Anthropic to release Mythos-class models to the public
Anthropic says it wants to eventually release Mythos-class bug-finding models publicly, but only after stronger safeguards exist.
Intelligence analysis by GPT-5.4 Mini
Anthropic plans to broaden access to its Mythos bug-finding AI and, later, make similar models public once it can reduce misuse risk. The post also shows the model has already surfaced thousands of serious bugs, including a critical issue in wolfSSL.
Anthropic has built a very smart computer helper that is good at finding weak spots in software. It is like a metal detector for hidden cracks in a wall, except the wall is code.
The company says this helper has already found lots of real problems, including one serious issue in a tool used by many devices. But it also says such a tool could help bad actors if it is handed out too early.
So Anthropic wants to keep it limited for now and only share a public version later, after it builds better locks and safety rules around it.
Analysis
What Anthropic is saying
Anthropic says its long-term goal is to release models with Mythos-level security research ability to the public, but only after it has built what it describes as much stronger safeguards. Until then, access stays limited through Project Glasswing, with the company also planning to widen that program to more trusted partners, including US and allied governments.
What Mythos has already done
The company says Mythos has scanned more than 1,000 open-source projects that, in Anthropic's view, support a large share of the internet and some of its own infrastructure. From that work it estimated 23,019 total flaws, including 6,202 rated high or critical. Anthropic reports that 1,752 of those high-or-critical findings have gone through its review process, and 90.6 percent of them were confirmed as real. Of the confirmed issues, 62.4 percent were still judged high or critical after reassessment.
One notable case involved wolfSSL, a cryptography library used by billions of devices. Anthropic says Mythos Preview produced an exploit that could let an attacker forge certificates and impersonate a trusted site, such as a bank or email provider. The company says the bug has already been patched and that a fuller technical write-up is coming later.
Why the company is cautious
Anthropic says the security ecosystem is already overloaded, and maintainers are struggling with the volume of AI-generated bug reports. It says some maintainers have even asked it to slow disclosures so they can keep up with patching. The post also acknowledges that no company, including Anthropic, has safeguards strong enough today to guarantee models like this cannot be misused. That makes the planned public release a future security event, not just a product launch.
Key points
- Anthropic says it wants to eventually release Mythos-class models publicly, but only after stronger safeguards exist.
- Project Glasswing currently limits access to selected partners, including governments.
- Mythos has scanned more than 1,000 open-source projects and found 23,019 flaws in total.
- Anthropic says 90.6% of the 1,752 reviewed high-or-critical findings were confirmed as real.
- A critical wolfSSL flaw could have enabled certificate forgery and fake trusted websites.



