department of Commerce has lifted export controls on Claude Fable 5 and Mythos 5" (Tweet). Retrieved July 1, 2026 via X (formerly Twitter).
  22. Carter, Sandy. "Anthropic Wins As Commerce Lifts Fable 5 And Mythos 5 Export Controls". Forbes. Archived from the original on July 1, 2026. Retrieved July 1, 2026.
  23. Field, Hayden (July 1, 2026). "Anthropic's long-sidelined Fable 5 is greenlit to return". The Verge. Archived from the original on July 1, 2026. Retrieved July 1, 2026.
  24. Writer, Senior; PCWorld. "Fable will stay in Claude plans, but not for everyone". PCWorld. Retrieved July 22, 2026.
  25. "Introducing Claude Fable 5.1 and Claude Mythos 5.1". www.anthropic.com. Retrieved September 1, 2026.
  26. Criddle, Cristina (April 7, 2026). "Anthropic rolls out cyber AI model days after source code leak". Financial Times. Archived from the original on April 8, 2026. Retrieved May 18, 2026.
  27. "Our evaluation of Claude Mythos Preview's cyber capabilities | AISI Work". AI Security Institute. April 13, 2026. Archived from the original on April 13, 2026. Retrieved April 22, 2026.
  28. Murphy, Margi (April 7, 2026). "Anthropic Limits Mythos Model Release in Bid to Stave Off Hacks". Bloomberg News. Archived from the original on April 16, 2026. Retrieved May 18, 2026.
  29. "The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic | flyingpenguin". www.flyingpenguin.com. Retrieved July 11, 2026.
  30. "Model system cards". www.anthropic.com. Retrieved July 11, 2026.
  31. "AI Cybersecurity After Mythos: The Jagged Frontier". AISLE. April 7, 2026. Retrieved July 11, 2026.
  32. Orland, Kyle (April 21, 2026). "Mozilla: Anthropic's Mythos found 271 security vulnerabilities in Firefox 150". Ars Technica. Archived from the original on May 28, 2026. Retrieved April 22, 2026.
  33. Newman, Lily Hay (April 21, 2026). "Mozilla Used Anthropic's Mythos to Find and Fix 271 Bugs in Firefox". WIRED. Retrieved April 22, 2026.
  34. Schroeder, Stan (May 15, 2026). "Anthropic's Mythos is already finding security flaws in Apple software". Mashable. Archived from the original on May 28, 2026. Retrieved May 17, 2026.
  35. Fraise, Thomas (May 12, 2026). "Hacking the bomb? What Claude Mythos AI reveals about the gamble of nuclear deterrence". The Conversation. Archived from the original on May 22, 2026. Retrieved May 17, 2026.
  36. Goldstein, Brett J. (April 28, 2026). "Opinion | Your Passwords Are Probably Screwed". The New York Times. ISSN 0362-4331. Retrieved May 17, 2026.
  37. Gillespie, Todd; Johnson, Katanga; Levitt, Hannah; Natarajan, Sridhar (April 9, 2026). "Anthropic Model Scare Sparks Urgent Bessent, Powell Warning to Bank CEOs". Bloomberg News. Retrieved May 18, 2026.
  38. Robertson, Jordan; Gillespie, Todd; Natarajan, Sridhar (April 10, 2026). "Wall Street Banks Try Out Anthropic's Mythos as US Urges". Bloomberg News. Retrieved May 18, 2026.
  39. Hertzberg, Erik; Dobby, Christine (April 10, 2026). "Bank of Canada, Major Lenders Met on Anthropic AI Cyber Risk". Bloomberg News. Archived from the original on May 22, 2026. Retrieved May 18, 2026.
  40. Rees, Tom (April 11, 2026). "Bank of England Set to Discuss Anthropic's Mythos With Banks". Bloomberg News. Archived from the original on May 22, 2026. Retrieved May 18, 2026.
  41. Lacqua, Francine; Stirling, Craig (April 14, 2026). "Lagarde, Worried About AI, Lauds Anthropic's Approach on Mythos". Bloomberg News. Retrieved May 18, 2026.
  42. Cohen, Claudia; Berthelot, Benoit (May 13, 2026). "Mistral Developing New AI Model for Banks Lacking Mythos Access". Bloomberg News. Archived from the original on May 14, 2026. Retrieved May 18, 2026.
  43. Murphy, Margi; Metz, Rachel (April 14, 2026). "US Treasury Seeking Access to Anthropic's Mythos to Find Flaws". Bloomberg News. Retrieved May 18, 2026.
  44. "White House and Anthropic hold 'productive' meeting amid fears over Mythos model". BBC. April 18, 2026. Archived from the original on May 22, 2026. Retrieved May 17, 2026.
  45. Gold, Ashley (May 13, 2026). "Scoop: Lawmakers press White House to act on AI cyber threats". Axios. Archived from the original on May 22, 2026. Retrieved May 17, 2026.
  46. "AI-Discovered Vulnerability Coordination Letter" (PDF). house.gov. May 13, 2026. Archived (PDF) from the original on May 26, 2026. Retrieved May 30, 2026.
  47. "If AI Can Hack Faster Than Humans, What Happens Next?". Forbes India. April 24, 2026. Archived from the original on May 22, 2026. Retrieved May 17, 2026.
  48. "Japan rushing to counter threat of cyberattack from Mythos AI model". The Asahi Shimbun. April 27, 2026. Archived from the original on May 22, 2026. Retrieved May 17, 2026.
  49. Hertzberg, Erik (April 14, 2026). "Anthropic Wins Accolades From Canada's AI Minister Over Mythos Approach". Bloomberg News. Archived from the original on May 22, 2026. Retrieved May 18, 2026.
  50. Eyers, James (April 29, 2026). "APRA meets with banks, urges more vigilance against AI-powered hacks". Australian Financial Review. Archived from the original on May 22, 2026. Retrieved May 17, 2026.
  51. Dastin, Jeffrey (June 2, 2026). "Anthropic Mythos access to quadruple to about 200 Glasswing partners". Reuters. Retrieved September 16, 2026.
  52. 1 2 Subin, Samantha (June 2, 2026). "Anthropic expands Mythos to 150 additional organizations in more than 15 countries". CNBC. Retrieved September 16, 2026.
  53. 1 2 Vijayan, Jai (September 9, 2026). "Mythos Vulnerability Firehose Hits a Human Bottleneck". Dark Reading. Retrieved September 16, 2026.
[edit]