Esc
SafetyCase Closed

Anthropic's 'Project Glasswing' Leak Reveals Dangerous Cyber Capabilities

Is this a scandal?

No longer — the story has resolved. Noise 6/100, cooling down, across 0 sources.

SCAND-138626as of Methodology
Cite this incident"Anthropic's 'Project Glasswing' Leak Reveals Dangerous Cyber Capabilities." SCAND.Ai incident SCAND-138626, noise 6/100 as of July 28, 2026. https://scand.ai/scandal/anthropic-mythos-1-cybersecurity-leak
FORECASTForecast, not fact

Anthropic will likely face intense pressure from the open-source community to prove these safety risks are not just marketing hype for enterprise exclusivity. Expect a formal statement from the CISA or similar regulatory bodies regarding the classification of such high-capability coding models as critical infrastructure risks.

6

Noise 6/100 — louder than 99% of tracked AI controversies.

AI-assisted analysis · How we work

Why it matters

This controversy underscores the dual-use nature of LLMs where coding proficiency evolves into automated cyber-weaponry. It forces a industry-wide debate on whether high-capability models should be treated as national security assets.

Key points

  1. Claude Mythos 1 reportedly identified 1,094 critical-severity exploits that human security teams had completely missed during internal testing.
  2. The model's performance in 'Project Glasswing' triggered nearly 100 emergency code patches across 50 global technology firms.
  3. Anthropic is allegedly delaying a public release due to the risk of the model being used for automated, internet-scale zero-day reconnaissance.
  4. Access to the model is expected to be restricted to a gated, enterprise-only tier starting in late June or early July 2026.

The story

Leaked documents from an internal Anthropic initiative titled 'Project Glasswing' suggest that the upcoming Claude Mythos 1 model possesses unprecedented autonomous cybersecurity capabilities. According to reports, the model was tested against the codebases of 50 global technology corporations, where it identified over 10,000 high-severity vulnerabilities and 1,094 critical exploits previously undetected by human security teams. The testing reportedly resulted in 97 immediate code patches and 88 high-level security advisories. Anthropic has allegedly moved to restrict the model's release, pivoting toward a 'heavily gated' enterprise-only rollout scheduled for late June 2026. Critics and insiders characterize the model as an automated cyber-reconnaissance system capable of mapping zero-day vulnerabilities across the internet in days. Anthropic has not officially commented on the leak but is reportedly citing national security concerns as the primary justification for withholding the model from the general public.

Who's involved

Critic
ShinkaIoT

Leaked the details and argues that powerful AI tools are being unfairly locked behind corporate doors under the guise of national security.

Defender
Anthropic

Allegedly restricting public access to Mythos 1 to prevent the weaponization of its automated cyber-reconnaissance capabilities.

Neutral
Project Glasswing Participants

Fifty global tech giants who utilized the model to patch critical vulnerabilities in their proprietary codebases.

Join the Discussion

Discuss this story

Community comments coming in a future update

Be the first to share your perspective. Subscribe to comment.

Noise Level

Quiet6?Noise Score (0–100): how loud a controversy is. Composite of reach, engagement, star power, cross-platform spread, polarity, duration, and industry impact — with 7-day decay.
Decay: 11%
Reach
54
Engagement
22
Star Power
45
Duration
100
Cross-Platform
90
Polarity
50
Industry Impact
50

The timeline

  1. Targeted Gated Release

    Projected date for Anthropic to begin providing limited enterprise-only access to the Mythos 1 system.

  2. Glasswing Details Leak

    A whistleblower via ShinkaIoT reveals the model's massive success in uncovering 10,000+ vulnerabilities.

  3. Project Glasswing Begins

    Anthropic initiates a restricted testing phase of Claude Mythos 1 with 50 enterprise partners.

The forecast

Anthropic will likely face intense pressure from the open-source community to prove these safety risks are not just marketing hype for enterprise exclusivity. Expect a formal statement from the CISA or similar regulatory bodies regarding the classification of such high-capability coding models as critical infrastructure risks.

Forecast, not fact — an editorial estimate we score when this resolves.

You're up to date

That's the complete picture as of — nothing more to know right now. We'll update this page the moment it changes.