Claude Mythos Preview is Anthropic's most capable AI model to date — and the first frontier model in the current AI cycle to be announced without a public release. Since its April 7, 2026 debut, it has dominated tech and security coverage for one reason: the model is too dangerous, by Anthropic's own assessment, to ship to the general public.
This piece compiles what is actually confirmed, what remains contested, and what security professionals and organizations need to know right now.
What Is Claude Mythos Preview?
Claude Mythos Preview is a general-purpose large language model that Anthropic describes, in its official Project Glasswing announcement, as performing "strikingly" well on computer security tasks. It sits above the Opus tier in Anthropic's model lineup — a full capability tier above Claude Opus 4.7, which itself shipped the week after Mythos was announced. Per the Claude API models overview, it is offered "separately as a research preview model for defensive cybersecurity workflows as part of Project Glasswing" with "no self-serve sign-up."
The model was not designed as a cyberoffense tool. Anthropic states explicitly in the Claude Mythos Preview system card that it did not train Mythos Preview to specialize in software exploitation. The cybersecurity capability is a downstream consequence of exceptional code reasoning: Mythos is very good at understanding large, complex codebases, finding the intent behind code, and inferring where logic breaks down. Applied to security, that translates directly into vulnerability discovery.
Four specific capabilities are highlighted in the system card:
- Understanding code intent to surface hidden flaws from a plain-language instruction
- Chaining minor vulnerabilities into a single high-severity attack path
- Reconstructing source code from deployed binaries to find exploitable weaknesses
- Mapping networks, moving laterally, and building custom exfiltration tools autonomously — within hours — once initial access is gained
Why Wasn't It Released?
Anthropic's explanation is unusually candid for a frontier lab. The company concluded that Mythos Preview's offensive cybersecurity capabilities are significant enough that broad public access would pose unacceptable risk to global digital infrastructure before adequate safeguards exist.
Rather than release and patch reactively, Anthropic chose a controlled-access model: deploy to vetted partners for defensive use only, build safeguards on a lower-risk model (Opus 4.7) in parallel, and graduate to broader access once those safeguards have been stress-tested in production. As Anthropic states on the Project Glasswing page: "We do not plan to make Claude Mythos Preview generally available, but our eventual goal is to enable our users to safely deploy Mythos-class models at scale."
The UK AI Security Institute (AISI) independently evaluated Mythos and corroborated the capability claims in their published evaluation. In their assessment, Mythos represents a step change over previous frontier models — the first model to solve the 32-step "The Last Ones" takeover simulation, and achieving a 73% success rate on expert-level capture-the-flag tasks. Two years ago, no available model could complete beginner-level cyber tasks.
As Fortune reported on April 7, shares in CrowdStrike, Palo Alto Networks, Zscaler, SentinelOne, and Okta all fell between 5% and 11% following the announcement, as investors worried AI could undermine demand for traditional security products.
Project Glasswing: The Controlled Rollout
Project Glasswing is the delivery vehicle for Mythos Preview access. Announced alongside the model on April 7, 2026, the program works as follows:
What it includes:
- Invitation-only access to Claude Mythos Preview for defensive cybersecurity work
- $100 million in model usage credits distributed to partner organizations
- $4 million in direct donations to open-source security groups
- A commitment to share vulnerability findings back with the broader security community
Who has access: Twelve named founding organizations — Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, and Cloudflare — plus roughly 40 additional organizations that build or maintain critical software infrastructure. Total program size: approximately 50 organizations. Per the API documentation, there is no public waitlist and no self-serve sign-up.
What partners can do with it: Defensive security work on their own systems and on foundational open-source code: vulnerability discovery, black-box testing, code review, penetration testing. Offensive use against systems the partner does not own is prohibited.
The results so far (as of May 26, 2026): Anthropic published first-month results on May 22 in their Project Glasswing initial update. Mythos Preview scanned over 1,000 open-source projects and produced 23,019 candidate findings. When 1,752 of those findings were reviewed by external security firms, 90.6% were confirmed as valid true positives. Estimated high- or critical-severity findings: 6,202. Mozilla patched 271 vulnerabilities in a single Firefox release (version 150). Cloudflare identified 2,000 vulnerabilities across its critical infrastructure. A notable individual finding: CVE-2026-5194, a flaw in the wolfSSL cryptography library that would have allowed forging TLS certificates across billions of IoT and industrial devices, detailed in the same update. As Help Net Security reported on May 26, the remediation gap is the most significant structural problem to emerge: fewer than 1% of discovered vulnerabilities have been patched.
How Powerful Is Claude Mythos? The Benchmarks
The benchmark numbers are not close. From the Claude Mythos Preview system card:
| Benchmark | Claude Mythos Preview | Claude Opus 4.6 |
|---|---|---|
| SWE-bench Verified | 93.9% | 80.8% |
| SWE-bench Pro | 77.8% | 53.4% |
| USAMO 2026 | 97.6% | 42.3% |
| Terminal-Bench 2.0 | 82.0% | — |
| OSWorld | 79.6% | — |
The USAMO 2026 gap — 97.6% versus 42.3% — is the single largest relative swing, indicating Mythos performs at a qualitatively different level on complex mathematical reasoning.
On cybersecurity specifically, the Anthropic red team technical blog post and the separate exploit evaluation post report:
- Thousands of zero-day vulnerabilities discovered autonomously across every major operating system and browser
- A 27-year-old remote code execution bug in OpenBSD (TCP SACK)
- CVE-2026-4747: a 17-year-old FreeBSD NFS remote code execution vulnerability
- On the Firefox 147 JavaScript engine exploit harness: Mythos produced 181 working exploits; Opus 4.6 produced 2
- Mythos Preview is approximately 100 times more successful than Opus 4.6 at producing working exploits for discovered vulnerabilities
One important caveat from the system card: Mythos could not produce working exploits for all hardened targets. The test environments differ from real-world deployments — they lack active defenders, defensive tooling, and penalties for triggering security alerts. Whether Mythos could attack a well-defended enterprise network at scale remains unconfirmed.
What Independent and Mainstream Coverage Says
The story moved from trade press to mainstream outlets faster than most AI announcements. BBC Science Focus asked whether society could be "on the brink of total internet collapse," while also reporting skeptical voices: AI critic Gary Marcus described the model as "incrementally better than previous recent models, but certainly not an off-the-chart breakthrough." The Ringer offered a detailed breakdown of what Mythos can and cannot do, and why "bugmaggedon" framing may be overstated. Industry analysts at Forrester went further in the other direction, writing in their Project Glasswing analysis that "Anthropic is now the most important partner for every cybersecurity company." Bain & Company advised enterprise clients that organizations will likely need to double cybersecurity spending, with planned 10% annual increases falling well short of what the threat now demands. The London School of Economics Media Blog placed Mythos in the longer history of dual-use technology, comparing the concentration of access to early nuclear capability.
The Alignment Finding
A counterintuitive result from the safety evaluations in the system card: by Anthropic's internal metrics, Mythos Preview is the most well-aligned model the company has trained. The risk is not that the model acts autonomously against its operators — it's that the underlying capability, once replicated by less careful labs or accessed by malicious actors, could be misused.
Anthropic's Transparency Hub lists Mythos Preview alongside its safety evaluation summaries for all current models.
Anthropic estimates similar capabilities will emerge from other frontier labs within six to eighteen months.
How to Access Claude Mythos Preview
The short answer: you almost certainly cannot right now.
Current access paths:
- Project Glasswing founding partners (named above) — invitation only, no application process
- Roughly 40 additional vetted critical-infrastructure organizations — not publicly named
- Private preview for select Google Cloud customers — separate distribution channel
Pricing for partners: $25 per million input tokens, $125 per million output tokens — five times the cost of Opus 4.7.
The closest alternative for security professionals: Anthropic has launched a Cyber Verification Program alongside Opus 4.7, allowing vetted security researchers, penetration testers, and red teamers to use Opus 4.7 for legitimate cybersecurity workflows with reduced restrictions. Details are available via the Project Glasswing page.
What Organizations Should Do Right Now
The practical implication for most organizations is not "acquire Mythos access" — it's "harden systems before Mythos-class capabilities become commodity."
Anthropic's own timeline projection: similar offensive capabilities will be available from other sources within six to eighteen months. The 90-day responsible disclosure window for Glasswing-discovered vulnerabilities closes in early July 2026, at which point thousands of previously unknown flaws and their technical details are expected to be published. Security Magazine and the Bloomsbury Intelligence and Security Institute have both noted that Anthropic's focus on large enterprise partners leaves smaller organizations exposed during the critical patching window.
Security fundamentals that address the highest-probability attack surface:
- Prioritize and accelerate patch cycles — particularly for open-source dependencies
- Review and tighten access controls and identity management
- Audit security configurations systematically, not on a breach-response cadence
- Expand logging coverage so AI-assisted lateral movement is detectable
- Treat AI-powered vulnerability discovery as a baseline assumption in threat modeling going forward
Frequently Asked Questions
Is Claude Mythos the same as "Claude Opus 5" or "Capybara"? The internal codename during development was "Capybara." Some UI sightings and leaked documents have referenced "Mythos 5" or "Mythos 5 (experimental)." Officially, the model is Claude Mythos Preview. Anthropic has not placed it formally within the Haiku/Sonnet/Opus naming hierarchy — it sits above the Opus tier rather than within it. The Wikipedia article on Claude notes simply that it "was released to some companies in 2026 but not to the public."
Will it come to Claude.ai or Claude Pro? Not currently, and there is no announced date. Anthropic's stated roadmap involves shipping a future "Mythos-class" successor model with mature safeguards — not releasing Mythos Preview itself broadly.
How does Mythos differ from Opus 4.7? Opus 4.7 is the current publicly available flagship and serves as the live test vehicle for safeguards that a future broadly available Mythos-class model would need. The capability gap between Mythos and Opus 4.7 is larger than the gap between Opus 4.6 and 4.7. Opus 4.7 ships with differential capability reduction on cyber tasks and automated detection of prohibited cybersecurity uses.
Did Anthropic train it specifically for cybersecurity? No. As Infosecurity Magazine reported, Anthropic states the cybersecurity capability is a byproduct of general improvements in code reasoning and software engineering performance.
Has it been used maliciously? One confirmed incident: Anthropic detected a coordinated intrusion campaign by a Chinese state-sponsored threat group using Claude Code (not Mythos Preview itself) to infiltrate approximately 30 organizations across tech, finance, and government. Anthropic shut down the campaign. No confirmed malicious use of Mythos Preview specifically has been reported.
When do the discovered vulnerabilities become public? Anthropic's 90-day responsible disclosure window closes in early July 2026. At that point, discovered vulnerabilities and technical details are expected to be published — creating a hard deadline for patch prioritization.
The Bottom Line
Claude Mythos Preview is the first frontier model announced with a system card but no product page. The benchmarks are independently corroborated, the cybersecurity capability is real and has been verified by the UK AI Security Institute, and the decision not to release publicly is, by Anthropic's own account, deliberate rather than temporary.
The more important story for most readers is structural: AI-driven vulnerability discovery now outpaces human remediation capacity. Over 23,000 candidate vulnerabilities were found in a single month. Fewer than 1% have been patched. Whether or not you ever interact with Mythos directly, the software you depend on is being scanned by models like it — and the window to patch proactively is closing.
