During a security audit contest for Ethereum’s Fusaka upgrade, Octane AI identified a high-severity vulnerability and received a $50,000 award. The finding offered an early example of AI working alongside human security researchers to identify flaws in real-world software.
Anthropic has opened public-beta access to Mythos 5, its specialized cybersecurity model, to eligible Claude Enterprise customers. The model is available through the Claude Security plugin, with usage metered through an organization’s existing token allocation. Eligible customers must connect the plugin to the repositories they authorize Claude to assess.
More access to defenders
Anthropic first released the Mythos-class models in April this year to a few select organizations like Microsoft, JPMorgan Chase and the Linux Foundation, under a program called Project Glasswing. The initial rollout was limited to a small group of participating organizations, leaving the capability unavailable to most enterprise customers.
Under the expanded rollout, eligible Claude Enterprise users can ask the model to assess an authorized GitHub repository, present potential vulnerabilities, and recommend patches for developers to review.
For each security flaw, Claude returns “a CWE (Common Weakness Enumeration) category, confidence and severity ratings, and a suggested fix.”
Human approval is required before a suggested fix is implemented. This human-in-the-loop approach is intended to keep developers in control and reduce the risk of applying an incorrect or incomplete patch.
Additionally, the Mythos model only gives the user certain outputs like the vulnerability or patch. If the user attempts to ask the model carry out an attack like data exfiltration, it would reject this request.
This safeguard ensures that developers only use Mythos for legitimate purposes.
Some security professionals may have legitimate reasons to use the model for both offensive and defensive testing, such as developing or evaluating security tools. Anthropic directs eligible professionals who require access to higher-risk dual-use capabilities to apply to its Cyber Verification Program for modified safeguards.
Human experts still required
One of the main challenges with AI-assisted security audits is determining which findings are genuine and exploitable. A reported weakness may be a false positive, may not be exploitable under real-world conditions, or may carry too little risk to justify immediate remediation.
Nikos Baxevanis, a protocol security engineer at Ethereum Foundation, said: “The surprise was how little of the work went into finding them, and how much went into telling the real bugs from the ones that just looked real.”
This was in relation to an AI-assisted security scan that he, along with the protocol team, took on last month to uncover flaws in the Ethereum node software.
The capabilities that these new frontier models possess can’t be dismissed. They are actively enabling developers to uncover zero-day attacks, in addition to equipping defenders with state-of-the-art tools to counter malicious actors.
Beside providing frontier tools, Anthropic has shared that they are providing $35 million in credits to open-source projects that want to access AI-assisted security.
For enterprise security teams, Mythos 5 could accelerate repository reviews and help prioritize potential weaknesses, but its findings should be treated as leads rather than final verdicts. Organizations will still need experienced security professionals to validate exploitability, review proposed patches, and decide which findings warrant remediation.
Read more: Anthropic’s Project Glasswing signals a potential AI-driven shift in cybersecurity explains how the company’s earlier program tested AI-assisted vulnerability research with a limited group of security partners.





