READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Anthropic Puts Its Most Powerful Cyber AI to Work Scanning Code, Backs It With $35M in Credits

Anthropic Puts Its Most Powerful Cyber AI to Work Scanning Code, Backs It With $35M in Credits
Anthropic rolled out Claude Mythos 5 inside its Claude Security product on August 21 and launched a $35 million credit fund for open-source defenders. The model that can find exploits never gets handed to a user directly, it just spits out a patch, which is exactly the right way to do this if the guardrails hold.

Anthropic's most capable cybersecurity model just went to work for anyone paying for Claude Enterprise. On August 21, 2026, the company announced that Claude Mythos 5, previously locked to a small group of vetted defenders, is now scanning codebases inside Claude Security, a product that entered public beta the same day.

The company also put real money behind it: a $35 million fund in Claude API credits, called the Defender Advantage Fund (0xDAF), aimed at organizations patching vulnerabilities in open-source software, according to Anthropic's own announcement on its Claude blog.

What actually changed

Mythos 5 has been around since April 2026 under a program called Project Glasswing, restricted to a handful of organizations securing critical software, according to Anthropic. A stripped-down public version, Claude Fable 5, launched with classifiers blocking cyber, biology, and chemistry queries.

Now Mythos 5 itself is doing real scanning work, just not in a chat window. An admin flips it on in the Claude console, a user picks a GitHub repository, and the model traces data flows across files and reads Git history rather than pattern-matching against a rules list, according to marktechpost. Each finding gets a CWE (Common Weakness Enumeration) category, a confidence score, a severity rating, and a suggested fix. Anthropic says findings pass an adversarial verification step where the model challenges its own result before it surfaces, which the company says is meant to cut down false positives.

Patching is a separate step. A human opens Claude Code, applies the fix using whatever model the organization already has access to, and a person has to approve it before it ships. No auto-merge.

Anthropic is billing the scans as standard token usage, no separate add-on fee, according to Unite.ai and confirmed on Anthropic's own blog post.

The logic behind keeping the model behind glass

Anthropic's stated reasoning is straightforward: the danger isn't the model's capability, it's direct access to it. A user who can prompt Mythos 5 freely could try to steer it toward writing exploits instead of finding them. A user who only receives a scan result, a patch, or an alert can't do that, according to Anthropic's announcement.

Anthropic has said Mythos 5 has the strongest cybersecurity capabilities of any model in the world, and that the same skills that find vulnerabilities can write exploits, according to marktechpost's reporting on the company's own statements. If that's true, the interface really is the safety mechanism, not the model's raw ability.

A scanning tool that can trace cross-file logic errors and authentication bypasses at a frontier level is still a tool that knows where the bodies are buried. Partner integrations follow the same "results only" design, according to Anthropic, but partner-built interfaces are only as good as the company that builds them. Anthropic says it and partners run abuse-prevention measures to keep the model inside scope, but that's a promise, not an audit.

Where the $35 million goes

The Defender Advantage Fund starts with a small set of pilot grants, with the first recipients expected in the coming weeks, according to Dealroom. Money flows to maintainers patching live vulnerabilities, automating scanning workflows, and building broader defenses, per Anthropic's own description.

Anthropic also says it's expanding its Cyber Verification Program, which currently gives vetted organizations reduced restrictions on Claude Opus and Sonnet, to cover broader dual-use capabilities in the coming weeks, with Mythos-class access to follow for defensive tasks. Project Glasswing itself continues with U.S. government partners for critical-infrastructure organizations meeting strict security requirements, according to Dealroom.

None of the seven sources reviewed here identify who is actually receiving the first 0xDAF grants, what "coming weeks" means in calendar terms for the Cyber Verification Program expansion, or how Anthropic verifies that partner integrations actually stay results-only in practice rather than trusting the partner's word. The enterprisedna.co writeup frames this mainly as a business-productivity story, useful for companies with thin security teams, but skips the dual-use tension entirely. The blurbrahlab.medium roundup buries the announcement in a list of unrelated Claude Code SDK updates without engaging the safety argument at all.

Anthropic is making a bet that scoped interfaces can neutralize the risk of a frontier-level offensive cyber model without walling it off completely. That bet has not been tested against a determined attacker trying to jailbreak a partner's wrapper around Mythos 5, and no independent security researcher's audit of the guardrails has been cited in any of the current reporting. Whether the Defender Advantage Fund's first grant recipients, due in the coming weeks according to Dealroom, actually move the needle on open-source vulnerability backlogs is the next thing to watch.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Crypto BriefingAnthropic expands Mythos 5 access, launches $35M open-source security fund
unknown
Unite.aiAnthropic Deploys Claude Mythos 5 in Security Tools, $35M Open-Source Fund
unknown
blurbrahlab.mediumAnthropic Launches $35M OSS Defense Fund with Claude Mythos 5 — Top 10 AI & Flutter News August 23, 2026 | by Blur Brah Lab | Aug, 2026 | Medium
unknown
marktechpostAnthropic Brings Claude Mythos 5 to Claude Security: Enterprise Teams Get Frontier Vulnerability Scanning Without Direct Model Access
unknown
enterprisedna.coAnthropic pushes Mythos 5 defensive tooling wider, opens a $35M vulnerability-patching fund
unknown
claudeBringing the cybersecurity capabilities of Claude Mythos 5 to more defenders | Claude by Anthropic
unknown
DealroomAnthropic embeds Claude Mythos 5 in security tools, pledges $35M in credits