Anthropic said its Claude Mythos AI model has identified more than 10,000 high- or critical-severity software vulnerabilities [1].
This discovery demonstrates that artificial intelligence can now detect security flaws at a speed that exceeds the ability of human developers to patch them. The result suggests a fundamental shift in how software security is managed, moving from reactive patching to AI-driven proactive discovery.
The findings were reported as part of an update on Project Glasswing, a collaborative effort between Anthropic and its partners [1]. According to the company, these vulnerabilities were uncovered within approximately one month [2]. The model, also known as Mythos Preview, was specifically designed for security analysis to stress-test software and identify systemic weaknesses [1].
By automating the discovery of critical bugs, Anthropic said AI can serve as a primary defense mechanism in cybersecurity. The scale of the findings highlights the persistent gap in traditional software auditing, where thousands of high-severity flaws can remain hidden until an automated tool scans the code [2].
Project Glasswing focuses on the practical application of the Mythos model in real-world environments. The partnership allows Anthropic to refine the model's accuracy while providing partners with a tool capable of scanning vast codebases for vulnerabilities that would typically take human teams years to find [1].
While the volume of bugs found is significant, the company said these numbers emphasize the potential of AI-driven security. The goal is to create a cycle where AI identifies the flaw and potentially suggests the fix, reducing the window of opportunity for malicious actors to exploit the same vulnerabilities [2].
“Claude Mythos has already found more than 10,000 high- or critical-severity software vulnerabilities.”
The ability of a single AI model to uncover 10,000 critical vulnerabilities in 30 days suggests that the current human-led approach to software security is insufficient. This shift places AI at the center of the cybersecurity arms race, where the speed of discovery now outweighs the speed of remediation, potentially forcing a transition toward AI-generated patches to keep pace.





