What changed
One month after Project Glasswing launched (April 7, 2026 invitation-only), Anthropic published the first quantitative results and significantly expanded the initiative: 40+ additional organizations gained Mythos Preview access (total ~90+ organizations); partners are now explicitly permitted to publicly disclose Mythos-generated findings to security teams, industry organizations, regulators, government agencies, OSS maintainers, media, and the public (subject to responsible disclosure standards β previously partners operated under confidentiality); Anthropic committed $100M in Mythos Preview usage credits and $4M in direct donations to open-source security organizations.
TL;DR
Claude Mythos Preview has found 10,000+ high/critical-severity vulnerabilities across ~50 partners' critical software in one month at a false positive rate better than human testers (Cloudflare's assessment); 6,202 high/critical vulnerabilities identified in 1,000+ open-source projects; partner access expanding from ~50 to ~90+ organizations.
Developer signal
Three concrete developer signals depending on your context: (1) OSS maintainers: This is the most immediate action item. Mythos has identified ~6,200 high/critical vulnerabilities in 1,000+ open-source projects, and as of May 22, Glasswing partners are explicitly permitted to disclose these findings publicly through normal security channels. You may begin receiving vulnerability reports attributed to Glasswing/Mythos Preview scanning from partner security organizations β check your project's security disclosure inbox and SECURITY.md contact. Standard 90-day responsible disclosure timelines apply per partner disclosure agreements, so if you haven't received anything yet, reports may be in the pipeline. (2) Enterprise developers using Claude Security (Claude Enterprise): The Cloudflare data is the first published third-party calibration of Mythos Preview's false positive rate in a production security context β 2,000 bugs found, FP rate "better than human testers" is an external operator claim, not Anthropic self-reporting. The 90.6% true positive rate across 1,752 findings independently reviewed also supports this signal. If you're evaluating Claude Security for your organization, use these numbers as calibration baselines for comparing against your current toolchain's FP rates. (3) Security tooling builders: The Glasswing false positive rate data (Cloudflare: better than human testers; Anthropic independent review: 90.6% TP rate) is a published benchmark for what AI-assisted vulnerability scanning at scale can achieve. Compare against your tool's current TP/FP metrics before positioning against Mythos-tier approaches.