Anthropic is scaling up access to Claude Mythos 5, its most capable model for offensive-grade cybersecurity reasoning, by embedding it into defensive tools rather than releasing it directly.
The August 21, 2026 announcement pairs the model’s arrival in Claude Security with a new $35 million open-source security fund and an expanded verification program for vetted defenders.
Mythos 5’s cybersecurity capabilities trace back to Project Glasswing, launched in April 2026 with roughly 50 partner organizations authorized to hunt vulnerabilities using Claude Mythos Preview.
Anthropic Brings Claude Mythos 5 to Claude Security
The program has since scaled to around 200 organizations, admitted under a criterion that a successful attack on the partner’s codebase could affect more than 100 million people.
Anthropic says that the pilot period let defenders find and patch flaws before comparable capabilities became broadly available or reached malicious actors.
The core design decision now shaping distribution is architectural rather than policy-based: instead of expanding who can prompt Mythos 5 directly, Anthropic is expanding who can receive its outputs.
Claude Security, in public beta for Claude Enterprise customers, connects to a GitHub repository, scans it with Mythos 5, and returns each finding tagged with a CWE category, confidence rating, severity score, and a suggested patch.
Users never converse with Mythos 5 itself; they route implementation through Claude Code using whatever model tier their organization already has access to. Anthropic explicitly states that the scan output does not grant Mythos-level access to other surfaces, and that every patch requires human review before deployment.
The rationale is straightforward from a dual-use risk standpoint: a model that can reason about exploit chains is equally capable of generating them if a user can freely steer its prompts.
By constraining Mythos 5 to a fixed task scan, validate, patch-suggest- Anthropic reduces the steerability surface that has historically enabled jailbreaking or repurposing toward offensive tooling.
Independent coverage notes the timing pressure behind this move: reporting by TheNextWeb cited Glasswing’s models surfacing roughly 10,000 critical vulnerabilities in a single month, far outpacing what maintainers could patch, a bottleneck the new fund is meant to address.
The newly launched Defender Advantage Fund (0xDAF) commits $35 million in Claude credits to three priorities: patching live vulnerabilities in widely used open-source projects, building replicable scan-and-patch automation, and pursuing structural fixes that close entire vulnerability classes rather than one CVE at a time.
Anthropic says it will start with a small number of larger pilot grants and disclose recipients in coming weeks a scaled continuation of the $4 million in direct Glasswing-era donations to open-source security foundations.
Separately, the Cyber Verification Program, which already grants vetted organizations reduced safeguards on Opus and Sonnet models for authorized security work, will expand in the coming weeks to cover broader dual-use capabilities on those models, with Mythos-class access to follow.
Approval is organization-scoped rather than individual, meaning independent consultants and personal workspaces currently fall outside the program’s reach.
For enterprise defenders, the immediate practical change is that Claude Security scans now run on Mythos 5 at no additional cost beyond standard token usage under existing Enterprise plans. Admins enable it through the admin console, and findings feed directly into Claude Code for remediation.
For the broader defender community without Enterprise or Glasswing status, the near-term path to Mythos-level capability remains indirect: through partner-integrated tools Anthropic is now recruiting for, or through eventual Cyber Verification Program expansion. Anthropic frames this as a deliberate sequencing: access follows the demonstrated ability to contain misuse, not the reverse.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.