anthropic
Held-back Mythos 5 now scans enterprise code
Promtime
anthropicAnthropic put Claude Mythos 5, the model it withheld from a public release, into its Claude Security vulnerability scanner on Friday and added a Defender Advantage Fund carrying $35 million in credits for open source security work. The rollout, reported by The New Stack, opens Mythos 5 to Claude Enterprise customers as a public beta.
At a glance
- Developers and security teams point the scanner at repositories their organization owns; Mythos 5 returns findings and suggested fixes, while direct access to the model itself remains closed to enterprise users.
- Usage is metered at $10 per million input tokens and $50 per million output tokens, and administrators have to switch the feature on before their developers can run it.
- Until now Mythos 5 reached only about 150 partners in Anthropic's Project Glasswing program, while the public got Fable 5, the same model shipped in June with much stricter guardrails.
Anthropic is testing whether capability it considered too dangerous to hand out directly can be sold safely as a managed service. The bet appears to rest on the harness rather than the weights: enterprise users receive patches and alerts, never a prompt box pointed at the model. That holds only as long as the ownership boundary holds, and modern codebases are assembled largely from open source libraries that ship far beyond the repository being scanned.
Mythos 5 enters public beta for every Claude Enterprise customer
Claude Security launched earlier this year as an enterprise tool that lets development teams scan a codebase for security vulnerabilities and patch them. Friday's upgrade puts Mythos 5 behind that workflow, in a public beta open to every Claude Enterprise customer, with administrators enabling it for their users.
Developers and security teams then scan their repositories with Mythos 5 at the helm and receive suggested fixes when it finds an issue, without ever interacting with Mythos 5 directly. Anthropic says Claude Security "uses Mythos 5 to scan code you own". Token usage is billed at $10 per million input and $50 per million output.
A new fund puts $35 million in credits into open source security
Anthropic also launched the Defender Advantage Fund, shortened to 0xDAF, a pool of $35 million in credits for finding and patching vulnerabilities in open source software. The announcement pairs it with the scanner upgrade and the partner integrations as one set of changes.
Beyond its own tooling, Anthropic is also working with other cybersecurity companies to help them integrate Mythos 5 into their products. Anthropic says it and its partners have abuse prevention measures in place to verify the model stays within its intended scope.
The Cyber Verification Program, which Anthropic launched before Friday's changes, lets vetted defenders run dual-use cybersecurity work on Opus and Sonnet with fewer blocks. The program covers dual-use work, the category of security research that can serve attackers as readily as defenders.
Fable 5 shipped in June as Mythos 5 with strict guardrails
Mythos 5 is the model Anthropic judged too capable in high-risk domains for a public release. In June Anthropic shipped Fable 5 instead, essentially Mythos 5 with very strict guardrails, and Fable 5 was later banned and then unbanned by the U.S. government. Mythos 5 itself went to roughly 150 partners in the Project Glasswing program.
In the announcement, Anthropic sets out why it is widening access now: risk concentrates where a user has a direct line to the model, and it drops when the only thing leaving the system is a patch or a security alert.
The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses. But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower.
When verified defenders get Mythos
Anthropic says organizations in its Cyber Verification Program will receive safeguarded access to Claude Mythos soon, without naming a date. Ownership of scanned code is the looser boundary: as The New Stack noted, a developer who clones a widely deployed open source library into a company repository would get the same findings an attacker would be hunting for.
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
We only use your name and avatar from Google. We never store your email address.
