JPMorgan Chase CEO Jamie Dimon has warned that broad access to Anthropic’s Claude Mythos cybersecurity model would be like “giving ballistic missiles to individuals,” sharpening the debate over whether exceptionally capable AI security tools can remain restricted to vetted defenders.
Speaking at the Pennsylvania Defense and Innovation Summit, Dimon called Mythos-related risk a “real issue,” according to TechRadar and Spanish financial daily Cinco Días. The concern is not that the model is a magical hacking button; it is that a system able to locate flaws, reason through exploit chains, and produce working attack paths could reduce the time, skill, and cost required to compromise vulnerable software.

Cybersecurity analysts monitor an AI network as a red warning signals missile threats and industrial infrastructure.A defensive tool with offensive potential​

Anthropic introduced Claude Mythos Preview and its Project Glasswing program on April 7. The company said the unreleased model had found thousands of high-severity vulnerabilities, including flaws affecting major operating systems and browsers, and that it could outperform all but the most skilled humans at finding and exploiting software vulnerabilities.
Project Glasswing initially gave access to 12 founding partners, including Microsoft, JPMorganChase, Google, Apple, Cisco, CrowdStrike, NVIDIA, Palo Alto Networks and the Linux Foundation, plus more than 40 organizations that maintain critical infrastructure or software. Anthropic committed up to $100 million in model-use credits for defensive work.
The program has since expanded. Anthropic said in June that approximately 150 additional organizations would be admitted after meeting its security requirements, with a focus on critical-infrastructure operators and maintainers of widely used codebases. The company says the growing bottleneck is no longer discovering vulnerabilities, but validating, disclosing and patching the volume of findings.

Why financial firms care​

Banks, payment providers and crypto exchanges have obvious exposure: sprawling web-facing systems, high-value credentials, third-party dependencies and a direct path from compromise to fraud or theft. Dimon’s remarks reflect a broader concern that automated vulnerability research may compress the window between a bug’s discovery and real-world exploitation.
JPMorgan is using Mythos through Glasswing for defensive testing, while its CISO, Pat Opet, has described the project as an opportunity to evaluate next-generation security tooling alongside other major organizations. Anthropic’s current cybersecurity material says the limited-access program now includes Claude Mythos 5, while Claude Fable 5 is presented as a safeguarded version for wider use.
Crypto Briefing’s suggestion that the access debate could itself drive token-market consequences is more speculative. There is no evidence that a particular token, exchange breach, or Windows vulnerability is linked to Mythos.

The Windows angle​

For Windows admins, the story is less about gaining access to Anthropic’s restricted model and more about the changed operating assumption: attackers may soon be able to triage public code, exposed services and known flaws faster than many organizations can patch them.
That makes basic hygiene less optional, not less relevant: keep Windows and third-party applications current, remove unnecessary internet exposure, enforce phishing-resistant MFA for privileged accounts, segment admin access, and treat vulnerability remediation as an operational queue with owners and deadlines.
Microsoft is a Project Glasswing founding partner, but neither Microsoft nor Anthropic has announced a Mythos-specific Windows update for ordinary customers.

References​

  1. Primary source: Crypto Briefing
    Published: 2026-07-19T23:25:32+00:00
  2. Related coverage: techradar.com
  3. Official source: anthropic.com
  4. Related coverage: techcrunch.com
  5. Related coverage: ibm.com
  6. Related coverage: theweek.com