Claude Mythos Preview and Project Glasswing
Anthropic showed a model that finds vulnerabilities and builds working exploits, and declined to release it generally: access runs only through a closed consortium.
Why it matters
A developer published evidence that a model had moved from finding bugs to assembling working attack chains at scale, and withheld it on that basis.
The publication is dated 7 April 2026. Anthropic reports that Mythos Preview is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser. In testing the model developed working exploits 181 times against vulnerabilities in the Firefox 147 JavaScript engine, where Claude Opus 4.6 did so only twice in several hundred attempts. The model produced 595 crashes at tiers 1 and 2 and achieved full control flow hijack on ten separate, fully patched targets; thousands of additional high- and critical-severity vulnerabilities were also identified. The model does not become generally available: access is given first to a limited group of critical industry partners and open source developers under the Project Glasswing initiative. The publication does not name the participants in that initiative.