Anthropic Puts Claude Mythos 5 to Work: Cyber Supermodel Now Scans Enterprise Code, Backed by a $35M Open-Source Defense Fund
Anthropic has deployed Claude Mythos 5 — its most cyber-capable model, restricted to vetted defenders since April — inside Claude Security for all Enterprise customers, launched a $35M Defender Advantage Fund for open-source protection, and previewed a wider Cyber Verification Program.
Anthropic just crossed a line it has been circling for four months. On August 21, 2026, the company announced that Claude Mythos 5 — the cyber-capable model it has kept locked to vetted defenders since its April debut — is now running vulnerability scans inside Claude Security for all Claude Enterprise customers, in public beta. Alongside the deployment, Anthropic launched the Defender Advantage Fund (0xDAF), a $35 million pool of Claude credits dedicated to securing open-source software, and previewed an expansion of its Cyber Verification Program that will eventually extend Mythos-class access to enrolled defenders.
For a company that has built its brand on caution, this is a deliberate acceleration — and the reasoning behind it says a lot about how frontier AI labs are learning to commercialize their most dangerous capabilities.
The Announcement: Four Changes
The rollout, detailed in Anthropic’s August 21 statement, bundles four concrete moves:
- Claude Security scans now run on Claude Mythos 5, live in public beta for all Claude Enterprise customers as of August 21.
- Partner integrations are coming. Anthropic is working with cybersecurity technology and services partners to embed Mythos 5 into tools defenders already use daily.
- The Defender Advantage Fund (0xDAF) will distribute $35 million in Claude credits to organizations patching live vulnerabilities in widely used open-source projects.
- The Cyber Verification Program is expanding — over the coming weeks, it will cover broader dual-use capabilities on Opus and Sonnet models, with Mythos-class access to follow.
This is the third stage of a rollout Anthropic has intentionally kept slow. The company’s stated logic: the danger of a cyber-capable model concentrates where a user has direct access and can steer it toward offensive work. When users only receive “specific outputs, such as a patch for a vulnerability or a security alert,” that risk drops considerably. The expansion widens access to defensive results while keeping guardrails around the model itself.
How Claude Security Delivers Mythos 5 Without Opening the Model
The scoping mechanism is the engineering story here. Claude Security, in public beta for Enterprise customers, bills Mythos 5 scans as standard token usage under existing plans — no separate add-on. Admins enable the feature in the admin console; from claude.ai/security, a user picks a repository, and the model scans the codebase for vulnerabilities.
Each finding returns a CWE (Common Weakness Enumeration) category, confidence and severity ratings, and a suggested fix. The user then opens Claude Code on the web to implement the patch — and every patch must be reviewed and approved by a human before it lands.
Crucially, running a Mythos 5 scan does not extend Mythos access to any other surface. The scan returns detailed findings rather than raw model outputs, and interactive patching uses whichever models the organization already has in Claude Code.
Partner integrations follow the same pattern. An end user of a partner product never prompts Mythos 5 directly; a purpose-built interface runs the model in the background for a defined task and returns only the intended artifact, such as a list of suggested patches. Anthropic says it and its partners run abuse-prevention measures to keep the model inside that scope.
From Project Glasswing to a Wider Defender Rollout
Anthropic’s caution with this model class traces to Project Glasswing, launched April 7, 2026 with a coalition including AWS, Microsoft, Google, CrowdStrike, and the Linux Foundation. The project put Claude Mythos Preview into the hands of a small group securing critical software, backed by up to $100 million in usage credits and $4 million in direct donations.
The results were striking. Mythos Preview found thousands of high-severity vulnerabilities, including flaws in every major operating system and web browser: a 27-year-old remotely triggerable bug in OpenBSD, a 16-year-old flaw in an FFmpeg line that automated testing had executed five million times without catching, and a chained Linux kernel privilege escalation. All three were reported to maintainers and patched before disclosure.
On June 9, 2026, Anthropic split the model in two. Claude Fable 5 — the same underlying model with safety classifiers routing cyber, biology, and distillation queries to Claude Opus 4.8 — went to general availability. Claude Mythos 5, with cyber safeguards lifted for vetted users, went to Glasswing partners at $10 per million input tokens and $50 per million output tokens, less than half the price of Mythos Preview. An external bug bounty produced no universal jailbreaks in over 1,000 hours of testing.
Since then, more than 40 additional organizations maintaining critical software infrastructure have received access beyond Glasswing’s 12 launch partners, with security firms like Horizon3.ai joining the vulnerability hunt in July.
The Defender Advantage Fund by the Numbers
The 0xDAF’s $35 million in Claude credits is earmarked for three kinds of work: patching live vulnerabilities in widely used open-source projects, automating scanning-and-patching pipelines that other projects can replicate, and approaches that make projects resistant to whole classes of attack rather than individual bugs.
The fund extends work Glasswing already started, including support for coordinated vulnerability-fixing efforts like Akrites and the White House’s Gold Eagle initiative. It starts with a small number of larger pilot grants while Anthropic learns what scales — initial recipients will be named in the coming weeks.
Why This Matters: Productizing the Most Dangerous Model
The commercial context is hard to miss. Anthropic is preparing for a blockbuster IPO, and the partner ecosystem it has assembled since May — Wiz, Palo Alto Networks, CrowdStrike, Accenture — describes the market opportunity in concrete terms. Wiz said its Opus-powered offensive-testing agent runs continuously across more than 150,000 production assets a week. Accenture said it took security-testing coverage from roughly 10% to over 80% across 1,600 applications while cutting scan turnaround from 3–5 days to under an hour.
CrowdStrike consulting chief Mark Manglicmot framed the shift: “Frontier models like Anthropic’s Claude Opus are giving defenders a capability advantage that didn’t exist a year ago, pushing vulnerability management all the way to the left.”
Mythos 5’s own numbers back the case — with caveats. Anthropic reports 83.1% on CyberGym vulnerability reproduction versus 66.6% for Opus 4.6, though these are company-measured figures rather than independent evaluations.
The deeper significance is architectural. Anthropic has found a template for productizing high-risk capabilities: wrap the model in a narrow interface, return sanitized outputs instead of raw model access, require human approval for actions, and bill it as ordinary usage. If that pattern holds, expect other labs with dangerous frontier models to copy it — and expect the debate over “capability containment vs. product surface area” to sharpen as Mythos-class access spreads through the Cyber Verification Program in the coming weeks.
For enterprises, the near-term takeaway is simpler: if you’re a Claude Enterprise customer, one of the most capable vulnerability-finding systems ever built just became a line item in your existing plan.
Sources
- [1] https://www.unite.ai/anthropic-deploys-claude-mythos-5-in-security-tools-35m-open-source-fund/
- [2] https://www.marktechpost.com/2026/08/21/anthropic-brings-claude-mythos-5-to-claude-security/
- [3] https://www.anthropic.com/news/claude-fable-5-mythos-5
- [4] https://releasebot.io/updates/anthropic/claude