Visa Deploys Anthropic's Claude Mythos to Identify 10,000+ Vulnerabilities

iconCryptoBriefing
Share
AI summary iconSummary
Visa announced on-chain news of its collaboration with Anthropic on Project Glasswing, using the Claude Mythos Preview model to detect over 10,000 high or critical vulnerabilities in its payment network within a month. The AI model identified exploit chains by linking minor weaknesses, outperforming traditional methods. Visa also open-sourced the Visa Vulnerability Agentic Harness (VVAH) on GitHub on June 10, 2026, with Anthropic providing up to $100M in credits. The project highlights vulnerability news in enterprise security.

Visa’s payment network spans more than 200 countries and territories, moves money across roughly 160 currencies, and links nearly 5 billion payment credentials to more than 175 million merchant locations. It also, as it turns out, had a lot of vulnerabilities waiting to be found.

That discovery came courtesy of Anthropic’s Claude Mythos Preview model, deployed inside a collaboration called Project Glasswing that kicked off around April 7, 2026. Within the first month, the AI model surfaced more than 10,000 high or critical vulnerabilities buried across Visa’s software stack.

What Claude Mythos actually did differently

Traditional vulnerability scanning tends to catch the obvious stuff. Claude Mythos did something harder: it stitched together minor, individually unremarkable weaknesses into complete exploit chains, connecting dots that a human tester might not have linked until late in an engagement, or might have missed entirely.

Advertisement

Rajat Taneja, Visa’s president of technology, presented the results at VB Transform 2026 and made a point that deserves attention. His team moved away from traditional remediation metrics and replaced them with a concept they invented internally: Mean Time to Adapt. Patching is reactive. Adapting implies a continuous posture against a threat environment that is itself moving.

Visa’s existing architecture also held up under the scrutiny. The company’s zero-trust framework and network segmentation prevented any of the identified vulnerabilities from being exploited during the exercise.

Visa open-sources the harness, Anthropic backs it with $100M in credits

On June 10, 2026, Visa published the Visa Vulnerability Agentic Harness, or VVAH, on GitHub as an open-source project. The harness is the multi-model orchestration layer that governed the entire vulnerability hunt: discovery, remediation support, and validation, all wrapped into one framework that any organization can now pick up and use.

Anthropic provided Visa with up to $100M in credits for Project Glasswing, along with an additional $4M specifically earmarked for the open-source work.

Claude Mythos itself remains unreleased to the general public. Visa’s engagement with the Preview model puts it among a select group of early-access partners stress-testing Anthropic’s most capable systems on real-world production environments rather than benchmark suites.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.