Anthropic's Mythos Found Millions of Security Vulnerabilities

7 Apr 2026 · 11 min · 6 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Anthropic’s Project Glasswing, an internal/partner-only security initiative using the Claude Mythos Preview model to scan first-party and open-source code for vulnerabilities before a public release, amid claims that “security of basically all software” could otherwise “explode.”

Guest backgrounds

No guests are mentioned; the host is Jaden Schaefer.

Key claims

Anthropic says it identified thousands of zero-day vulnerabilities (many critical) over weeks, including issues 10–20 years old; the model is “more powerful” than all but the most skilled humans at finding vulnerabilities; it’s not publicly available and is shared with 40 partner orgs.

Notable examples

partners named include Amazon, Apple, Broadcom, Cisco, CrowdStrike, Linux Foundation, Microsoft, and Palo Alto Networks; Anthropic cites prior incidents like exposing ~2,000 source code files and ~500k lines via Cloud Code v2.188.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Overview of Project Glasswing

0:45 to 1:40

Discussion on Anthropic's new initiative aimed at securing critical software.

“And there's vulnerabilities everywhere that can be found.”

The Implications of Software Vulnerabilities

1:40 to 2:50

Exploration of the existential crisis posed by software vulnerabilities and the role of security researchers.

“All right, let's talk about what's going on with Anthropic.”

Anthropic's Powerful Model: Claude Mythos

3:20 to 6:40

Insight into Anthropic's Claude Mythos model and its distribution to prominent tech organizations.

“So honestly, that's a pretty wild point.”

The Risks of Releasing Mythos

6:40 to 8:10

Discussion on the concerns about releasing the Mythos model and its potential misuse.

“And the other thing that I think is important is everyone's like, you know, well, why don't they just, like, not release it?”

Growth and Revenue of Anthropic

8:10 to 9:10

Analysis of the rapid growth and revenue increase of Anthropic.

“The company accidentally caused a thousand code repositories on GitHub to be taken down because they were trying to clean the mess and they're, you know, launching cease and desists.”

The Future of AI and Security

9:10 to 10:40

Consideration of the future implications of AI models on cybersecurity and software integrity.

“I mean, the end of 2025, they were at$9 billion in run rate and run rate revenue.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Welcome to the podcast. I'm your host, Jaden Schaefer. Today on the show, we are talking about Project Glasswing from Anthropic. They just tweeted this out like an hour ago. They said, Introducing Project Glasswing, an urgent initiative to help secure the world's most critical software. It's powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. Okay, there is this crazy project. It's not released to the public. They're sending this out to security researchers, and they've pledged$100 million, essentially, to big companies like Microsoft to go and test all of the open source software, all of the software in the world to find the vulnerabilities and fix it before they release this to the public.

0:41Because they said, basically, this is going to be an existential crisis for code, because everything can be hacked. And there's vulnerabilities everywhere that can be found. So they're trying to like, give it to the security researchers to fix everything before they release it. And it's not just for software, this is just a general, insanely good model, but that's just something that they're concerned about. So we're going to get into all of that on the podcast without too much doomerism. I think there's a lot of optimism, but this is definitely an absolutely massive drop in model. And speaking of AI models, if you want to test all of the top AI models, everything from Anthropic to OpenAI to Grok to Gemini to 11 Labs for audio, tons of cool image models, go check out my startup, AIbox.ai for$8.99 a month.

1:23You get access to over 80 of the top audio, image, text, video models. OpenAI is sore, which is going to get discontinued because it costs$130 to generate a video for them. But for you, it's very cheap. So if you want to check it out, go check out AIbox.ai. Hope that saves you a ton of money and you get access to everything in one spot. All right, let's talk about what's going on with Anthropic. So they just released this, what they're calling, of course, their, quote, most powerful model yet. Now, what's interesting is usually everyone's like, this is our, you know, most capable model. This is most powerful.

1:54This sounds a little bit ominous. There was a leaked memo where they were actually calling it that. So this is what they told the world. This is just kind of internally. And basically, this right now is limited to, it's just kind of a debut for a bunch of the top organizations as part of a new security initiative in which there's 40 partner organizations, and they're all deploying the model across a bunch of different quote unquote defense security work areas. And they're basically trying to secure critical software before this goes out to the general public. I think they didn't specify exactly what this was trained on.

2:29So they're not saying like, hey, we specifically trained this on like cybersecurity work or kind of like source code. But right now the preview that they're sending out to everyone is being used to scan both first party and open source software systems. They're looking for code vulnerabilities. And they're just giving this out to a lot of the big organizations. What they're saying right now is that over the last few weeks, they were using it internally and they were able to identify, quote, thousands of zero-day vulnerabilities, many of them critical. So they're saying a lot of the vulnerabilities are one to two decades old.

3:03So they have this new software, they run on code bases, and they're finding vulnerabilities that have been around for 10 to 20 years in literally everything and they're just they're concerned they really can't release this to the public because they're like as soon as we release it to the public security of basically all software is going to explode so now they're trying to get this out to people that can fix it before they release it it's like the model's so powerful they can't release it till we fix all the software in the world and so they're like okay everyone uh we really want to release this new model because we're probably gonna make a lot of money and beat open ai but like we're not held back by anything other than that we're going to destroy the entire internet and all software combined.

3:44So honestly, that's a pretty wild point. And I mean, this is just crazy. Apparently, this isn't just like a software model. It's a general purpose model. It's the new tier. So they have like Opus, Sonnet. They have these other tiers. This is going to be Mythos and is kind of the next highest tier. They have a higher tier. I guess they're not continuing with the Opus model or the Sonnet model. but kind of the opus being the best they actually are creating a new thing because it is such a big step up which is really interesting it has really strong agentic coding and reasoning skills so everyone using Claude Cowork which I've been shouting from the rooftops and Claude Code recently are going to love it and it's basically the most sophisticated and high performance model it can do complex tasks and it can do a lot of agent building and coding so who is Anthropic giving this to in order to go and, you know, put it out onto all of the different, you know, test all the code bases in the world and fix all these vulnerabilities.

4:44They're giving it to Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft and Palo Alto networks. All of those people are going to share what they've learned from using the model so that the rest of the tech world can benefit from it. It's not going to be made publicly available. So we don't know exactly when they're going to actually launch it feels it's kind of like a wait and see. They're like, look, we're giving this to all of the biggest tech companies. We're going to see what they can do with it, what they can fix with it, what they can teach us about it. And then we'll basically decide on how and when we get this out.

5:16Anthropic says that right now they have engaged in, quote, ongoing discussions with a bunch of federal officials about the use of mythos. Although one would imagine that I think a lot of those discussions are pretty complicated by the fact that Anthropic and the current administration are having a whole bunch of legal battles. Pentagon labeled the AI lab a supply chain risk because Anthropic didn't let them use their AI model for autonomous targeting or surveillance and basically had a bunch of different rules and they didn't want to follow them. Or maybe they just didn't want a precedent of having rules, I think would probably be a fair characterization.

5:49But in any case, news of this right now is originally something that got leaked a little while back. We kind of reported on it. There was a data security incident that got reported by Fortune. And there was a blog with some, you know, some is like an unpublished blog draft somewhere that someone found. And it alluded to this. So we kind of knew that this was coming. We didn't realize how wild this was. Basically, Anthropic attributed that leak in particular to quote unquote human error. So they're like, look, it wasn't like an AI model leaking this. The AI model didn't do it. but what they did say is that capybara is the new name for a new frontier of model it's larger and more intelligent than opus so it's actually going to be called capybara that's i guess their their latest i don't know where they get the names for these it's almost as bad as bard in my opinion but whatever so capybara is going to be better than opus but mythos is kind of the umbrella of models right they kind of do these these pushes where they'll make an umbrella of models and they go from best and then like medium if you want to save power and then kind of worse if you want to like run it on locally or on an edge device or something like that so capybar is the new one it's going to replace opus and according to all these leaked documents it is by quote by far the most powerful ai model we've ever developed um in this leak anthropic claimed that this new model was going to far exceed the performance in areas like software coding academic reasoning and cyber security and evidently the cyber security was one of the big areas they were concerned about because now they're pushing this, you know, making this big push.

7:21When they released it, you know, if you kind of look at some of the current public models, like, sure, you could use something like ChatGPT or Gemini or anything for some sort of cybersecurity issue, but it feels like this one is so advanced, they're concerned about the threats of this being weaponized by bad actors, it's going to find bugs and exploit them, and because they found, they just alone found so many zero-day exploits and so much, you know, infrastructure and software. They're, you know, even with bad relationships with the government, they're giving this to the government, they're giving this to every major organization and telling them, look, like, use this and try to fix it before something like this gets out.

7:58And the other thing that I think is important is everyone's like, you know, well, why don't they just, like, not release it? If it's so dangerous, why don't they keep it forever? And the reality is these models are all getting better and better and someone in China is gonna make an open source version of this and release it either way. So I think it's in everyone's best interest to take this, use it to fix the software as fast as possible because if Anthropic was able to create it, other people inevitably are going to be able to create it eventually as well. Last month, Anthropic accidentally exposed about 2 ,000 source code files and more than half a million lines of code that was kind of linked to a mistake in the launch of version 2.188 of Cloud Code and their software package.

8:34The company accidentally caused a thousand code repositories on GitHub to be taken down because they were trying to clean the mess and they're, you know, launching cease and desists. In addition, I think what not a lot of people know is that Anthropic right now is absolutely exploding in revenue. If you take a look at the numbers, just how fast Anthropic is growing right now, they put out a tweet a couple days ago where they said, our run rate revenue has surpassed$30 billion, up from$9 billion at the end of 2025. As demand for Claude continues to accelerate, this partnership gives us the compute to keep pace.

9:07So the revenue is exploding. They're making a lot of these partnerships. I mean, the end of 2025, they were at$9 billion in run rate and run rate revenue. And now they're past 30 billion triple since the end of last year. I mean, we're three months in. So this is absolutely exploding. Open AI is concerned. Everyone's concerned. Obviously, the software industry is concerned with what is, you know, coming down the pipe here. Something that's interesting is as far as that whole$9 million at the end of last year goes. They said, when we announced our Series G fundraise in February, we shared that over 500 business customers were each spending over a million dollars on an annualized basis.

9:47Today, that number exceeds 1000 doubling in less than two months. That is crazy. Their growth is absolutely astronomical. And I think where Anthropik really crushed it, opening eyes kind of targeting the everyday user who maybe will spend $20 a month, and many will just use it for free. Anthropic is targeting business users. I personally am spending hundreds and hundreds of dollars a month on it, loving every second of it because I'm getting so much done. But I think they know their customer, they're finding the power users that are really pushing AI to its limits. And I mean, even in the case of giving it to all these cybersecurity people, it's like they basically made the problem.

10:23They're like, we made a model so, you know, good, it discovered all the cybersecurity issues. And now you need to use our model to fix the problem that we basically made. And so they're giving it out. But they are, in all fairness, they are pledging about$100 million. They're giving to all of these different companies and credits and tokens. And they're like, look, we're gonna give you guys$100 million to run through and fix all of the software in the world. Because we know we made this problem, and we want to get the model out. So that's pretty fascinating. They're literally paying Microsoft to fix the security vulnerabilities of the world, because their model is about to crush shit.

10:58Everyone, thank you so much for tuning into the podcast today. If you enjoyed this episode, I mean, this was an absolute wild ride. Make sure to test all of the latest models from OpenAI, Anthropic, Gemini, test them side by side. I think this is so important to understand the capabilities of all these models. And you can do that at AIbox.ai for$8.99 a month. And you also get audio, image, video, everything in one place. Hope that it is a phenomenal product for you. Put a lot of blood, sweat and tears into it. So let me know what you guys think. Hope you have a fantastic rest of your day and I will catch you in the next episode.

From the publisher
In this episode, we explore Anthropic's ambitious Project Glasswing, aimed at securing critical software vulnerabilities with the powerful Claude Mythos Preview model. With a $100 million pledge to major tech companies, this initiative is designed to address the urgent risks in software security before its public release.


Chapters
00:00 Introduction to Project Glasswing
00:40 The Power of Claude Mythos Preview
01:40 Initial Findings and Concerns
03:58 Deployment and Partnerships
07:39 Revenue Growth and Business Strategy
09:59 Conclusion and Future Outlook
  See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

More from AI Today

All 897 episodes
Anthropic's Mythos Found Millions of Security VulnerabilitiesAI Today · 11 min
Listen in VO