Ground Truth.
AI, checked against the source.

News · 2026-09-13

VulnCheck says Anthropic's Glasswing bug ledger shows 202 fixes from 26,153 claimed findings, and its numbers don't reconcile

Anthropic's public record of its AI-found software vulnerabilities shows only a small fraction of the findings the company claims, and its own figures disagree with each other, according to an analysis published on 8 September 2026 by Patrick Garrity of the vulnerability intelligence firm VulnCheck. Of 26,153 findings Anthropic claims for Project Glasswing, 2,736 appear in its disclosure ledger and 202 are marked fixed.

Key facts

The promise being audited

Anthropic launched Project Glasswing in April 2026 to point its most capable, restricted Claude models at real software and find security holes before attackers do. It has been one of the company's main arguments that frontier AI can strengthen defence, and in August Anthropic said partners had used its restricted model to find more than ten thousand high- or critical-severity vulnerabilities.

Big numbers in vulnerability research need receipts, because a “finding” is only valuable once a maintainer confirms it, fixes it and users can patch. Anthropic published a vulnerability disclosure ledger on 22 May to provide that record. Garrity, who has tracked the program since launch, went through it after the latest update.

What the ledger shows

The gap between claims and records is large. Beyond the 202 fixed findings, Garrity counts 245 withdrawn and 2 duplicates, meaning the ledger holds more withdrawn findings than fixed ones. About 2,096 are marked as reported to maintainers but not confirmed fixed, and 191 appear in the ledger without having been reported.

The 202 fixes span 113 projects, under two per project. And the documents disagree internally: Anthropic's dashboard, Garrity writes, “states 421 findings patched upstream,” while the ledger itself shows 202 fixed, and its separate ledgers of CVE identifiers do not match either, one listing 70 and the main ledger 82.

His summary: “The receipts are starting to trickle in, they just don't reconcile.”

The severity problem

The second finding may matter more to open-source maintainers. Where both parties rated a bug, “Claude determined a critical or high severity for 91.5% of findings, while the maintainer determined only 51.3% as critical or high.”

Picture a smoke alarm that goes off at full volume for burnt toast as often as for a real fire. It may never miss a fire, but a household that hears it constantly stops treating every alarm as urgent. Maintainers of volunteer-run projects already struggle with floods of automated reports, and an AI that labels nearly everything urgent adds to the load even when its findings are real. The problem echoes our lesson on calibration, whether a system's confidence means anything.

Garrity also questions Anthropic's stated true-positive rate of 91.4%, noting the ledger contains more withdrawn or duplicate entries than fixed vulnerabilities. Separately, Ground Truth has reported on AI tools finding real bugs frontier scanners missed, such as six curl vulnerabilities found by AISLE, so the question is not whether AI finds bugs but how accurately programs report the results.

Why it matters

AI-driven vulnerability discovery is becoming a central claim in the policy fight over frontier models: labs cite defensive wins to justify building more capable systems. Public, checkable ledgers are the right idea. VulnCheck's analysis shows that the numbers in them need to add up before they can carry that weight.

The caveat

Disclosure is slow by design. Maintainers take weeks or months to confirm and patch, embargoes delay publication, and a five-month-old program would naturally show a long tail of unresolved reports. The severity comparison covers only findings where both sides gave a rating, and VulnCheck, which sells vulnerability data, has a professional interest in scrutinising other disclosure sources. VulnCheck's post does not include a response from Anthropic.


Primary source, verified: read the paper →

Key questions

What is Anthropic's Project Glasswing?

It is Anthropic's program, launched in April 2026, that uses its most capable restricted Claude models with partners to find security vulnerabilities in software, publishing a vulnerability disclosure ledger of its findings.

Does VulnCheck's analysis mean Glasswing's findings are fake?

No. VulnCheck shows that only a small share of claimed findings have visibly reached the public ledger or been fixed, and that Anthropic's own figures disagree with each other, but disclosure and patching take months and many reports may still be in progress.

Why does the severity gap between Claude and maintainers matter?

Because maintainers have limited time. If an AI tool labels most of its findings critical or high while maintainers agree only about half the time, it inflates the urgent queue and makes triage harder for the people who have to fix the bugs.
Cite this

APA

Ground Truth. (2026, September 13). VulnCheck says Anthropic's Glasswing bug ledger shows 202 fixes from 26,153 claimed findings, and its numbers don't reconcile. Ground Truth. https://groundtruth.day/news/vulncheck-says-anthropics-glasswing-ledger-shows-202-fixes-from-26153-findings.html

BibTeX

@misc{groundtruth:vulncheck-says-anthropics-glasswing-ledger-shows-202-fixes-from-26153-findings,
  title  = {VulnCheck says Anthropic's Glasswing bug ledger shows 202 fixes from 26,153 claimed findings, and its numbers don't reconcile},
  author = {{Ground Truth}},
  year   = {2026},
  month  = {sep},
  url    = {https://groundtruth.day/news/vulncheck-says-anthropics-glasswing-ledger-shows-202-fixes-from-26153-findings.html}
}

Topics: cybersecurity · vulnerabilities · ai-security · anthropic · vulnerability-disclosure · open-source

Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.