# Anthropic launches $35M fund for open-source cyber defense

> Source: <https://cryptobriefing.com/anthropic-35m-open-source-cyber-defense/>
> Published: 2026-08-21 17:42:18+00:00

Via time.com

# Anthropic launches $35M fund for open-source cyber defense

The AI company is assembling a coalition of tech giants to hunt vulnerabilities in critical open-source software before attackers do.

Anthropic is putting serious money behind the idea that AI should be used to defend software, not just write it. The company has unveiled Project Glasswing, a collaborative cybersecurity initiative backed by a fund targeting open-source security projects, alongside pledges of up to $100 million in model usage credits and $4 million in direct donations to open-source security organizations.

The initiative brings together a consortium that reads like a tech industry all-star roster: AWS, Apple, Google, and Microsoft are all participating. At the center of the effort sits Anthropic’s unreleased Claude Mythos Preview model, which has already been put to work scanning codebases for vulnerabilities.

## What Project Glasswing actually does

Claude Mythos Preview has already identified over 10,000 high and critical vulnerabilities, including longstanding flaws buried in established software products.

The financial commitments break down across several channels. Anthropic is providing up to $100 million in model usage credits so that security researchers and organizations can run their own vulnerability scans using Claude Mythos Preview. On the direct funding side, the company has allocated $2.5 million to Alpha-Omega and the Open Source Security Foundation (OpenSSF), plus $1.5 million to the Apache Software Foundation.

Anthropic also participates in the Linux Foundation’s grant program to the tune of $12.5 million, and previously committed $1.5 million in a partnership with the Python Software Foundation focused on security improvements.

## Why this matters now

Since its launch, the initiative has expanded to include approximately 150 additional organizations.

Open-source software is uniquely vulnerable to this dynamic. Most critical open-source projects are maintained by small teams, sometimes just one or two developers, despite being used by Fortune 500 companies and governments worldwide. The Log4j vulnerability in late 2021 demonstrated what happens when a widely used open-source component contains a critical flaw. That single bug triggered a global scramble affecting hundreds of thousands of organizations.

## The broader landscape

Rather than building a proprietary security product and selling it, Anthropic is taking an ecosystem approach, funding existing organizations, providing free compute credits, and bringing competitors into the same room.

For the 150-plus organizations that have joined since launch, the practical benefit is access to a vulnerability scanning model they couldn’t build themselves. Most open-source foundations operate on shoestring budgets. Free access to a frontier AI model purpose-built for security analysis is the kind of resource that actually changes outcomes.

**Disclosure:** This article was edited by Editorial Team. For more information on how we create and review content, see our

[Editorial Policy](https://cryptobriefing.com/editorial-policy/).
