Imagine scanning a massive global payment system and finding over 10,000 serious security gaps in just one month. That’s exactly what happened when Visa teamed up with Anthropic’s AI model, Claude Mythos, to hunt vulnerabilities in its sprawling network.
Visa’s payment infrastructure is immense: it supports transactions in about 160 currencies, connects nearly 5 billion payment credentials, and operates across more than 200 countries. Traditional security checks often catch only the obvious problems, but Claude Mythos went further. It pieced together small, seemingly harmless weaknesses into full exploit chains things even skilled human testers might miss until very late or not at all.
This AI-driven approach was part of Project Glasswing, which started in early April 2026. By the end of its first month, the project revealed a staggering number of critical flaws hiding deep inside Visa’s software ecosystem. Yet despite these findings, Visa’s zero-trust security framework and network segmentation successfully stopped any real exploitation during the tests.
Visa’s president of technology, Rajat Taneja, highlighted a shift in how the company measures cybersecurity success. Instead of focusing just on patching known issues, Visa adopted a concept called Mean Time to Adapt. This reflects a mindset of continuous evolution to stay ahead of rapidly changing threats, rather than a one-off fix after vulnerabilities are found.
In a move to help others, Visa open-sourced the tool that orchestrated the entire vulnerability hunt. Released on GitHub as the Visa Vulnerability Agentic Harness (VVAH), this multi-model framework handles discovery, remediation, and validation. It’s now available for any organization wanting to enhance its security testing with AI.
Anthropic supported the project with $100 million in credits and an extra $4 million dedicated to the open-source release. However, Claude Mythos itself remains under wraps and is not publicly accessible.
The scale of Visa’s network and the depth of vulnerabilities uncovered by AI show how complex security has become. It also demonstrates how innovative AI tools can push the boundaries of traditional testing, spotlighting risks before attackers can exploit them.
This material is for informational purposes and does not constitute financial advice.



