Project Glasswing
Anthropic’s initiative for AI-assisted vulnerability research: organisations behind critical software were invited to test Claude Mythos against their own systems. visa participated and built visa-vulnerability-agentic-harness on what it learned (visa-mythos-glasswing).
Anthropic reports participants collectively identified more than 10,000 high- or critical-severity vulnerabilities in the first month across software underpinning critical systems industry-wide.
Anthropic’s own conclusion is the finding
Per visa-mythos-glasswing, Anthropic placed the bottleneck after discovery — in verification, disclosure and patching speed. The vendor whose model generated 10,000 findings in a month concluded that generating findings is not the constraint. Visa’s harness reaches the same conclusion independently and builds its primary metric around it (mean-time-to-adapt).
Why it matters to the guardrail problem
defender-guardrail-asymmetry documents Hugging Face’s forensics being refused by commercial APIs because “the providers’ safety guardrails cannot distinguish an incident responder from an attacker.” Glasswing is a partial answer of a specific kind: rather than solving the classification problem, Anthropic allocated access out-of-band — an invitation to named organisations to use, for defence, a model whose access it had restricted in April over exactly this capability (exploitgym).
That resolves the asymmetry for Visa and leaves it exactly where it was for everyone else. The distinguishing feature is not the request, it is the relationship, which is closer to how zero-trust answers the same question (identity and context rather than content) and further from anything a smaller responder can invoke mid-incident. Recorded in synthesis as a tension, not a fix.
Related
visa-mythos-glasswing · visa-vulnerability-agentic-harness · defender-guardrail-asymmetry · mean-time-to-adapt · exploitgym · visa · synthesis