Anthropic on April 7 disclosed that its unreleased Claude Mythos Preview model autonomously discovered thousands of high-severity zero-day vulnerabilities across every major operating system and web browser, including flaws in the cryptography libraries that underpin DeFi infrastructure. The comp...
"AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure." — Anthony Grieco, Chief Security Officer, Cisco
Anthropic on April 7 disclosed that its unreleased Claude Mythos Preview model autonomously discovered thousands of high-severity zero-day vulnerabilities across every major operating system and web browser, including flaws in the cryptography libraries that underpin DeFi infrastructure. The company is withholding the model from public release, instead sharing it with 40 organizations — including JPMorgan Chase, Google, Apple, and Microsoft — under a defensive initiative called Project Glasswing, backed by up to $100 million in compute credits.
The disclosure lands on a DeFi ecosystem managing approximately $200 billion in total value locked across smart contracts on Ethereum, Solana, and other chains. Anthropic's own red-team research (SCONE-bench) showed prior-generation models exploiting 51.1% of 405 historically attacked smart contracts, extracting $550.1 million in simulated value. Mythos operates a tier above those models. The implied threat: the cost to find and exploit smart contract vulnerabilities is falling faster than the industry can patch them.
Claude Mythos Preview identified what Anthropic describes as "thousands of high-severity zero-day vulnerabilities" across major software stacks. Specific disclosed findings include:
Anthropic submitted 198 findings for manual review by external contractors. Of those, 89% received the same severity rating the model assigned, and 98% fell within one severity level, according to the company's technical assessment published April 7.
Project Glasswing is a controlled-access defensive security initiative. Its 12 founding partners are: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, Palo Alto Networks, and Anthropic.
Financial commitments from Anthropic:
| Category | Amount | |---|---| | Mythos Preview usage credits | Up to $100 million | | Alpha-Omega / OpenSSF (via Linux Foundation) | $2.5 million | | Apache Software Foundation | $1.5 million | | Total disclosed | $104 million |
An additional 40+ organizations supporting critical infrastructure receive secondary access. Open-source maintainers can apply through the Claude for Open Source program. Anthropic committed to publishing 90-day public reports on vulnerabilities fixed.
Post-preview pricing for Mythos is set at $25 per million input tokens and $125 per million output tokens — approximately 2.5x the cost of Claude Opus 4.6 at current rates.
Anthropic released comparative performance data on standard security and coding benchmarks:
| Benchmark | Claude Mythos Preview | Claude Opus 4.6 | |---|---|---| | CyberGym | 83.1% | 66.6% | | SWE-bench Pro | 77.8% | 53.4% | | SWE-bench Verified | 93.9% | 80.8% |
In targeted exploit testing, Mythos generated 181 successful shell exploits against the Firefox 147 JavaScript engine, compared to 2 for Opus 4.6. On the OSS-Fuzz benchmark covering 7,000 entry points, Mythos achieved the highest-tier control flow hijack 10 times; predecessor models managed it once each.
Against a set of 40 potentially exploitable Linux kernel CVEs from 2024-2025, Mythos built working privilege escalation exploits for over half.
"The window between vulnerability discovery and exploitation has collapsed — minutes with AI," stated Elia Zaitsev, CTO of CrowdStrike.
The Mythos disclosure intersects with DeFi security at three levels:
1. Cryptographic Infrastructure TLS, AES-GCM, and SSH are not blockchain-specific, but they are foundational to the off-chain infrastructure DeFi depends on: node communication, RPC endpoints, oracle feeds, custodial systems, and exchange APIs. Flaws in these libraries affect every protocol that relies on standard internet security for its operational layer.
2. Smart Contract Code Anthropic's SCONE-bench evaluation, conducted with prior-generation models (Claude Opus 4.5, Sonnet 4.5, GPT-5), tested 405 historically exploited smart contracts across Ethereum, BSC, and Base. Results:
Two vulnerability types — improperly protected function calls and WebKeyDAO pricing logic flaws — accounted for 92% of exploited value. These are known vulnerability classes, but the speed and cost at which AI models locate them has shifted.
3. Friction-Based Defenses Anthropic's assessment notes that "mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries." This directly implicates multisig governance, timelocks, and the traditional security audit model — all of which impose time and complexity costs that AI-driven attackers can compress.
The Mythos disclosure arrives against a backdrop of continued DeFi losses. According to multiple security firms, Q1 2026 totals include:
Year-over-year DeFi protocol losses declined from $1.58 billion in Q1 2025 (skewed by Bybit's $1.4 billion breach) to $168.6 million. But 2025 closed at a record $3.4 billion in total crypto theft, per Chainalysis, suggesting the attack surface continues to expand.
The economic calculus is stark: Anthropic demonstrated that a prior-generation model can scan 2,849 contracts and find exploitable zero-days for approximately $3,476 in compute. Mythos, which operates at materially higher capability, would presumably lower that cost further.
The market registered the announcement with a 7% gain in the CoinDesk DeFi Select Index within 24 hours — an unusual positive reaction to a security threat disclosure, possibly reflecting expectations that Project Glasswing's defensive capabilities will benefit the ecosystem.
Several structural questions remain unaddressed:
Access asymmetry. Project Glasswing gives 40+ organizations defensive access to Mythos. The remaining thousands of DeFi protocols, many with sub-$10 million TVL and minimal security budgets, do not have access. The question of whether Mythos-level capabilities will reach adversarial actors before they reach small DeFi teams is not theoretical — Anthropic's December 2025 red-team study already demonstrated that non-frontier models could "autonomously exploit smart contracts and uncover novel zero-day vulnerabilities at low cost."
Audit model obsolescence. The traditional smart contract audit — a one-time human review costing $50,000–$500,000 — was already under pressure. If AI can scan codebases continuously and at near-zero marginal cost, the static audit model may not survive in its current form. According to Igor Tsyganskiy, Microsoft CISO: "The opportunity to use AI responsibly to improve security at scale is unprecedented."
Regulatory implications. There is no current framework requiring DeFi protocols to undergo AI-assisted vulnerability assessment, nor is there guidance on liability when AI-discoverable flaws lead to exploits. The SEC's pending Reg Crypto framework does not address this vector.
Open-source exposure. Jim Zemlin, Executive Director of the Linux Foundation, stated: "Project Glasswing offers a credible path to changing the equation for open source maintainers." Most DeFi protocols rely on open-source dependencies — the same dependencies Mythos is now scanning. The 90-day disclosure window creates a race condition between defensive patching and adversarial exploitation.
The Mythos disclosure marks a measurable shift in the cost curve for vulnerability discovery. Finding a 27-year-old zero-day for under $50 in compute, or scanning 2,849 smart contracts for exploitable flaws at $3,476, establishes a new baseline for what AI-assisted security research — and AI-assisted attacks — can achieve.
For DeFi, the implications are concrete. The ecosystem's $200 billion in locked value depends on a security model built around human audits, multisig governance, and time-delayed transactions. Anthropic's own data suggests these defenses degrade against model-assisted adversaries. Project Glasswing provides a defensive umbrella for 40+ organizations, but the majority of DeFi protocols operate outside that perimeter.
The 90-day reporting window will offer the first empirical look at whether Mythos-driven defensive scanning reduces exploit rates in practice. Until then, the data points in one direction: the cost to attack is falling faster than the cost to defend.