Anthropic's Secret AI Model Finds Thousands of Critical Security Flaws

Powerful AI tool uncovers vulnerabilities across major OSes and browsers, sparking debate in Washington

Apr. 13, 2026 at 12:00am

A highly detailed, glowing 3D illustration of a complex network of interconnected cybersecurity infrastructure, with pulsing neon lights representing the discovery of critical vulnerabilities, conceptually illustrating the scale and impact of Anthropic's AI-powered security research.Anthropic's powerful AI model uncovers a vast web of critical security vulnerabilities across major tech platforms, sparking national security concerns.Washington Today

Anthropic's secret AI model, known as Project Glasswing and built around the Claude Mythos Preview, has already uncovered thousands of critical security vulnerabilities across every major operating system and web browser. This has alarmed US intelligence agencies and defense officials, who are concerned about the implications of such a powerful tool falling into the wrong hands.

Why it matters

The discovery of these widespread vulnerabilities by Anthropic's AI model has raised serious national security concerns, as it could potentially be devastating if accessed by adversaries. This has sparked a debate within the intelligence community about how to responsibly disclose and address these flaws without compromising critical infrastructure.

The details

Anthropic unveiled Project Glasswing on Tuesday, a defensive cybersecurity initiative built around the Claude Mythos Preview AI model. The model remains withheld from public release, with access limited to partners like Amazon Web Services, Apple, Cisco, Google, and Microsoft. The scale of what Mythos Preview has already found is what is alarming officials, as security researchers had long anticipated a model capable of identifying vulnerabilities at speed. Multiple US intelligence agencies and Defense Department components are already discussing the implications, with concerns that a tool powerful enough to expose weaknesses in critical infrastructure could be devastating in the wrong hands.

  • Anthropic unveiled Project Glasswing and the Claude Mythos Preview AI model on Tuesday, April 13, 2026.

The players

Anthropic

An artificial intelligence company that has developed a powerful AI model, known as Claude Mythos Preview, capable of identifying thousands of critical security vulnerabilities across major operating systems and web browsers.

US Intelligence Agencies

Multiple US intelligence agencies and Defense Department components are discussing the implications of Anthropic's AI model and the potential national security risks if the tool were to fall into the wrong hands.

Cybersecurity and Infrastructure Security Agency (CISA)

Anthropic has briefed senior officials at CISA about the findings of its Claude Mythos Preview AI model.

NIST's Center for AI Standards and Innovation

Anthropic has also briefed senior officials at NIST's Center for AI Standards and Innovation about the capabilities of its AI model.

Senator Mark Warner

The vice chairman of the Senate Intelligence Committee, who has called on industry to accelerate patching in response to the AI-powered vulnerability discovery.

Got photos? Submit your photos here. ›

What they’re saying

“Given ongoing attacks on the open-source ecosystem, Mythos reaching a hostile government was 'barely a hypothetical.'”

— Hayden Smith, co-founder of software supply chain risk firm Hunted Labs

“There's going to be a real equity conversation that occurs.”

— Morgan Adamski, former executive director at US Cyber Command

“As AI speeds up vulnerability discovery, patching must keep pace.”

— Senator Mark Warner, vice chairman of the Senate Intelligence Committee

What’s next

The White House has ordered federal agencies to phase out Anthropic tools due to the company's refusal to ease restrictions on domestic surveillance tools and autonomous weapons for Pentagon use. Anthropic is contesting this decision in court.

The takeaway

Anthropic's powerful AI model has uncovered thousands of critical security vulnerabilities across major operating systems and web browsers, raising serious national security concerns and sparking a debate within the intelligence community about how to responsibly address these flaws without compromising critical infrastructure.