AI Model Report

Model Releases · AUGUST 22, 2026

Anthropic drops Mythos 5 into Claude Security, adds $35M open-source defender fund

The model previously locked to Project Glasswing partners now runs GitHub vulnerability scans for any Claude Enterprise customer, billed as standard token usage — with a partner channel and Cyber Verification Program expansion to follow.

By Lars Iverson · Open source & model weights · August 22, 2026

Anthropic on August 21, 2026 moved Claude Mythos 5 out of its vetted-partner enclosure and into Claude Security, the company's enterprise vulnerability scanner, making its most capable cyber-reasoning model available to any Claude Enterprise administrator with a repository to point it at. The scan runs from claude.ai/security, returns a CWE category, confidence and severity ratings, and a suggested fix, and bills as standard token usage. Claude Security itself stays in public beta.

This is the third stage of a rollout that started with Project Glasswing, launched April 7, 2026 alongside AWS, Microsoft, Google, CrowdStrike, and the Linux Foundation, and backed by up to $100 million in usage credits and $4 million in direct donations to open-source security organizations. Since April 2026, Mythos-class access was gated to that coalition. Glasswing partners have been paying $10 per million input tokens and $50 per million output tokens for Mythos 5, less than half of Mythos Preview.

The results Anthropic is citing are load-bearing for the expansion. Mythos Preview surfaced thousands of high-severity vulnerabilities during the Glasswing window, including a 27-year-old remotely triggerable flaw in OpenBSD, a 16-year-old bug in an FFmpeg line that automated testing had hit five million times without catching, and a Linux kernel privilege escalation. That's the marketing case. The safety case is a bug bounty that logged more than 1,000 hours of testing without finding a universal jailbreak, plus a 30-day retention requirement on Mythos-class traffic that Anthropic frames as safety rather than training data.

"Our aim remains to help organizations adapt to the pace and demands of cybersecurity as AI models become increasingly powerful."

The architecture of access is the actual story. Mythos 5 in Claude Security doesn't extend Mythos to other Claude product surfaces; interactive patching in Claude Code still runs on whatever models the org already licenses. A partner channel is coming next, embedding Mythos 5 in third-party defensive tools where end users see only downstream artifacts like suggested patches, per The Decoder's reporting, several vendors are migrating over from Claude Opus. A Cyber Verification Program expansion will follow, opening broader dual-use capabilities on Opus and Sonnet first, with Mythos-class access after.

Anthropic's stated reasoning is that misuse risk concentrates where a user can steer a model directly and drops considerably when the user only receives specific outputs. The $35 million Defender Advantage Fund (0xDAF), announced in Claude credits rather than cash, applies the same theory at ecosystem scale: hand compute to open-source defenders, keep the model itself behind a narrow output surface. It's a governance posture dressed as a product release, and it lets Anthropic sell the thing it can't quite let go of.

Sources