Anthropic opens Claude Mythos 5.1 to vetted defenders — and authorized hackers: the Cyber Verification Program's three tiers
Anthropic merged Project Glasswing and its Cyber Verification Program into a single three-tier program announced Tuesday, giving verified security professionals reduced safeguards on Claude Mythos 5.1, Opus 5.5 and Sonnet 5.5 — after Glasswing partners found more than 129,000 verified software vulnerabilities in four months.
On Tuesday, Anthropic announced a revamp of its Cyber Verification Program — the free, application-based scheme that lets vetted security professionals use Claude for legitimate defensive work its default cyber safeguards block. The new CVP folds in Project Glasswing, the defensive initiative built around Claude Mythos, Anthropic's most cyber-capable model family, into one program with three tiers: Defense, Red Team, and Specialized.
“We’re expanding our Cyber Verification Program to give security professionals broader access to our most capable models,” the company said in its announcement. “Through this program, verified security professionals can access Claude Mythos 5.1, Opus 5.5, and Sonnet 5.5 with safeguards designed for defensive work. We’re also opening up new tiers to allow for authorized offensive work, like penetration testing and red-teaming.”
The numbers that forced the move
Under Glasswing, organizations securing critical software found at least 129,000 verified vulnerabilities between April and July. Anthropic's own open-source scanning turned up 5,500 more between April and October. More than 33,000 of the findings so far are rated critical or high severity.
Anthropic says those figures are likely an undercount: they come from a survey of a limited number of partners, and the company expects the true impact to be at least five times higher.
The stakes were set in April, when Anthropic unveiled Claude Mythos Preview — a model capable enough at finding and exploiting software flaws that the company declined to release it publicly at all, routing it instead to vetted defenders. That decision, widely read as an admission that frontier cyber capability was arriving faster than defenses could absorb it, is the direct ancestor of today's program.
The three tiers
All three tiers include access to Claude Opus 5.5, Sonnet 5.5 and Mythos 5.1, plus future models. Each tier has its own verification requirements and security controls:
Defense covers work such as incident response and malware analysis. Security teams, critical infrastructure operators, open-source maintainers and researchers with a record of reported vulnerabilities can apply.
Red Team adds authorized penetration testing and red-teaming. Only organizations can apply — no individuals.
Specialized has the fewest restrictions and is reserved for a small group of organizations authorized to test safety-critical systems: power grids, flight systems, and interbank transfer infrastructure.
Anthropic vets every member jointly with the US government, and existing Glasswing members move into the Specialized tier. Anthropic's CVP documentation confirms the tier structure, including that Specialized Access is not available through third-party platforms.
Why it matters
The industry's operating assumption is now explicit: models that can find and exploit zero-days will be in everyone's hands within six to twelve months, so defenders get them first. The new CVP turns that head start into a formal program — and makes access to offensive AI capability a gated, government-co-vetted privilege rather than a product anyone can buy.
That gate cuts both ways. Providers need a way to tell a red team from a criminal: the same request is routine defensive work in one context and a crime in another. But it also concentrates the decision over who may wield the sharpest tools in a lab working hand-in-hand with a state. And it lands in a week when the Pentagon told the BBC it had ceased using Anthropic's products, months after designating the company a supply-chain risk — a reminder that the relationship between frontier labs and governments is being negotiated on several fronts at once.