AI safety
Anthropic's Mythos finds 6,202 critical software flaws
AI vulnerability-hunting, with independent receipts. The brief.
The answer
Anthropic says Claude Mythos flagged 6,202 critical open-source flaws; a sample validated 90.6%.
What happened
In a 26 May update on Project Glasswing, Anthropic said Claude Mythos Preview scanned more than 1,000 open-source projects and flagged 23,019 issues, of which 6,202 rated high or critical severity. Six independent security firms assessed a sample of 1,752 of those findings; 90.6% (1,587) were valid true positives and 62.4% (1,094) confirmed high/critical — a clean signal, stated as a sample rather than a blanket claim. Concrete examples: a certificate-forgery flaw in wolfSSL (CVE-2026-5194, used by billions of devices, since patched), a 27-year-old OpenBSD flaw and a 16-year-old FFmpeg bug.
Who has it — and the catch
About 50 vetted partners — AWS, Apple, Google, Microsoft, NVIDIA, JPMorgan, Cloudflare, Mozilla and others — have defensive-only access. Their own bug-finding reportedly rose more than tenfold (Cloudflare alone reported ~2,000 bugs; Mozilla found 271 in Firefox 150). Mythos itself stays restricted: the same capability that helps defenders find flaws would help attackers build exploits.
Anthropic said the relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity.
What's next
Watch patch velocity, not find counts. The Glasswing vulnerability dataset isn't fully public yet — aggregate numbers and examples only, while patches continue to ship. The durable question: can the repair side scale as fast as the discovery side? Anthropic's OpenSSF partnership and free tooling are a start; the structural under-resourcing of open-source maintenance is the harder, longer-term problem.
Mythos has already helped its partners find more than ten thousand vulnerabilities overall just a month after Glasswing's launch … the company said that its partners' rate of bug-finding has increased by more than a factor of ten.
Frequently asked questions
What did Mythos actually find?
Is this tool public?
What is Anthropic doing about the patching problem?
Sources
- Project Glasswing: An initial update — Anthropic, 26 May 2026
- Anthropic says Mythos has already found more than 10,000 vulnerabilities — Engadget, 26 May 2026
- Anthropic: Claude Mythos identified 10,000+ software flaws — Help Net Security, 26 May 2026
- Anthropic's Mythos finds 10,000 critical software flaws — Techzine, 26 May 2026