Why Anthropic Is Not Releasing Mythos, Its Most Powerful Model Yet
Anthropic built an internal model called Mythos that found a 27-year-old OpenBSD bug and a 16-year FFmpeg flaw that millions of automated tests missed. Instead of releasing it, they launched Project Glasswing to give defenders a head start on patching.

The coverage of Mythos, Anthropic's most capable internal model, has been almost entirely about the benchmark numbers. SWE-bench: 93.9 percent. Cybersecurity: 83.1 percent. A 27-year-old OpenBSD vulnerability that could crash servers remotely. A 16-year-old flaw in FFmpeg that five million automated tests had never caught. These numbers are striking and they deserve attention. But they are the mechanism, not the story. The story is what Anthropic chose to do with a model at this capability level, and why that choice is the most significant thing about Mythos.
The decision was to not release it publicly. Instead, Anthropic stood up Project Glasswing, a defenders-first disclosure program that gives this model's capabilities to infrastructure defenders before anyone else. AWS, Apple, Google, Microsoft, NVIDIA, Cisco, CrowdStrike, JP Morgan, and more than forty other organizations got access to Mythos first. The model scans their infrastructure for vulnerabilities. When it finds something, the finding goes to the organization that owns the infrastructure first. They get time to patch it before any disclosure happens publicly.
This is an inversion of how the security industry has worked for a decade, and that inversion is the actual breakthrough.
The Benchmark Numbers Are Not the Story
Let me be precise about what the numbers show. Mythos is substantially more capable than Opus 4.5, which is already a strong coding model. On SWE-bench, which measures how well a model can resolve real GitHub issues in production codebases, Opus sits at 80.8 percent. Mythos sits at 93.9 percent. That gap is not incremental. It represents a qualitatively different level of ability to understand a large codebase, identify the source of a bug, write a fix, and verify it works without introducing a regression.
The cybersecurity benchmark is more consequential. At 83.1 percent versus Opus's 66.6 percent, Mythos can find vulnerabilities that Opus would miss. And the qualitative descriptions of what Mythos actually found illustrate why this matters at a practical level. The 27-year-old OpenBSD bug was not a new vulnerability. It had been in the codebase for 27 years. Humans had read that code thousands of times. Automated testing systems had run over it millions of times. Mythos found it because it can hold a large amount of code context simultaneously and reason about interactions between components in a way that neither humans reading under time pressure nor test suites scanning for known patterns can replicate.
The FFmpeg flaw is in the same category. Sixteen years old. Five million automated test runs. Not found. Mythos found it in a single analysis session. The flaw allowed, under specific conditions, a specially crafted media file to crash or potentially compromise a system running FFmpeg. FFmpeg is embedded in billions of devices and applications. The exposure surface for that flaw, unpatched, was enormous.
The Linux privilege escalation bugs that Mythos found share the same characteristic: known systems, long in service, reviewed by skilled teams, carrying vulnerabilities that remained invisible until a model with the right combination of context depth and reasoning capability looked at the full interaction graph.
But here is why these numbers are not the story: they tell you what the model can do, not what happens to that capability in the world. A vulnerability-finding model is a two-sided capability. It can help defenders find and patch flaws before they are exploited. It can also help attackers find flaws to exploit in systems they do not own. The capability is identical. The governance determines which use case dominates. The benchmark scores are impressive. The governance model is the innovation.

For a Decade, Attackers Got to Vulnerabilities First
The asymmetry in security has been consistent and depressing for a long time. In most cases, attackers find vulnerabilities before defenders do. The economic logic behind this is straightforward. An attacker who finds a zero-day vulnerability can use it immediately, sell it on the vulnerability market for significant sums, or hold it for strategic future use. There is a return on the discovery. A defender who finds a vulnerability has to report it, coordinate a fix, test the patch, push it through an update cycle, and communicate the update to users before they see any benefit. The attacker's timeline is shorter than the defender's, and the attacker's incentive structure is simpler and more immediate.
This asymmetry has produced a shadow economy in discovered vulnerabilities. Governments, criminal organizations, and independent security researchers all participate in finding and trading exploits. Broker markets for zero-day vulnerabilities have existed for years, with prices for critical exploits reaching into the millions of dollars for the most widely deployed and hard-to-patch systems. The people responsible for defending infrastructure have generally been working with less information and less speed than the people trying to break in.
AI changes this calculus fundamentally, but only if the AI capability is deployed on the defender side first. A model that can scan a large codebase for vulnerabilities faster than any human team, at a fraction of the cost, with the ability to chain multiple small flaws into full attack paths the way an expert attacker would, is worth more to a defender than to an attacker if the defender gets access first. The attacker already has time advantage and financial incentive. What they have lacked, until now, is speed and scale at the level of reasoning required to find complex, chained vulnerabilities. The defender has legitimate access to the systems and the incentive to patch. What they have lacked, until now, is the speed to find vulnerabilities before the attacker does.
Glasswing gives defenders access to model capability at attacker speed and scale. That is the asymmetry flip that the benchmark numbers enable but do not describe.

What Changes When Defenders Get There First
The concrete change is that the patch comes before the exploit. This sounds obvious but it has not been the default state of the security industry for the past decade.
The industry default has been reactive patching. A vulnerability is discovered, either by a researcher following responsible disclosure or by an attacker. If discovered by a researcher, it is disclosed under a 90-day responsible disclosure window. The vendor patches. The patch goes out. Users who update promptly are safe. Users who do not update remain exposed, sometimes for years. If discovered by an attacker, the vulnerability is used silently until it is detected in the wild, at which point the patch race begins with unknown exposure already having occurred.
Glasswing's model is proactive. The defender gets the finding before anyone else. The patch is applied before any attacker knows the vulnerability exists. The 90-day disclosure timeline Anthropic committed to means that after 90 days, the finding is made public, which incentivizes actual patching rather than indefinite delay. But the public disclosure happens after the patch, not before.
This only works if the defenders-first distribution holds. If the vulnerability-finding capability were released as a general tool, it would be available to attackers within hours, defeating the entire purpose of the disclosure model. The decision not to release Mythos publicly is not timidity or excessive caution. It is the only configuration in which the capability produces a net security benefit rather than accelerating the arms race in the attacker's favor.
Consider what happens in the counterfactual. Mythos is released publicly. Within 48 hours, security researchers, penetration testers, and attackers alike are running it against targets. The defenders do not have a head start. They have the same access at the same time as everyone else. The 27-year-old OpenBSD vulnerability gets found by multiple parties simultaneously. Whoever acts fastest wins. Attackers, who have clear and immediate incentives to act, often act faster than organizations with large governance and review processes for deploying patches. The asymmetry does not improve. It might get worse.
Glasswing avoids this by creating a protected window between discovery and disclosure during which only defenders have the information.
The $100 Million Commitment Is a Signal, Not Just a Number
Anthropic committed $100 million in model credits to Glasswing partners. They donated $4 million to open-source security projects. They pledged 90-day public disclosure on every vulnerability found. These commitments are design decisions that determine whether the program has real teeth or is primarily a public relations exercise.
The $100 million in credits makes the scanning economically accessible to organizations that could not otherwise afford continuous AI-powered vulnerability scanning at this model quality. Large infrastructure operators like AWS and Microsoft have the resources to run expensive security programs regardless of what Anthropic does or does not provide. The smaller organizations in the Glasswing consortium, regional banks, healthcare networks, government contractors, municipal infrastructure operators, do not. The credit commitment means Mythos can scan their codebases too, which matters because the vulnerability surface that gets covered is broader than what commercial security scanning could reach economically.
The $4 million to open-source security matters because the most widely deployed software in the world is open-source. The Linux kernel runs inside most web servers, most mobile devices, and most cloud infrastructure. OpenSSL handles encrypted communications across a massive fraction of internet traffic. SQLite is embedded in more systems than most people can enumerate. These projects are maintained by small teams with limited budgets and enormous responsibility. A vulnerability in OpenSSL found by a well-resourced attacker and patched slowly by an underfunded maintenance team is a genuinely dangerous situation that affects a large fraction of connected devices. Investment in open-source security infrastructure changes that dynamic at the ecosystem level, not just for the specific organizations in Glasswing.
The 90-day public disclosure pledge creates external accountability. Without it, organizations that receive vulnerability findings could sit on them indefinitely, patching at their own pace without any pressure to actually deploy the fix. With the 90-day commitment, the clock runs. The patch has to ship. Public disclosure happens regardless of whether the organization has completed their remediation, which means there is real pressure to finish the patch before the disclosure date. This is modeled on the responsible disclosure norms that security researchers have used for years, but applied to AI-discovered vulnerabilities at scale.
A Concrete Illustration of What the Asymmetry Costs
Consider a small restaurant that runs its business on a software platform for online ordering and table reservations. The platform includes a library that handles data serialization. Three years ago, a vulnerability was disclosed in that library, a flaw that under specific conditions allows an attacker with network access to read database records. The platform vendor is aware of the disclosure but the update cycle is slow, the patch involves testing changes to the data layer across many restaurant configurations, and the restaurant has not applied any pressure to expedite the fix.
An attacker scanning for exposed systems using automated tools finds the restaurant's ordering endpoint within a few weeks of deploying a targeted scan. The breach takes a weekend to execute. The forensic investigation that follows costs $22,000. PCI compliance fines for the way payment data was stored cost $18,000. State data breach notification requirements mean physical letters to every affected customer, costing $7,000 in printing, postage, and the notification service. Total exposure: $47,000, for a business with eight employees and annual revenue that does not absorb that amount easily.
If the vulnerable library had been flagged by a Glasswing-style scan during the disclosure window, the fix is a library update that the vendor prioritizes because it has been directly notified and the 90-day clock is running. The restaurant's software is patched before any attacker runs the scan. Cost: one vendor update cycle. A few hundred dollars in developer time for testing. The $47,000 exposure does not exist.
This is not a hypothetical edge case. It describes the actual cost structure of small-business data breaches. The specific numbers vary by breach type and size, but the pattern is consistent: an unpatched vulnerability in widely deployed software gets found, and the question is only whether it gets found by someone whose interest is in fixing it or by someone whose interest is in exploiting it.
What the Glasswing Model Gets Right About Consequential Capabilities
The instinct behind Glasswing is that some capabilities are too consequential to release and then observe what emerges. The normal model for technology deployment is: release it, watch the use cases that develop, address harms reactively as they surface. This model works tolerably well for capabilities with a limited or recoverable blast radius. It works badly for capabilities that can be used to compromise critical infrastructure at scale before any reactive response can be mounted.
Mythos can chain small vulnerabilities into full attack paths. This is the part of the capability description that carries the most weight. Finding a single vulnerability is useful. Chaining vulnerabilities, the way an expert attacker does, moving from a low-privilege entry point through a series of individually minor flaws to full system compromise, requires a level of reasoning that automated scanners have not historically been able to do. Human penetration testers do it, and they are both expensive and limited in scale by the number of available hours. Mythos can do it at the scale and speed that human testers cannot match, and at a cost per finding that makes it economically viable to run continuously against large infrastructure.
Releasing that capability publicly, before defenders have had time to patch the vulnerabilities it would find, inverts the intended effect. The first users of a public release would not be defenders. They would be whoever was paying closest attention to model releases and had the fastest deployment pipeline. Attackers who specialize in vulnerability research are, by definition, paying close attention to exactly these developments. The defenders-first model reverses this by creating a window during which only defenders know what was found.
Whether Glasswing is a permanent governance model for Mythos or a transitional structure for a capability that will eventually be released more broadly is an open question. Anthropic has not committed to a permanent restricted deployment. What they have committed to is not releasing Mythos until the governance infrastructure can adequately limit the attack surface of the capability itself.
That is a conservative position. It is also the defensible one for a model that can find 27-year-old vulnerabilities in the foundations of the infrastructure the internet runs on, and chain them into attack paths that expert human security researchers took years to identify.
The benchmark numbers are impressive. The SWE-bench score and the cybersecurity benchmark are worth discussing. But impressing people with benchmark numbers is not what Glasswing is for. The point was to get to vulnerabilities before attackers do. Glasswing is the mechanism that makes that possible in a way that actually improves the security posture of defenders rather than just accelerating a race that attackers were already winning. That is the story. The benchmarks just explain why the story is now possible when it was not before.
That is exactly what we do at AI DOERS. Book a private 30-minute call with Madhuranjan Kumar and we will map the fastest path to it for your specific business.
Book your call →
