Anthropic has dramatically expanded Project Glasswing, its flagship cybersecurity initiative, from approximately 50 partner organizations to nearly 200, with new participants including the North Atlantic Treaty Organization (NATO), Samsung, SK Hynix, and the European Union Agency for Cybersecurity (ENISA). The expansion, announced June 2, adds roughly 150 organizations spanning critical infrastructure sectors such as power utilities, water systems, healthcare, and telecommunications across at least 15 countries. The timing of the announcement—one day after Anthropic confidentially filed its S-1 draft with the SEC for an initial public offering—reveals much about how the company intends to position itself as both a public-benefit security player and a formidable commercial enterprise.
Project Glasswing’s First Month: 10,000 Vulnerabilities and a Patch Bottleneck
Project Glasswing began in April as a limited-access cybersecurity program. Anthropic provided its unreleased Claude Mythos Preview model to roughly 50 partner organizations, tasking it with scanning their codebases for vulnerabilities. The results, published May 22, were striking. Across all partners, the model identified more than 10,000 high-severity and critical vulnerabilities.
Cloudflare detected 2,000 vulnerabilities in its own critical systems, 400 of which were classified as high or critical severity, with a false positive rate lower than that of human testers. Mozilla found and remediated 271 vulnerabilities in Firefox 150—more than ten times the number discovered when it scanned Firefox 148 using earlier Claude models. Palo Alto Networks released patches at more than five times its normal cadence. Microsoft stated that the scale of its patch releases would continue to expand for the foreseeable future.
Anthropic itself scanned more than 1,000 open-source projects using Mythos Preview, detecting 23,019 issues. Of those, 6,202 were classified as high or critical severity. Six independent security research organizations verified 1,752 of those findings, and 90.6 percent were confirmed as genuine vulnerabilities. The numbers are impressive on their face, but the more revealing statistic is what happened next. Of the 530 high or critical severity vulnerabilities that had been disclosed to maintainers, only 75 had been patched as of May. The ability to find vulnerabilities at scale has outpaced the human capacity to fix them. Anthropic has acknowledged this bottleneck explicitly, stating that the program’s focus has shifted from discovery to verification, disclosure, and remediation.
What NATO and Samsung Joining Means for the Program
The initial Glasswing cohort consisted primarily of US-based technology giants: AWS, Apple, Google, Microsoft, CrowdStrike, NVIDIA, and Palo Alto Networks. The new wave of roughly 150 organizations reaches into sectors that were underrepresented in the first phase—power, water, healthcare, telecommunications, and hardware manufacturing. Critically, many of these new participants are not end-user organizations but “vendors”—companies and nonprofit entities that maintain codebases upon which countless governments and organizations depend.
Anthropic has not formally disclosed the full list of new partners, but reporting has confirmed participation by identity management firm Okta, Samsung Electronics, SK Hynix, SK Telecom, NATO, and ENISA. The inclusion of ENISA is particularly significant. Since Mythos Preview was made available in April, the European Union had pressed repeatedly for access. Multiple rounds of negotiations between the European Commission and Anthropic took place, and agreement was finally reached June 1. ENISA becomes the first EU body to join Project Glasswing. Those negotiations were reportedly complicated by the fact that vulnerabilities discovered by Mythos extended into European financial software—the European Central Bank convened eurozone banks to discuss the implications.
“What all partners have in common is that a successful attack on their codebase could produce catastrophic consequences. For a majority of partners, we estimate that a large-scale attack could impact over 100 million people.”
blockquoteblockquoteblockquoteblockquoteblockquote
That Anthropic used such explicit language in its official announcement signals the scale at which the company now views this program. These are not theoretical risks. The organizations being brought into the fold are precisely those where a single unpatched vulnerability could cascade across borders and sectors.
Competition Reshapes the Landscape
Anthropic is not operating in this space alone. In May, OpenAI released GPT-5.5-Cyber as a limited-access model. It is a cybersecurity-specialized variant of GPT-5.5 (codename “Spud,” released April 23) that permits defensive workflows for vetted security professionals. Testing by the UK AI Safety Institute (AISI) reported that GPT-5.5 successfully completed multi-step attack simulations in 2 out of 10 attempts.
Anthropic has stated publicly that within six to twelve months, many other companies will possess models with capabilities comparable to Mythos, and that those models may be released without the safety guardrails that Anthropic has built into Glasswing. That is not wishful thinking—it is a realistic assessment reinforced by the existence of GPT-5.5-Cyber. The competitive window during which Anthropic can exclusively supply defensive capability to critical infrastructure is narrower than many might assume, and the aggressive expansion of Project Glasswing reflects exactly that urgency.
The Two-Pronged Product Strategy
While Project Glasswing remains a limited-access program for critical infrastructure, Anthropic has also moved to productize its security capabilities for the broader market. On April 30, the company launched Claude Security as a public beta. Built on Claude Opus 4.7, it is a code-scanning and patch-suggestion tool for enterprise users, with plans to extend it to Team and Max plans. (The June 2 announcement also referenced Claude Opus 4.8 and the deployment of publicly available frontier models.)
On May 27, Anthropic released the “security-guidance” plug-in for Claude Code across all subscription tiers. The plug-in provides a three-layer real-time vulnerability detection system during code editing. Internally, Anthropic reports that the tool has reduced security-related code review comments by 30 to 40 percent.
These two tracks—Project Glasswing’s restricted-access model for the most sensitive targets and Claude Security’s broad commercial availability—form the dual strategy. The former concentrates Mythos-class capability on critical infrastructure; the latter raises the security baseline for developers everywhere using publicly available models. Both are necessary, and both are racing against the same clock.
The IPO Context: Timing as Signal
The June 2 expansion announcement came the day after Anthropic disclosed that it had confidentially filed a draft S-1 registration statement with the SEC on June 1. On May 28, the company closed a Series H round of $65 billion, pushing its post-money valuation to $965 billion. Reports place its annualized revenue run rate at approximately $47 billion as of May.
Project Glasswing serves as a powerful narrative for the IPO. “We are using our most advanced, unreleased model to fundamentally change the trajectory of cybersecurity” is a compelling value proposition for institutional investors. NATO and ENISA participation signals trust at the national-security level. That does not mean Anthropic expanded Glasswing solely for the IPO—the structural vulnerabilities in critical infrastructure will not wait for convenient market timing—but the simultaneous progress of both tracks should be understood as part of a single, coherent trajectory.
Time Remaining for Defenders
Anthropic’s own timeline is sobering. Within six to twelve months, models with Mythos-level capability will likely be available from other developers, potentially without safety guardrails. If and when that happens, attackers will have the same capability that defenders are now racing to deploy. The current window—during which defenders hold the advantage—must be used to eliminate as many vulnerabilities as possible and to build the institutional infrastructure for continuous, AI-assisted remediation at scale.
Project Glasswing will continue to expand, prioritizing critical infrastructure operators, major open-source software maintainers, and security testing firms. A Cyber Verification Program is also being planned for broader rollout. Longer term, Anthropic aims to make Mythos-class capability safely available to the general public, but the company acknowledges that the abuse-prevention mechanisms required for that step do not yet exist—not at Anthropic, and not anywhere in the industry.
As the cost of finding vulnerabilities approaches zero while the cost of fixing them remains entirely human-dependent, the asymmetry will persist. Every vulnerability that AI discovers is simultaneously a gift to defenders and a weapon for attackers. The difference lies in who gets there first and what they are allowed to do with what they find. Project Glasswing is Anthropic’s answer to that question, and the roster now includes NATO.