Merit AC™
2026-10-06

Anthropic's vulnerability-hunting partners found 129,000 real flaws in four months -- and Anthropic thinks the true number is 5x higher

The expanded Cyber Verification Program folds Project Glasswing into a three-tier access structure, with the most sensitive tier -- flight systems, power grids -- reviewed case by case with the US government.

Anthropic announced on October 6 that it's expanding its Cyber Verification Program, folding the earlier Project Glasswing initiative into a three-tier access structure for defensive security work: Defense Access (security-operations and incident-response use, including malware reverse-engineering), Red Team Access (adds authorized penetration testing and red-teaming on top of the defensive tier, with individual researchers excluded), and Specialized Access, reserved for organizations testing safety-critical systems -- flight operating systems, power grids -- which Anthropic says it reviews "in depth in collaboration with the US government" on a case-by-case basis.

The number behind the announcement

The headline figure is what Project Glasswing's partners actually found while using Claude for defensive security work between April and July 2026: at least 129,000 verified software vulnerabilities, more than 33,000 of them rated critical or high severity. Anthropic's own open-source scanning efforts added another 5,500 verified vulnerabilities between April and October. The company's own estimate of the true scale is the more striking number: it believes the real impact is "at least five times higher" than what's been counted so far, based on partial data -- meaning Anthropic itself is treating 129,000 as a floor, not a total.

Why the access tiers matter more than the vulnerability count

A vulnerability count this size is easy to read as a pure capability flex -- look how much a model can find. The more consequential part of this announcement is the gating structure around who gets to point that capability at what: excluding individual researchers from red-team-level access, and routing the most sensitive use case (safety-critical infrastructure) through a government-reviewed approval rather than a self-service tier. That's Anthropic making an explicit bet that the risk from Claude finding vulnerabilities in the wrong hands scales faster than the benefit from finding them in the right ones -- and building the access control to match, rather than publishing the capability and trusting usage policy alone to contain it.

Sources

← All news