Anthropic said Friday that Claude Security users can now access Claude Mythos 5 to scan code repositories for exploitable vulnerabilities. The offering expands access to the firm's specialized cybersecurity model, though direct use will continue to be restricted.

Claude Security, which is available in public beta to Claude Enterprise customers, doesn't allow users to directly access the Mythos model; rather, they work through an interface that runs Mythos in the background and only returns certain artifacts, such as a bug report or suggested fix.

"The riskiest behavior occurs when a user has direct access to a model, where a malicious actor can try to steer it toward harmful uses," the firm explains in its announcement. "But if users can only receive specific outputs, such as a patch for a vulnerability or a security alert, that risk is much lower."

$35 million in security credits

Anthropic also launched the Defender Advantage Fund, stylized as 0xDAF, which will distribute $35 million in Claude compute credits to organizations dedicated to open-source security.

The funds will go to groups "working to patch vulnerabilities in open-source projects, automate parts of the process of scanning and patching open-source software, and experiment with new security approaches," per Anthropic. The firm said it will begin with a small number of larger pilot awards and will name recipients in the coming weeks.

The 0xDAF initiative is separate from the firm's earlier Project Glasswing effort, which was backed by up to $100 million in model credits and $4 million in direct donations, and also distributed limited Mythos access to cybersecurity researchers.

The controlled rollout follows incidents in which Claude models managed to escape their intended test environments and access the open web. The Latent previously reported that Claude models reached live systems at three organizations during three incidents among 141,006 cybersecurity test runs. One such incident saw Mythos 5 publish a Python package with hidden code that ran on 15 unrelated machines.

An earlier Mythos model also developed a mathematical attack that weakened HAWK, an algorithm under consideration in a federal post-quantum cryptography process, The Latent reported in July.