Skip to content
InnovateTechie
Claude AI

Claude Mythos Preview: What It Is and Who Can Access It

EdithBy Edith11 min read
Share
Claude Mythos Preview, the restricted Anthropic frontier model behind Project Glasswing

Part ofClaude Models Explained: Opus vs Sonnet vs Haiku

Quick answer

Claude Mythos Preview is Anthropic's restricted frontier model behind Project Glasswing. What it found, why it stays private, and who can actually access it.

Key takeaways

  • Anthropic disclosed Claude Mythos Preview on April 7, 2026 but never sold it — access stayed limited to roughly 50 vetted Project Glasswing partners.
  • Anthropic reports it found a 27-year-old OpenBSD SACK bug for under $50 per run and produced 181 working Firefox exploits versus 2 for Opus 4.6 — vendor figures, not independently reproduced.
  • The Preview is superseded: Claude Mythos 5 is the current restricted version, and Claude Fable 5 is the same underlying model with safety classifiers on and general availability.
  • Both current Mythos-class models list $10 per million input tokens and $50 per million output — eligibility, not price, is the barrier.
  • U.S. export controls barred non-U.S. nationals from both models between June 12 and June 30, 2026, with access restoration beginning July 1.

Claude Mythos Preview is the Anthropic model you almost certainly cannot use. Anthropic disclosed it on April 7, 2026, and deliberately never released it to the public — because it found exploitable flaws in every major operating system and every major web browser it was pointed at.

Model availability and pricing verified 31 July 2026 against Anthropic's model overview.

Every other Claude release follows a familiar script: an announcement, an API endpoint, a pricing page. This one broke the script. Anthropic built the model, handed it to roughly 50 companies under a program called Project Glasswing, published what it did, and then kept it off the open market on purpose.

Here's what the model actually is, what it found, and the honest answer on whether you can get near it.

Key takeaway

Anthropic disclosed Claude Mythos Preview on April 7, 2026 but never sold it — the model found a 27-year-old OpenBSD bug for under $50 per run and produced 181 working Firefox exploits versus 2 for Opus 4.6, so access stayed limited to roughly 50 vetted Project Glasswing partners.

What is Claude Mythos Preview?

It is a general-purpose Anthropic frontier model that proved unusually strong at finding software vulnerabilities and writing working exploits. Announced on April 7, 2026, it was a disclosure rather than a product — no tier, no endpoint, no pricing page.

Claude Mythos Preview is a general-purpose frontier language model from Anthropic that proved unusually capable at computer security work — specifically, at finding software vulnerabilities and writing working exploits for them. Anthropic announced it publicly on April 7, 2026 and stated it had no plans for a general release.

The word Preview is doing real work in that name. It was never a product tier you could buy. It was the first model in what Anthropic now calls the Mythos class, and its public existence was essentially a disclosure — a lab telling the world what its internal model could do, rather than selling access to it.

According to Wikipedia's account of the rollout, the model's existence actually surfaced on March 26, 2026 through leaked blog post drafts, about two weeks before Anthropic's own announcement.

What the model actually found

Anthropic reports a 27-year-old OpenBSD SACK bug found for under $50 a run, a 16-year-old FFmpeg flaw, a 17-year-old FreeBSD NFS bug, and 181 working Firefox exploits against 2 for Opus 4.6. Treat these as vendor figures.

The numbers are the reason anyone cares. In Anthropic's own assessment of Mythos Preview's cybersecurity capabilities, the model:

  • Discovered a 27-year-old OpenBSD SACK vulnerability, at a cost of under $50 per discovery run
  • Found a 16-year-old FFmpeg H.264 codec flaw that had survived years of scrutiny
  • Identified a 17-year-old FreeBSD NFS remote code execution bug, now tracked as CVE-2026-4747
  • Produced working exploits 181 times on Firefox JavaScript vulnerabilities, against just 2 for Claude Opus 4.6 — a model released only a month earlier
  • Hit 595 crashes at tiers 1–2 on OSS-Fuzz benchmarks, where earlier models managed 150–175

Across roughly 1,000 open-source projects Anthropic scanned, Mythos surfaced 23,019 issues, of which 6,202 were high or critical severity — and more than 90% were validated as true positives. Mozilla alone reported 271 security vulnerabilities found in Firefox.

What Claude Mythos Preview uncovered — a 27-year-old OpenBSD SACK bug, a 16-year-old FFmpeg H.264 flaw, a 17-year-old FreeBSD NFS bug (CVE-2026-4747), and 181 Firefox exploits versus 2 for Opus 4.6

The economics are the part security teams noticed. Around 1,000 OpenBSD scanning runs cost under $20,000 total; hundreds of FFmpeg scans came in near $10,000. Anthropic reported that Claude Mythos Preview autonomously developed exploits in hours that expert penetration testers estimated would take weeks.

One evaluation from this run became a headline of its own — the story that Claude Mythos escaped a secure environment, which is less dramatic and more interesting than the coverage suggests.

It's worth saying plainly: independent researchers have questioned some of these claims, noting the headline results leaned heavily on a small number of specific bugs. The findings are Anthropic's own, published by the company that built and benefits from the model, and they have not all been independently reproduced. Treat the exploit counts as a vendor benchmark rather than a peer-reviewed result — the direction is clear even where the magnitude is arguable.

When we write up a restricted model like Claude Mythos Preview that we cannot call ourselves, our standing rule is to attribute every capability number to Anthropic's own document and stop short of implying we verified it. We have learned to keep the model's claimed feats and our own hands-on experience in separate boxes, because blurring them is how a vendor benchmark quietly gets repeated as an independent result. On a model nobody outside Glasswing can test, the honest posture is to report the source, not to vouch for the figure.

Why it was never made publicly available

The same capability that finds a flaw also weaponises it, and Anthropic judged defence unready. Safeguards were procedural rather than technical: vetted critical-infrastructure access only, a 90-day disclosure clock extendable by 45 days, and human validators on every report.

The reason is that the same skill that finds a vulnerability also weaponises it, and Anthropic decided the defensive side of that trade wasn't ready. The company framed this as a transitional period: a window where the technology can find flaws faster than the world can fix them.

Anthropic's own framing was blunt — in the short term, the beneficiaries of a careless release could be attackers. A model that chains multiple undisclosed vulnerabilities into a working intrusion path is genuinely dual-use, and there is no configuration flag that separates the two uses.

So the safeguards were procedural rather than technical:

  • Access limited to vetted critical-infrastructure operators through Project Glasswing
  • A responsible disclosure clock of 90 days, extendable by a maximum of 45 more
  • Professional human validators reviewing bug reports before any disclosure
  • A planned Cyber Verification Program for legitimate security professionals

What is Project Glasswing?

Glasswing is the vetted-partner program that let roughly 50 organisations — AWS, Apple, Cisco, Google, Microsoft, NVIDIA and peers — scan their own codebases with the model. It expanded to about 150 more on June 2, 2026, and there is no self-serve signup.

Project Glasswing is the Anthropic program that put Claude Mythos Preview in the hands of the organisations most likely to be attacked. Rather than sell the model, Anthropic gave screened partners the ability to scan their own codebases with it.

The launch cohort in April 2026 was about 50 partners, and the names explain the intent: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks. Between them, partners found more than 10,000 high- or critical-severity flaws.

On June 2, 2026 Anthropic expanded Project Glasswing to roughly 150 more organisations across more than 15 countries, widening it into power, water, healthcare, communications and hardware. Many of the new partners ship code whose compromise could affect more than 100 million people.

Organisations don't apply and get a key. They have to meet Anthropic's security requirements before access is granted — which is why searches for anthropic claude mythos preview project glasswing rarely end in a signup page.

Claude Mythos Preview vs Mythos 5 vs Fable 5

The Preview model is superseded and unavailable. Mythos 5 is the current restricted version, and Fable 5 is the same underlying model with safety classifiers switched on and general availability. Both list $10 per million input tokens and $50 output.

This is where most write-ups are out of date. Claude Mythos Preview is no longer the current Mythos-class model. On June 9, 2026 Anthropic released two successors, and the split between them is the whole story.

Claude Mythos PreviewClaude Mythos 5Claude Fable 5
StatusSuperseded (April 2026)Current, restrictedCurrent, general availability
Model IDnot offeredclaude-mythos-5claude-fable-5
Who can use itGlasswing partners onlyGlasswing cyber partners; limited biomedical enrollmentAnyone
SafeguardsProcedural onlyLifted in some areasFull — risky queries fall back to Opus 4.8
Price per 1M tokensnot offered$10 in / $50 out$10 in / $50 out

Which Mythos model you can actually use — Mythos Preview is superseded with no access, Mythos 5 is restricted to Glasswing partners, Claude Fable 5 is generally available, and Opus 4.8 is the safe fallback

Fable 5 and Mythos 5 are the same underlying model. The difference is safeguards, not capability. Fable 5 ships with safety classifiers that route cybersecurity, biology and distillation queries to Claude Opus 4.8 instead of answering them directly. Mythos 5 is that model with specific safeguards lifted for vetted partners, and it carries a 30-day data retention requirement for safety monitoring.

If a page currently quotes Mythos pricing at $25 per million input tokens, it predates this release. Anthropic's published figure is $10 in and $50 out for both current models — the same rate, because it's the same model underneath. For a wider view of how these tiers relate, see our guide to the Claude model lineup and the Opus release history.

What happened with the export controls?

Between June 12 and June 30, 2026 the U.S. Department of Commerce barred non-U.S. nationals from either current Mythos-class model. The controls were then lifted, and access restoration for affected organisations began on July 1.

For about three weeks, nationality decided access — a wrinkle almost no coverage mentions. The timeline:

  1. June 12, 2026 — the U.S. Department of Commerce prohibited non-U.S. nationals from accessing either Mythos 5 or Fable 5
  2. June 30, 2026 — those export controls were lifted
  3. July 1, 2026 — access restoration began for affected organisations

Anthropic's Mythos page confirms the lifting restored access for certain US organisations. For a model priced identically to a normal API product, that detour through export-control policy is the clearest signal of how governments currently classify Mythos-class capability.

What it means if you'll never touch it

Its legacy is what it forced into the open: Mythos-class capability is heading toward broader release as safeguards mature, Fable 5 already ships much of it publicly, and Claude Security brings codebase scanning to teams outside Glasswing.

Most readers will never run this model, and that's rather the point. Its practical legacy is what it forced into the open.

Anthropic has confirmed that Mythos-class capability is heading toward broader availability as safeguards mature, with new protections planned for an upcoming Opus model. Claude Fable 5 is already the proof: Anthropic describes its capabilities as exceeding anything the company had previously made generally available, with the risky paths fenced off rather than removed.

Anthropic also shipped Claude Security, a codebase scanning tool built on public models, so teams outside Glasswing get some of the defensive benefit. For example, a team wanting a security review today would use the public tooling — see our notes on the Claude Code security review — not a Mythos-class model.

The uncomfortable implication stands on its own. If a model can find a 27-year-old bug in OpenBSD for under $50, that bug was findable all along. Claude Mythos Preview didn't create the risk; it revealed how much of it was already sitting there.

The model was public knowledge before Anthropic said a word — the Claude Mythos leak put finished announcement drafts on the open web twelve days early.

The current restricted model is Claude Mythos 5 — byte-identical to Fable 5 at the same price, so the gate is eligibility rather than money.

Frequently Asked Questions

No. Claude Mythos Preview was never generally available and has been superseded by Claude Mythos 5, which remains restricted to vetted Project Glasswing partners and a limited biomedical research enrollment. The closest thing you can actually use is Claude Fable 5.

Nearly. Claude Fable 5 and Claude Mythos 5 share the same underlying model. Fable 5 is generally available with safety classifiers that redirect cybersecurity and biology queries to Claude Opus 4.8, while Mythos 5 has those safeguards lifted for approved partners.

Anthropic lists $10 per million input tokens and $50 per million output tokens for both Claude Mythos 5 and Claude Fable 5. Pricing is not the barrier to Mythos — eligibility is.

Organisations must meet Anthropic's security requirements before receiving access, and the program targets operators of critical software and infrastructure. There is no self-serve signup, and individual developers are not the intended audience.

To document the capability publicly and coordinate defence before that capability became widely available. Anthropic argued that a careless release would benefit attackers first, so it disclosed the results while restricting the model itself.
Edith

Written by

Edith

Writing about Claude and the Anthropic toolkit — models, Claude Code, pricing, features, and fixes, in clear, practical, hands-on guides tested by daily use.

View all posts →