Anthropic splits Mythos access into three security tiers

Partners in Anthropic's Project Glasswing verified at least 129,000 software vulnerabilities between April and July, Reuters reports, and Anthropic thinks the real number is at least five times higher. Anthropic is now giving more vetted security teams access to its most capable models, with fewer safeguards.
At a glance
- Anthropic has merged Glasswing and its original Cyber Verification Program into one revamped CVP, announced on Tuesday, with three tiers that each carry their own verification requirements and security controls.
- Every tier gets Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models, and the tiers differ in permitted work, from incident response up to testing power grids and flight systems.
- The fivefold multiplier rests on a survey of a limited number of partners, and Anthropic's disclosure dashboard in May named human triage and review as the rate-limiting step.
If you missed the spring: according to Anthropic, Glasswing launched on April 7, 2026 around Claude Mythos Preview, an unreleased model Anthropic said can surpass all but the most skilled humans at finding and exploiting vulnerabilities. Its unveiling raised fears that AI could hack software before it had been secured. On June 2, 2026 the program added about 150 organizations in more than 15 countries, including NATO and ENISA.
Glasswing partners logged at least 129,000 verified vulnerabilities in four months
The headline count comes from Glasswing partners: at least 129,000 verified vulnerabilities between April and July. Anthropic's own scanning of open-source code found 5,500 more between April and October. More than 33,000 have so far been rated critical or high severity.
Anthropic says these figures are likely an undercount and expects the true impact to be at least five times higher, since the data comes from a survey of a limited number of partners.
For scale, Build Fast with AI reports that the first-month results, published on May 22, 2026, had Mythos scanning over 1,000 open-source projects and flagging 23,019 vulnerabilities, 6,202 of them estimated high or critical. By the same account, independent firms checked a sample of 1,752 findings and confirmed that 90.6% were real bugs.
All three tiers get Opus 5.5, Sonnet 5.5 and Mythos 5.1
The revamped Cyber Verification Program merges two programs Anthropic has run for the past six months. Glasswing gave organizations securing critical software access to Claude Mythos, Anthropic's most cyber-capable family of models. The original CVP gave vetted security teams reduced safeguards on Claude Opus and Sonnet.
Each new tier has its own verification requirements and security controls, but all three share the same models: Claude Opus 5.5, Sonnet 5.5, Mythos 5.1 and future models. The Defense tier covers work such as incident response and malware analysis. Security teams, critical infrastructure operators, open-source maintainers and researchers with a record of reported vulnerabilities can apply.
The Red Team tier adds authorized penetration testing and red-teaming, but only organizations can apply. The Specialized tier has the fewest restrictions and is reserved for a small group of organizations authorized to test safety-critical systems such as power grids, flight systems and interbank transfer infrastructure. Anthropic vets each member together with the US government, and existing Glasswing members will move into this tier.
The Red Team tier adds pentesting and the Specialized tier has the fewest restrictions
According to Anthropic, the Specialized tier offers qualifying security professionals "reduced blocking classifiers". A classifier here is a filter that checks each request and response and blocks anything that looks like attack work. Picture a hardware store that questions every customer who wants lock picks, while a verified locksmith gets served without the questioning.
The tiers also move the old boundaries. According to Build Fast with AI, the original rules let partners use Mythos only for finding and fixing vulnerabilities in their own or open-source software, and offensive use, even authorized penetration testing, was outside the program. Under the new Red Team tier, pentesting is part of the program.
By May 22, 97 of 1,596 disclosed vulnerabilities had been patched
According to Ciphers Security, the Glasswing pipeline runs in four steps. Partners submit code or grant read access, and Mythos scans on its own, generating proof-of-concept exploits in sandboxes to confirm a bug is exploitable. A human validation team reviews each finding, and validated findings go to the code owner for patching.
As of May 22, 2026, Anthropic's disclosure dashboard showed 1,596 disclosed vulnerabilities across 281 open-source projects, 97 of them patched, and named human triage and review as the rate-limiting step. One account, from Build Fast with AI, says less than 1% of Mythos-found vulnerabilities had been patched.
In our view, adding more finders without a stated plan for more human reviewers and fixers will likely widen the gap between bugs found and bugs patched. Reuters also describes no method behind the fivefold multiplier, which rests on a survey of a limited number of partners.
Who clears the government vetting
The announcement gives no number of organizations per tier, no verification timeline and no detail on how the joint vetting with the US government works in practice. Existing Glasswing members will move into the Specialized tier, so the first thing to watch is how many newcomers join them. No date has been given for the next set of vulnerability figures, which would show whether the fivefold estimate holds up.
Related stories
- Anthropic's OSS Scanner skips human review on bug reports
- A Mythos-found HFS bug was exploited a day after disclosure
- Claude's workarounds take every Anthropic eval offline
- Anthropic test agents reached a State Department visa form
- Anthropic model sent police a fake murder tip
- Anthropic's weapons ban now names the software too
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
