Your privacy choices

Optional Google Analytics cookies help us understand which guides are useful. They stay off unless you accept. You can change your choice in the footer. Privacy policy

Anthropic Reports 129,000 Partner-Found Bugs and Expands Cyber Access

Anthropic’s expanded Cyber Verification Program offers tiered access. Its reported bug counts and benchmark results need careful interpretation.

By Ubedulla · 6 min read
A magnifying glass reveals a glowing orange crack in one panel of a vast wall of glowing code panels stretching into the distance.
Editorial illustration of cybersecurity research; not a screenshot of reported vulnerabilities.

Anthropic reports that Glasswing partners found at least 129,000 verified vulnerabilities from April through July 2026. These are vendor-reported totals, not findings independently reproduced by The Bot Post.

The announcement also reports 5,500 findings from Anthropic’s own scanning and more than 33,000 critical- or high-severity findings across the reported work. Its estimate of broader impact is an extrapolation from incomplete partner reporting.

That is the headline statistic from a programme called Project Glasswing, and on October 6 Anthropic announced what it is doing next: folding Glasswing into a three-tier Cyber Verification Program that hands vetted security teams versions of Claude with fewer and fewer safeguards, up to a tier where, by the company's own measurement, the cyber blocks are effectively off.

The numbers first

  • 129,000 verified vulnerabilities found by Glasswing partners, April–July 2026
  • 5,500 more found by Anthropic's own open-source scanning, April–October 2026
  • 33,000+ rated critical or high severity
  • 5× — Anthropic's estimate of how much the true count exceeds the survey

Finding vulnerabilities and fixing them are different outcomes. A discovery count alone cannot establish a patch rate or the proportion attackers exploited.

The three tiers

The new programme replaces the old all-or-nothing Glasswing membership with graduated access. Applications go through Anthropic's developer portal, and existing Glasswing members move into the top tier without reapplying.

Defense Access

For security operations centres, incident response, malware reverse-engineering and vulnerability analysis. Open to company security teams, nonprofits, universities, government bodies, critical infrastructure operators, smaller security firms, open-source maintainers and, notably, individual researchers with a track record of vulnerability disclosure. Review takes "a few days."

Red Team Access

Everything in Defense, plus authorised penetration testing and red-teaming. Organisations only: in-house red teams, government red teams, pentest firms. Individuals are not eligible. Review takes "a few weeks." Real-time blocks still apply to anything that could cause physical harm or mass disruption.

Specialized Access

The fewest cyber blocks of all. Reserved for verified organisations authorised to test the safety systems that genuinely cannot fail: flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networks. Applications are reviewed in collaboration with the US government.

All three tiers get Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, plus future models. Mythos is the one to pay attention to: it is the version of Anthropic's top-tier model that ships without the extra dual-use safety measures applied to the consumer-facing Fable 5.1, and until now it has been available only to a handful of approved organisations.

How much the safety rails actually come off

This is the part most coverage is skipping, and it is the most interesting thing in the announcement.

Anthropic tested each tier against an internal benchmark called CyScenarioBench: 10 offensive cyber challenges, 5 attempts each, 50 trials per tier, run on Claude Opus 5.5. The results:

  • Standard Claude (no programme): all 50 trials blocked on the first prompt.
  • Defense Access: 46 of 50 blocked. Four succeeded.
  • Red Team Access: zero blocks. The model completed 34 of 50 trials, a 68% success rate on offensive tasks.
  • Specialized Access: the announcement uses an unguarded-model result as a benchmark comparison, not a claim that every possible safeguard is absent.

In these 50 trials, the Red Team configuration produced no blocks. That result does not mean it never refuses requests outside this evaluation; Anthropic says restrictions remain for physical harm and mass disruption.

The fine print

Two conditions come with the access, and both matter for anyone considering applying.

Retention has exceptions. Anthropic generally requires retention for the program, but describes an interim exception for organizations already using Fable 5.1 or Mythos 5.1 with zero data retention. Consult the linked announcement for eligibility rather than assuming every applicant has the same terms.

Platform availability is uneven. The programme runs on the Claude Platform, Google Cloud Vertex AI and Microsoft Foundry. On Amazon Bedrock it is limited to customers eligible for Enterprise Frontier Safeguards.

There is also a form for reporting false positives, which tells you something about how often the blocks fire on legitimate defensive work.

Why this matters beyond security teams

Three things are happening at once here.

First, the reported scale is large. Discovery totals are useful evidence to examine, but independent reproduction and patch verification would tell readers more than the headline number alone.

Second, Anthropic is now in the business of selling tiers of restraint. The same model, with the same capabilities, behaves differently depending on who you are and what you have proven about yourself. That is a reasonable answer to the dual-use problem. It is also a system whose entire safety story now rests on how good Anthropic's verification is. Vet the wrong firm and the 68% success rate on offensive tasks belongs to them.

Third, this is the industry's direction, not one company's. OpenAI open-sourced an AI security auditor this summer. The month before that, OpenAI's own agents escaped a cyber evaluation and spent four days inside Hugging Face. The capability is here either way. The question each lab is now answering, in public, is who gets the version with the brakes removed.

Frequently asked questions

What is Project Glasswing?

Anthropic's programme giving vetted partners access to Claude with reduced cyber safeguards for finding and fixing vulnerabilities. Between April and July 2026, partners reported 129,000 verified vulnerabilities. It is now being folded into the expanded Cyber Verification Program.

What is the Cyber Verification Program?

A three-tier access scheme (Defense, Red Team, Specialized) announced on October 6, 2026. Each tier removes more cyber-related blocks from Claude, in exchange for stricter verification of who is applying.

Which models are included?

Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, with future models to be added. Existing members are automatically evaluated for new models.

Can individuals apply?

Yes, but only for Defense Access, and only with a documented history of responsible vulnerability disclosure. Red Team and Specialized Access are limited to organisations.

Does Red Team Access really have no safeguards?

Cyber-specific blocks did not fire in any of the 50 benchmark trials, but Anthropic says real-time blocks remain on actions that could cause physical harm or mass disruption. The benchmark comparison does not establish that all safeguards are absent from every Specialized Access use.

Reporting based on Anthropic's "Expanding the Cyber Verification Program" announcement of October 6, 2026, and coverage from The Hacker News, SecurityWeek, CSO Online and SiliconANGLE. Benchmark figures are Anthropic's own. The Bot Post will update this story as independent evaluations appear.

Editorial correction, October 8, 2026: Attributed the totals, bounded the benchmark conclusions and clarified retention exceptions. Removed an exploitation-rate claim not substantiated by the linked announcement.

About the author

Ubedulla

Founder & Editor

Founder and editor of The Bot Post, covering AI news and technology.

Related Articles