Anthropic launched Project Glasswing in April 2026 to tackle a growing cybersecurity problem: software has more security flaws than humans can realistically find and fix.
The company gave about 50 organizations early access to a new AI model called Claude Mythos Preview, designed specifically to search for vulnerabilities in code.
The results exceeded expectations.
>In just one month, the system found more than 10,000 high or critical security vulnerabilities.
>Scanning over 1,000 open-source projects uncovered 23,019 total issues
>6,202 were rated high or critical severity.
>Independent reviewers confirmed that about 90.6% of the findings were real problems.
Several organizations reported major discoveries:
>Cloudflare identified around 2,000 bugs, including 400 high or critical ones.
>Mozilla fixed 271 vulnerabilities in Firefox version 150, more than 10 times the number fixed in the previous release.
>The project also rediscovered old flaws, including a 27-year-old vulnerability in OpenBSD and a 16-year-old issue in FFmpeg.