Project Glasswing

Anthropic-led initiative (April 2026) to secure critical software using Claude Mythos Preview, a frontier model that finds and exploits vulnerabilities at near-expert-human level, deployed defensively with major industry partners.

Glasswing exists because Mythos Preview already found thousands of high-severity zero-days in every major OS and browser, with exploits developed autonomously in many cases. Anthropic is not releasing Mythos Preview broadly; goal is defensive scale first while safeguards mature. Source: anthropic.com/glasswing, 2026-04-07

Partners and resources

Launch partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Anthropic committed up to $100M in Mythos usage credits plus $4M to open-source security orgs; 40+ additional critical-infrastructure maintainers get access. Source: anthropic.com/glasswing, 2026-04-07

The original source thread adds three operational constraints worth preserving: Anthropic said it did not plan to make Mythos Preview generally available, committed to report back on what partners learn, and separated the Glasswing initiative from the Mythos Preview system card. Treat the bookmark as restricted defensive-deployment evidence, not as a normal model-routing option. Source: X/@AnthropicAI thread, 2026-04-07; Source: Claude Mythos Preview system card, 2026-04-07

Example findings (patched subset)

Technical report: Anthropic Frontier Red Team blog (Mythos Preview). Source: X/@AnthropicAI thread, 2026-04-07

Relevance to Kevin

Validates agent-powered vuln scanning (Security and Review Skills, security automations). Glasswing is vendor-scale defensive deployment; Mythos is not a general coding model. Claude Fable 5 (June 2026) is the generally available Mythos-class model with safeguards; Claude Mythos 5 (same underlying model, fewer safeguards) remains restricted to Glasswing partners until trusted-access expands. Source: X/@claudeai thread, 2026-06-09 Cross-ref Claude Code Harness for harness-side security practices.

For Long Live Hard SaaS, Glasswing is evidence for harnessed bug discovery rather than evidence that SaaS is dead. Cloudflare's writeup says generic coding agents are the wrong shape for broad vulnerability coverage and describes a multi-stage harness with narrow scopes, adversarial validation, parallel hunts, dedupe, tracing, and reporting. That is a model-plus-process system, not one-shot bug-free software. Source: Cloudflare Blog, 2026-05-18

The reviewed Eugene Yan artifact is the compact bookmark form of Cloudflare's harness: Recon, Hunt, Validate, Gapfill, Dedupe, Trace, Feedback, and Report. It should route readers to Harness Engineering for the reusable loop and back here for the Project Glasswing / Mythos-specific deployment context. Source: X/@eugeneyan and local image review, 2026-07-04

Signal

42,231 likes, 15,374 bookmarks on announcement tweet. Source: X/@AnthropicAI, 2026-04-07


Timeline