Mythos Comes Out of the Vault: Anthropic Moves Its Cyber-Capable Model Toward Public Release
First held back as too dangerous to ship, Anthropic's Mythos-class models are now being widened — first to security partners, then, it says, to everyone.
- 01Mythos was unveiled in April 2026 as a frontier preview model deliberately withheld from public release, shipped only to defensive-security partners via 'Project Glasswing'.
- 02Anthropic now plans a wide release of Mythos-level models 'in the coming weeks', contingent on stronger safety safeguards.
- 03The model's distinguishing trait is offensive-security capability — finding and exploiting software vulnerabilities above the level of most human experts — which is exactly why release has been staged so carefully.

Most model launches are about getting capability into as many hands as fast as possible. Anthropic's Mythos is the opposite story: a frontier model so capable at a specific, double-edged task that the company chose not to ship it — and is only now, carefully, opening the door.
What Mythos is
Mythos was unveiled around 7 April 2026 as a frontier preview model, stronger than Opus 4.7 on maths and security. The headline capability is the uncomfortable one: it can find and exploit software vulnerabilities at a level above most human experts, reportedly discovering thousands of zero-day flaws, and scoring well above Opus 4.6 on hard reasoning benchmarks like USAMO 2026.
That capability is precisely why Anthropic didn't release it the normal way. A model that's superhuman at finding exploitable bugs is a gift to defenders and a weapon for attackers — the same tool, pointed in two directions.
Project Glasswing
Rather than a public launch, Anthropic shipped Mythos through Project Glasswing: a controlled distribution to a small set of defensive-security partners — initially around 50 organisations, reportedly including names like Apple, Nvidia, Microsoft, CrowdStrike and Palo Alto Networks. As of early June, that's expanded to a further ~150 partners across more than 15 countries, and Anthropic has signalled it will extend access in the EU.
The logic is defensive asymmetry: get the vulnerability-hunting capability into the hands of the people patching systems before it leaks to the people attacking them.
Toward a wider release
Alongside the Opus 4.8 launch on 28 May, Anthropic said it had made "swift progress" on "stronger safety safeguards" that would let it release Mythos-level models to all customers "in the coming weeks." That's a meaningful shift — from 'too dangerous to ship' to 'shippable with the right guardrails' in roughly two months.
Why it matters
Mythos is the clearest live example of a lab treating model release as a safety decision rather than a product decision. Whether you read the staged rollout as responsible stewardship or as a controlled way to seed a powerful capability among the best-resourced players, the precedent is the same: frontier capability and frontier risk are now arriving in the same package, and the release calendar is becoming a safety lever.
The thing to watch is the actual public release. If a model that finds zero-days at superhuman level ships broadly, the security community — offensive and defensive alike — gets a step-change in tooling overnight. How Anthropic gates that will be a template others follow.
Ask Relay — he reads every question himself and replies personally by email.
