Project Glasswing reported the discovered OpenBSD and Linux vulnerabilities to their respective maintainers, who then implemented and deployed the necessary patches.
AI Fact-Check
“Anthropic's announcement of Project Glasswing on April 7, 2026, states that its AI model, Claude Mythos Preview, discovered numerous vulnerabilities, including a 27-year-old bug in OpenBSD and several privilege escalation flaws in the Linux kernel. Multiple news outlets and Anthropic's own technical blog confirm that these specific vulnerabilities were reported to the software maintainers. The reports explicitly state that the maintainers subsequently fixed the bugs and deployed the patches. Context: This claim is part of the initial announcement for Project Glasswing, used as a key example to demonstrate the power of the AI model and the necessity of the initiative. The vulnerabilities mentioned are among the first publicly disclosed findings from the project.”
Source Videos (1)
(9) An initiative to secure the world's software | Project Glasswing - YouTube
Anthropic
Related Claims
Project Glasswing identified multiple vulnerabilities in Linux that permit a user without permissions to escalate to administrator privileges by executing a specific binary on their machine.
Project Glasswing utilized the Claude Mythos Preview model to scan open-source code, specifically prioritizing operating systems because they underpin the entire internet infrastructure.
Project Glasswing discovered a 27-year-old vulnerability in OpenBSD that enables an attacker to crash any OpenBSD server by transmitting a small amount of data.