Anthropic’s Project Glasswing Update
Bruce Schneier says Anthropic’s Project Glasswing is finding vulnerabilities, but almost none have been patched. He also questions the data because Anthropic is not releasing details.
Intelligence analysis by GPT-5.4 Mini
The post argues that Anthropic’s status report for Project Glasswing looks impressive on the surface because it found many vulnerabilities, including some dangerous ones. But Schneier says the lack of patching and missing details make the results hard to trust.
Anthropic says its AI can spot holes in software, like a flashlight finding cracks in a wall. Bruce Schneier says that is useful only if someone also fixes the cracks, and right now that part seems to be missing.
Analysis
What the post says
Schneier says Anthropic started Project Glasswing in April as a way for companies to use its new model to find and fix vulnerabilities in their own software. He describes it as a strong public-relations move, but says press coverage has repeated Anthropic’s claims too uncritically and that the idea that Mythos is better than other models at finding vulnerabilities is not true.
The core concern
Anthropic’s status report says the project is finding many software vulnerabilities, and Schneier acknowledges that some are dangerous. The problem, in his view, is that almost none of those issues has been patched. That makes the headline numbers look less useful than they first appear, because finding bugs is only part of security work; fixing them is the part that changes risk.
Why he is skeptical
Schneier says the data looks strange to him and that there is something he does not understand about it. He specifically objects to Anthropic not releasing details and instead asking readers to “trust us.” In his framing, that lack of transparency is a serious problem, especially for a security claim that depends on evidence.
Bottom line
The post is not saying the project finds nothing. It says the reported findings may be real, but the presentation is incomplete and the results are hard to evaluate without more disclosure about what was found, how severe it was, and why so little has been patched.
Key points
- Schneier says Project Glasswing is finding many vulnerabilities, including some dangerous ones.
- He says almost none of the discovered issues has been patched.
- He questions Anthropic’s lack of detail and says “trust us” is not enough.
- He argues that the widely repeated claim that Mythos is better than other models is not true.
- The post frames vulnerability discovery as incomplete unless it leads to real remediation.
If the report is accurate, Project Glasswing could help teams uncover real weaknesses faster than manual review alone. More visibility into vulnerabilities could still push developers to improve their security processes, even if patching is currently lagging.
If the findings are hard to verify and almost nothing gets patched, the project may become a publicity story instead of a security tool. Without more transparency, it is hard to know whether the results are meaningful, exaggerated, or too overwhelming for teams to act on.



