Anthropic's AI-powered Project Glasswing uncovered 129,000 verified software vulnerabilities in four months, including 33,000 critical or high severity, and is now expanding into a tiered external access program.
Anthropic's Project Glasswing, an internal AI-powered vulnerability discovery program, found at least 129,000 verified software flaws between April and July 2026 — more than 33,000 of them rated critical or high severity. Anthropic is now converting Glasswing into a formal three-tier Cyber Verification Program (CVP) that will give vetted external security teams controlled access to a restricted AI model with reduced safeguards.
Automated vulnerability discovery is not new — static analysis tools like Semgrep and CodeQL have run in CI/CD pipelines for years. What makes Glasswing significant is both scale and the source of the capability: a large language model operating under reduced safety guardrails, specifically the Claude Mythos Preview, a model variant Anthropic otherwise restricts from general release. The combination of reasoning depth and speed allowed Glasswing to surface flaws that traditional pattern-matching tools miss.
What Anthropic disclosed: According to Anthropic's announcement, Project Glasswing ran from April through July 2026. Key figures:
- 129,000+ verified software vulnerabilities identified across the four-month period
- 33,000+ rated critical or high severity by standard CVSS scoring
- Anthropic estimates the true count is approximately five times higher — roughly 645,000 — based on survey data gaps and incomplete coverage in the discovery pipeline
- The model used: Claude Mythos Preview, a restricted variant not available to the public
Glasswing is being restructured into the Cyber Verification Program (CVP), a three-tier access framework:
Get this in your inbox.
Daily AI intelligence. Free. No spam.
- Tier 1 — approved security researchers, standard reduced-safeguard access
- Tier 2 — vetted organizations (CERTs, national security teams), broader model capabilities
- Tier 3 — deep access for Anthropic's internal red teams and select government partners
Applicants must pass identity verification, agree to responsible disclosure terms, and operate under use-case restrictions. Anthropic has not disclosed which external organizations have already been admitted to the program.
The dual-use tension here is real. A model capable of finding 129,000 vulnerabilities in four months is also, by definition, capable of helping attackers exploit them. Anthropic's response is to create a vetted access layer rather than publish the capability broadly — the same model logic that governs export controls on conventional weapons. The three-tier structure mirrors frameworks used by intelligence agencies for classified tooling: access is commensurate with verification, accountability, and use-case specificity.
For enterprise security teams, the CVP represents a potential step change in the economics of defensive security. Red teams that currently spend weeks on manual code review could, under CVP access, run AI-assisted sweeps that surface an equivalent volume of findings in days. The critical/high-severity count alone — 33,000 in four months — exceeds what most mid-size organizations discover across their entire product lifetime.
For software vendors, the implication is that AI-assisted discovery will soon make the current baseline of unpatched vulnerabilities untenable. If Anthropic's five-times-higher estimate is accurate, there are hundreds of thousands of high-severity flaws in production software that existing tooling has never surfaced.
What to watch: The CVP's credibility depends on two things Anthropic hasn't fully detailed: the disclosure pipeline for vulnerabilities found in third-party software, and the liability framework if a CVP-tier researcher's access is abused. Watch for the first public CVP-facilitated CVE disclosures as a signal of how the responsible disclosure loop actually functions — and whether competing labs (Google DeepMind's Project Zero, Microsoft's Security Copilot team) respond with comparable structured access programs.
Did this help you understand AI better?
Your feedback helps us write more useful content.
Get tomorrow's AI briefing
Join readers who start their day with NexChron. Free, daily, no spam.