Anthropic announced Claude Mythos (specifically Claude Mythos Preview) on April 7, 2026, marking a significant advancement in AI capabilities, particularly in cybersecurity. This frontier large language model has demonstrated an unprecedented ability to autonomously discover and exploit high-severity vulnerabilities.

Key Capabilities & Performance:

  • Zero-Day Discovery: Mythos can identify previously unknown (zero-day) vulnerabilities in real-world software across major operating systems and web browsers, having reportedly found thousands of high-severity flaws.
  • Autonomous Exploitation: Beyond identification, the model can generate complete, working exploits and execute complex, multi-stage cyber operations with minimal human intervention.
  • Cyber Range Success: In evaluations by the UK AI Security Institute (AISI), Mythos became the first model to successfully complete “The Last Ones,” a 32-step corporate network attack simulation, in 3 out of 10 attempts.
  • Legacy Bug Detection: Notably, it identified a 27-year-old TCP vulnerability in OpenBSD and a 17-year-old remote code execution flaw in FreeBSD (CVE-2026-4747).

Technical Specifications:

  • Context Window: 1 million tokens
  • Max Output: 128,000 tokens
  • Knowledge Cutoff: December 2025
  • Reasoning: Exhibits significant improvements in mathematics, long-context reasoning, and software engineering compared to its predecessor, Claude 4.6 Opus

Project Glasswing & Restricted Access:
Due to the critical nature of its hacking capabilities, Anthropic has not made Claude Mythos generally available. Instead, they launched Project Glasswing, restricting access to a consortium of approximately 50 organizations, including major tech companies (Google, Microsoft, Apple, Amazon) and critical infrastructure maintainers. The project’s aim is primarily defensive, using Mythos to find and patch vulnerabilities proactively. Anthropic has committed 4 million in donations to open-source security organizations for this initiative.

Regulatory and Political Context:
The emergence of Mythos has generated considerable debate. The U.S. Department of Defense designated Anthropic a “supply chain risk” in March 2026 after the company refused to lift prohibitions on using Claude for mass surveillance, although a temporary injunction was issued against this designation. Concerns have also been raised by the World Economic Forum and international regulators regarding the potential for Mythos-class models to shift the balance of power towards malicious actors.