# Mythos 5 Goes Scan-and-Patch — Not a Chat Box — With $35M in Defender Credits

Times of AI Desk · 2026-08-21 · Research

[https://timesof.ai/2026/08/anthropic-claude-security-mythos-5-defender-fund](https://timesof.ai/2026/08/anthropic-claude-security-mythos-5-defender-fund)

> Anthropic put Claude Mythos 5 behind Claude Security for Claude Enterprise: CWE category, confidence, severity, and a suggested patch without giving the user a Mythos prompt box — and launched the Defender Advantage Fund with $35 million in Claude credits for open-source vulnerability work. Bounded defensive outputs, not Mythos consumer GA.

Mythos-class cyber is the capability labs will not put in a chat box. Anthropic is productizing it as **scan-and-patch** and **partner artifacts**, then paying OSS maintainers in **credits**.

**Anthropic** put **Claude Mythos 5** behind **Claude Security** for **Claude Enterprise** (public beta): pick a repo at **claude.ai/security**, get findings with **CWE**, confidence, severity, and a suggested fix. **Scans bill as standard token usage** — no add-on. Interactive patching in **Claude Code** uses the models the org already has; **Mythos does not leak** onto other surfaces. Same post: **Defender Advantage Fund (0xDAF)** — **$35 million in Claude credits** for OSS patching, scan/patch automation, and ambitious hardening; small pilot grants first. **Cyber Verification Program** will expand dual-use access on **Opus/Sonnet** in coming weeks, with **Mythos-class** defensive access to follow. Partners can integrate Mythos so end users receive **artifacts** (patches, alerts), not a chat.

## What shipped

| Item | Detail (claude.com/blog primary) |
|------|----------------------------------|
| **Claude Security × Mythos 5** | Enterprise public beta; admin enable in console |
| **Output** | CWE + confidence/severity + suggested patch; **human approval** required |
| **Billing** | Standard tokens |
| **0xDAF** | **$35M** credits; builds on Glasswing’s **$4M** cash + credits |
| **CVP** | Reduced safeguards today on Opus/Sonnet; Mythos defensive expansion “coming weeks” |
| **Partner path** | Mythos in existing SOC/IR tools; register interest form |

Thesis in the post: **direct model access** is the risky bit; **bounded defensive outputs** are how Glasswing scales beyond the original small cohort. **Fable 5** remains the broadly available model that **blocks dual-use cyber**. This is **not** a Mythos 5 consumer GA.

Not Fable 5 / Mythos 5 model launch, not Project Glasswing preview, not August 7 Fable biology safeguards, not August 14 Risk Report / Model 2, not August 20 Platform computer-use GA.

## Limits

- Mythos does **not** appear as a prompt box on other surfaces.
- CVP Mythos-class defensive access is “coming weeks,” not shipped.
- Whether 0xDAF recipients are named, and how this sits next to OpenAI **Daybreak** (Aug 10–11), is open.

## Sources

- [Anthropic: Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders (August 21, 2026)](https://claude.com/blog/bringing-claude-mythos-5-to-more-defenders)
- [Claude Security product](https://claude.com/product/claude-security)
- Times of AI: `openai-daybreak-gpt-5-6-cyber` (August 10); `anthropic-august-2026-risk-report` (August 14)
