Anthropic said on August 21 that it is expanding access to its most capable and most tightly restricted model, Claude Mythos 5, by folding it into Claude Security, the company’s vulnerability-scanning tool, and by launching a new fund to support open-source software security.

Mythos 5 moves into Claude Security

Claude Security, in public beta for Anthropic’s Enterprise customers, now runs scans on Mythos 5 instead of smaller models. Customers can point the tool at a codebase they own through claude.ai/security and get back findings tagged with a vulnerability category, a severity and confidence rating, and a suggested fix — reviewed by a human before any patch goes in. The scans bill as standard token usage rather than a separate product fee.

Mythos 5 had previously reached only a vetted group of defenders through Project Glasswing, a consortium that started getting early access in April. What Is Claude Mythos 5 explains why the model’s dual-use cyber capabilities have made its rollout unusually cautious so far.

A $35 million fund for open-source maintainers

Alongside the product change, Anthropic launched the Defender Advantage Fund, internally called 0xDAF, offering $35 million in Claude credits to groups working on open-source software security. The company says the money targets teams patching live vulnerabilities in widely used projects, building repeatable scanning-and-patching workflows, and testing new defensive approaches — the unglamorous maintenance work open-source security often struggles to fund.

Anthropic is also widening its Cyber Verification Program, which already gives vetted defenders reduced safeguards on Opus and Sonnet models; it said broader dual-use access on those models is coming within weeks, with Mythos-class access to follow.

The company framed the staged rollout as a safety trade-off. Rather than hand out direct model access, Anthropic said the riskiest scenario is a user with unrestricted access to a model, since a malicious actor “can try to steer it toward harmful uses” — hence routing Mythos 5 through structured tools like Claude Security instead.