Ten Thousand Bugs, One Model: Inside Anthropic's Project Glasswing
Claude Mythos Preview has scanned more than a thousand open-source projects and surfaced thousands of critical flaws. The bottleneck has moved — and the patch queue is not moving fast enough.

The first version of the number that circulated was 10,000. Ten thousand critical or high-severity vulnerabilities, found by a single AI model and a coalition of fifty-odd partners, across software that quietly holds up much of the internet. That figure landed in a Project Glasswing update published by Anthropic late last week, and it immediately demanded a closer read.
The actual shape of the data is more specific — and, depending on how you hold it, more sobering. Anthropic's Claude Mythos Preview scanned more than 1,000 open-source projects and flagged 6,202 high or critical severity vulnerabilities. Six independent security research firms then assessed 1,752 of those findings. Of that reviewed subset, 90.6 percent — 1,587 bugs — were confirmed true positives, and 62.4 percent (1,094) cleared the bar for high or critical severity. Anthropic says that at current triage rates, Mythos Preview is on track to have surfaced nearly 3,900 validated high or critical findings in open-source code, before counting whatever it has found for Project Glasswing's private partners.
Anthropoc launched Project Glasswing in April alongside a commitment of more than $100 million in usage credits and a separate $4 million in donations to open-source security organizations. The premise, stated plainly in the initiative's original announcement, was that Claude Mythos Preview had crossed a threshold: AI models could now "surpass all but the most skilled humans at finding and exploiting software vulnerabilities." The update does not walk that back.
But 530 bugs disclosed. Seventy-five patched. Sixty-five public advisories. Those numbers sit in a different column.
Mark Tauschek, distinguished analyst at Info-Tech Research Group, said the update validates something security leaders have been slow to reckon with. "The cost of discovering software vulnerabilities has dropped dramatically," he said. "If a single AI model can surface thousands of serious vulnerabilities across foundational software in a matter of weeks, the window between vulnerability discovery and exploitation will keep compressing."
The human side of the story is quieter and harder to fix. Several open-source project maintainers — often volunteers with day jobs, managing code that enterprises run at massive scale — have asked Anthropic to slow its disclosure rate. They need time to design patches. Tauschek said that ask "points to a capacity problem that has been building for years," not resistance to better security.
Kellman Meghu, CTO of DeepCove Cybersecurity, said none of this surprised him. His firm recognized two years ago that competent researchers using AI could dramatically accelerate both discovery and exploitation. "The barrier of entry to drive the prompts in a large language model has dropped significantly," he said. "This will only get better, and is our new reality." DeepCove has responded by building AI-assisted auditing into its own development pipeline and tightening patch SLAs on critical dependencies — but Meghu was direct about what that entails. "We do not blindly trust LLMs or agents to operate autonomously."
David Shipley, CEO of Beauceron Security, applied a more skeptical ruler to the headline figure. Start at 10,000, subtract the unreviewed pool, and you reach roughly 1,500 human-verified, legitimate bugs. "That's quite a fall-off," he said. And he raised a question Anthropic has not yet answered publicly: what does each found vulnerability actually cost in compute? "I've heard it's in the range of $500 a minute," he said. "Surely, if they can tell us how many they found, they can tell us how much compute it cost."
Anthropoc has now released Claude Security in beta for enterprise customers and launched a Cyber Verification Program allowing credentialed security professionals to use its models outside certain default safeguards. Both moves reflect a calculation that the capability is already in the world.
Shipley's proposed fix was the bluntest of the three: make software makers legally liable for their code. "That is the only way out of this mess," he said, "because that is the fundamental misalignment that got us here."
The bugs keep coming. The patches do not.


