Anthropic has expanded its Cyber Verification Program, giving approved security professionals access to advanced Claude capabilities with fewer automated blocks on defensive work such as malware analysis, incident investigation and vulnerability testing. The restructuring, announced October 7, merges the existing CVP with Project Glasswing into a single program with three verification tiers.
The move is a deliberate bet on capability gating: rather than restricting cyber operations uniformly, Anthropic is trading verified identity and monitored usage for fewer refusals on legitimate defensive work — while keeping hard blocks on the operations most likely to cause physical harm.
Three tiers, three risk envelopes
Defense Access covers incident investigation, malware analysis, and vulnerability analysis and validation, and is open to security teams at businesses, nonprofits, universities and government organizations, as well as critical-infrastructure operators, smaller security firms, open-source maintainers and individual researchers with a record of reporting vulnerabilities. Anthropic says most organizations doing defensive work should qualify, with responses to applications expected within days.
Red Team Access adds authorized penetration testing and simulated attacks, intended for internal and government red teams and security testing firms. Actions that could cause physical harm or widespread disruption — deploying ransomware, testing high-risk safety systems — remain subject to real-time blocks, individual researchers are currently ineligible, and reviews may take weeks.
Specialized Access carries the fewest cybersecurity blocks and is reserved for a limited group of organizations authorized to test high-risk systems: flight operating systems, power grids, telecom networks, interbank transfer infrastructure and government administrative networks. Anthropic reviews each applicant in collaboration with the U.S. government, and existing Project Glasswing members move over without re-approval.
The program requires data retention so Anthropic can monitor for misuse, with an Enterprise Frontier Safeguards option expected later this fall allowing eligible companies to store data in infrastructure they control. In benchmarks Anthropic published alongside the announcement, Claude Opus 5.5 on the CyScenarioBench multistage-operations test was blocked on all 50 trials without CVP access, completed 4 of 50 under Defense Access safeguards, and completed 34 of 50 with no blocks under Red Team Access.
What the scanning has found
The disclosure also updated the vulnerability numbers. Project Glasswing partners used Claude Mythos models to uncover at least 129,000 verified software vulnerabilities in their own systems between April and July 2026, and Anthropic's own open-source scanning identified another 5,500 vulnerabilities between April and October. More than 33,000 of the findings were rated critical or high severity, and the company says the figures likely undercount the total because they draw on only a subset of Glasswing partners. An independent analysis of Anthropic's Frontier Red Team disclosure dashboard, published on dev.to, counted 6,157 vulnerabilities disclosed across 591 open-source projects as of October 2 — of which 5,103 were acknowledged by maintainers but only 516 are known to have been patched upstream.
That remediation gap is the more instructive number. Machine-driven discovery at this scale has outpaced the human capacity to triage, patch and acknowledge findings — precisely the bottleneck that verification tiers and monitored access are meant to manage on the tooling side. A finding is not a fix; an acknowledged finding is not a patched one. Coverage of the expansion by Help Net Security makes the same point from the opposite direction: the same model generations that can plan multistage attacks are the ones defenders now get to use with fewer interruptions.
For the crypto ecosystem, where a single unpatched dependency or contract flaw moves real funds, the trend line is clear — AI-assisted scanning is becoming operational infrastructure for defenders and attackers simultaneously. The differentiator is no longer access to a capable model; it is the verification, monitoring and disclosure discipline wrapped around it.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.