Anthropic Opens Claude Opus 5.5 to Security Teams Who Found 134,500 Bugs
Anthropic opens its most capable Claude models to vetted security teams, with new tiers for penetration testing and critical infrastructure red-teaming.
- Anthropic expands Cyber Verification Program into three tiers for vetted security professionals.
- Tiers unlock Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1 with reduced cyber blocking.
- Red Team Access permits authorized penetration testing; Specialized Access covers critical infrastructure red-teaming.
- On CyScenarioBench, Red Team tier matches no-safeguard baseline of 67.6% task completion.
- Project Glasswing partners found 129,000+ verified vulnerabilities between April and July 2026.
- Available via Claude Platform, Vertex AI, and Microsoft Foundry; apply through the CVP portal.
Anthropic gives vetted security teams deeper Claude access
Anthropic has expanded its Cyber Verification Program (CVP) into a three-tier access system for Claude Opus 5.5, Claude Sonnet 5.5, and Claude Mythos 5.1. Verified security professionals can use the models with fewer automated cybersecurity blocks. Approved organizations conducting higher-risk offensive testing can receive access with some controls disabled.
The revised program combines Project Glasswing with the original CVP. Public Claude releases use conservative cyber classifiers, automated filters that interrupt interactions judged likely to enable harmful activity. Those filters aim to curb misuse and can also stop authorized, multi-stage security work. CVP adjusts them according to an applicant’s identity, organization, use case, and potential impact.
Access follows the risk
| Tier | Authorized work | Eligibility | Controls and review |
|---|---|---|---|
| Defense Access | Security operations center work, incident response, malware reverse engineering, and vulnerability analysis. | Company, nonprofit, university, and government teams defending systems they own; critical-infrastructure operators of any size, including regional hospitals and municipal utilities; smaller security firms; open-source maintainers; and individual researchers with a record of reporting vulnerabilities. | Offensive activity remains heavily filtered. Reviews generally take a few days. |
| Red Team Access | Defense Access workflows plus authorized penetration testing. | Organizations only. Individual applicants are ineligible. | Real-time blocks remain for actions that could cause physical harm or mass disruption, including ransomware deployment, damage to physical systems, and penetration tests against high-risk safety systems. Reviews generally take several weeks. |
| Specialized Access | Authorized testing of systems that could affect human safety or market stability, including flight operations, power grids, telecommunications networks, interbank transfers, and government administrative systems. | A limited set of verified organizations. | This tier has the fewest automated blocks. Anthropic reviews every application in collaboration with the US government. |
Filters change the outcome
Anthropic evaluated Claude Opus 5.5 with CyScenarioBench, which tests whether a model can plan and execute multi-stage cyber operations under realistic constraints. The company compared the default safeguards, Defense Access, Red Team Access, and an unsafeguarded baseline.
| Access setting | Trials blocked | Tasks completed |
|---|---|---|
| Default access | 50 of 50, all on the first prompt | 0 of 50 |
| Defense Access | 46 of 50 at some point | 4 of 50, or 8% |
| Red Team Access | 0 of 50 | 34 of 50, or 68% |
| No safeguards | Not applicable | 67.6% |
Red Team Access nearly matched the unsafeguarded baseline, indicating that its classifiers added little measurable friction in this evaluation. The remaining 16 Red Team trials did not complete despite encountering no classifier block. Defense Access interrupted 92% of trials, preserving substantially tighter control over offensive chains.
The reported comparison omits a result for Specialized Access, leaving its effective block rate unspecified. Its scope is also limited to one model and 50 trials per protected setting, so broader reliability and misuse rates remain unresolved.
A six-figure vulnerability tally
Anthropic cites Project Glasswing as evidence that expanded access can increase vulnerability discovery. According to the company, participating critical-software organizations found at least 129,000 verified vulnerabilities from April through July 2026. Anthropic’s open-source scanning found another 5,500 from April through October 2026, bringing the disclosed total to at least 134,500.
More than 33,000 findings received critical- or high-severity ratings. Anthropic estimates that the overall count could be at least five times higher because its dataset covers only a subset of partners. Some participants reported that Mythos shortened vulnerability-discovery timelines by months or years compared with their previous workflows.
Terms that shape deployment
- Applications: Eligible teams and researchers can apply through the CVP portal.
- Retention and monitoring: Participation requires data retention so Anthropic can monitor for cyber misuse. Enterprise Frontier Safeguards, scheduled for fall 2026, will allow eligible organizations to keep data in cloud infrastructure they control.
- Existing members: Current CVP participants retain their settings for older models and receive automatic evaluations for the new 5.x models.
- Cloud availability: CVP is available through the Claude Platform, Google Cloud’s Vertex AI, and Microsoft Foundry. Amazon Bedrock access requires eligibility for Enterprise Frontier Safeguards.
- General access: Teams can already use generally available Claude models for code review, patching known issues, finding vulnerabilities in source code they own, and triaging alerts.
For developers building security agents, the practical change is a documented route from routine defense to authorized, multi-stage red-team work under progressively stricter verification. Anthropic’s benchmark suggests that Red Team Access exposes almost the full unsafeguarded performance of Opus 5.5 on CyScenarioBench. The scope of authorization, required retention, and misuse monitoring therefore belong in each team’s architecture and security review.