Anthropic's Mythos Model Discovers Security Vulnerabilities Faster Than Teams Can Patch
What
Anthropic's Claude Mythos model has been deployed under Project Glasswing to find software vulnerabilities in critical systems at a rate that has outpaced human patching teams [1]. Microsoft was an early partner, holding emergency cross-team engineering meetings to address the volume of Mythos-discovered flaws [1]; by May 2026, Mythos had reportedly identified over 10,000 software vulnerabilities [2]. In a separate research session, Mythos autonomously found mathematical weaknesses in the HAWK post-quantum signature standard and a reduced-round version of AES-128 over 60 hours at approximately $100,000 in API costs [4]. Anthropic frames the program as a race to fix flaws before adversarial governments deploy equivalent tools [1].
Why it matters
The core tension is that AI-driven vulnerability discovery at scale benefits defenders and attackers symmetrically — the same capability that lets Anthropic find and fix thousands of flaws also signals that adversarial governments should be building identical tools [1]. The cryptographic findings, while currently impractical, show Mythos can perform genuine mathematical research rather than pattern-match on known vulnerability types, which extends the potential scope of AI-assisted attack surface analysis [4].
Open questions
Can Microsoft and other Project Glasswing partners sustain the patch velocity needed to prevent a growing backlog of AI-discovered but unpatched vulnerabilities? [1]
How will Anthropic's coordinated vulnerability disclosure process [6] handle cases where discovery speed consistently exceeds vendor remediation capacity?
The HAWK and AES weaknesses are currently impractical — at what point does further AI-assisted cryptanalysis push them toward exploitability? [4]
Microsoft engineers internally questioned whether Mythos lived up to Anthropic's capability claims [1] — will independent assessments of Project Glasswing's results be published?
Narrative
Anthropic's Claude Mythos model has become the center of a significant AI-assisted security research program. Under Project Glasswing, Anthropic gave select software organizations access to Mythos with the explicit goal of finding and fixing vulnerabilities before hackers and adversarial governments — China is specifically named — could exploit similar AI tools [1]. Microsoft was among the first partners; the company convened emergency cross-team engineering meetings to handle vulnerabilities Mythos was uncovering faster than their teams could patch [1]. By May 2026, Mythos had reportedly identified over 10,000 software flaws [2], and Microsoft's Security Response Center published a blog describing how it was adapting processes to work with AI-driven discovery at scale [3].
In parallel, Anthropic researchers ran Mythos in a focused 60-hour cryptographic research session that found mathematical weaknesses in the HAWK post-quantum signature standard and a reduced-round version of AES-128 [4]. The session cost approximately $100,000 in API fees. Crucially, the primary human interventions were motivational rather than technical: researchers repeatedly prompted the model not to give up when it concluded problems were unsolvable, urging it to find something worth publishing [4]. The discovered weaknesses have no practical impact on current systems, but the session demonstrated that Mythos can reach genuine mathematical analysis — not just pattern-matching on known vulnerability classes [4][5].
The ProPublica and Ars Technica investigation into the Microsoft partnership surfaced internal tension: at least one Microsoft engineer asked whether Mythos 'lived up to the hype that Anthropic claimed it would have had,' suggesting the model's performance was not uniformly viewed as a success inside the company [1]. The dual-use dimension runs through the entire program — the same capability that lets defenders find and fix vulnerabilities at scale is one that, in adversarial hands, could accelerate exploitation faster than any human-staffed security team could respond.
Timeline
- 2026-04: Microsoft MSRC publishes a blog describing how it is evolving its security processes for AI-driven vulnerability discovery. [3]
- 2026-05-06: Barracuda Networks publishes a CISO-level analysis asking how Mythos will change the vulnerability discovery landscape. [10]
- 2026-05-26: Anthropic's Project Glasswing update reports Mythos has identified over 10,000 software flaws. [2]
- 2026-07-28: Anthropic publishes research showing Mythos found mathematical weaknesses in HAWK and reduced-round AES-128 in a 60-hour, ~$100,000 session requiring primarily motivational rather than technical guidance. [4]
- 2026-07-29: ProPublica and Ars Technica report that Microsoft held emergency engineering meetings under Project Glasswing as Mythos discovered bugs faster than teams could patch them, with internal skepticism about Mythos's claimed capabilities. [1][9]
Perspectives
Anthropic
Deploying Mythos as a defensive tool under Project Glasswing, framing the program as a race to find and fix vulnerabilities before adversarial governments deploy equivalent AI tools.
Evolution: Consistent across the thread; no public acknowledgment of the patching-speed tension Microsoft's situation revealed.
Simon Willison
Impressed by the cryptographic research results; identifies the motivational prompting dynamic — the model declaring problems impossible and needing human encouragement to persist — as the most revealing aspect of how Mythos actually works.
Evolution: Single-pass commentary with no prior stance to compare against.
Microsoft
Publicly cooperative via the MSRC blog; internally under strain, with emergency meetings to handle discovery volume and at least one engineer questioning whether Mythos matched Anthropic's capability claims.
Evolution: Public posture is aligned with Anthropic's framing; internal reporting reveals skepticism and operational pressure not visible in official communications.
ProPublica / Ars Technica
Investigative: the story is that discovery pace has outrun patching capacity, and the dual-use risk — adversarial governments building equivalent tools — is the unstated but central concern.
Evolution: Consistent investigative posture; no prior stance in thread.
Security industry analysts (Barracuda, Dynatrace, Cloud Security Alliance)
Treating Mythos as a meaningful operational development; focused on what it means for organizational vulnerability management processes and defender readiness rather than the dual-use question.
Evolution: Uniformly analytical; no strong dissent from the broader framing.
Tensions
- Mythos finds vulnerabilities faster than Microsoft's engineering teams can patch them, creating a growing backlog of known-but-unpatched flaws. [1]
- Microsoft internally questions whether Mythos lived up to Anthropic's capability claims, while Anthropic's public framing presents Project Glasswing as a clear success. [1]
- The cryptographic weaknesses Mythos found in HAWK and AES are mathematically demonstrated but currently impractical — whether continued AI-assisted research could change that is unresolved. [4]
- Anthropic's defensive framing (fix before adversaries exploit) is in tension with the dual-use reality that demonstrating Mythos's capabilities publicly signals exactly what adversarial governments should build. [1][4]
- The $100,000 cost for a session producing currently-impractical cryptographic findings sits awkwardly against claims of Mythos as a practical, scalable security tool. [4]
Status: active and growing
Sources
- [1] Anthropic is finding bugs faster than Microsoft can fix them — Ars Technica AI (2026-07-29)
- [2] Anthropic: Claude Mythos identified 10,000+ software flaws - Help Net Security — reactive:anthropic-mythos-vulnerability-discovery
- [3] Strengthening secure software at global scale: How MSRC is evolving with AI — reactive:anthropic-mythos-vulnerability-discovery
- [4] Discovering cryptographic weaknesses with Claude — Simon Willison (2026-07-28)
- [5] Claude found mathematical flaws in two cryptographic algorithms that ... — reactive:anthropic-mythos-vulnerability-discovery
- [6] Anthropic's coordinated vulnerability disclosure dashboard — reactive:anthropic-mythos-vulnerability-discovery
- [7] Project Glasswing: An initial update — reactive:anthropic-mythos-vulnerability-discovery
- [8] Project Glasswing: Securing critical software for the AI era - Anthropic — reactive:frontier-ai-cyber-capabilities
- [9] Microsoft Struggling with AI-Discovered Security Bugs — reactive:anthropic-mythos-vulnerability-discovery (2026-07-29)
- [10] From the desk of the CISO: How will Anthropic’s Mythos change vulnerability discovery? | Barracuda Networks Blog — reactive:anthropic-mythos-vulnerability-discovery
- [11] Anthropic Claude Mythos is reshaping the vulnerability landscape — reactive:anthropic-mythos-vulnerability-discovery
- [12] Claude Mythos: AI Vulnerability Discovery and Containment Failures — reactive:frontier-ai-cyber-capabilities