Anthropic Routes Claude Mythos 5's Cybersecurity Power Through Claude Security, Not Raw Model Access
Anthropic is putting Claude Mythos 5’s cybersecurity capability into defenders’ hands through a controlled product layer instead of direct model access. Claude Security, now in public beta for Enterprise customers, scans codebases on Mythos 5 and returns findings with CWE categories, confidence and severity ratings, and suggested fixes — the model never hands a user the kind of open-ended access that a bad actor could steer toward offense. Anthropic is pairing the release with the Defender Advantage Fund (0xDAF), $35 million in credits earmarked for patching vulnerabilities in open-source projects, on top of the $4 million Project Glasswing already donated to open-source security groups.
The design choice — specific defensive outputs instead of raw model access — is the same logic Anthropic used to scale its own internal tooling. In an earlier case study, the Government of Alberta’s Ministry of Technology and Innovation ran roughly 50 Claude Code agents in parallel to scan 466 million lines of code across 1,280 applications and 3,400 repositories in about 20 hours — work the team estimated would take 6.5 years by hand. Every fix still routed through human engineers before shipping; one subsidy-program portal, originally a five-month build, was rebuilt in four to five days. That’s the pattern 0xDAF is trying to fund at open-source scale: agentic scanning and patching, with a human checkpoint before anything merges.
The commercial case for output-limited access is already running in production. Anthropic separately profiled Outtake, a security startup whose “Recon Agent” traces full attack chains — from a cloned login page to the fake support accounts behind it — autonomously, for a median of 16 minutes per investigation. Outtake’s ARR grew 6x and its customer base grew more than 10x year-over-year while the system processed over 20 million potential cyberattacks in 2025. That’s the commercial proof that scoped, tool-using agentic security products can scale to real attack volume without needing to hand every user a raw frontier model.
For consulting engagements advising security or platform teams, the throughline is that Anthropic isn’t betting on broader raw access as the growth lever — it’s betting on more scoped products built on the same underlying capability, with 0xDAF specifically aimed at hardening the open-source infrastructure the rest of the industry depends on.