Visa’s payment network spans more than 200 countries and territories, moves money across roughly 160 currencies, and links nearly 5 billion payment credentials to more than 175 million merchant locations. It also, as it turns out, had a lot of vulnerabilities waiting to be found.

That discovery came courtesy of Anthropic’s Claude Mythos Preview model, deployed inside a collaboration called Project Glasswing that kicked off around April 7, 2026. Within the first month, the AI model surfaced more than 10,000 high or critical vulnerabilities buried across Visa’s software stack.

What Claude Mythos actually did differently

Traditional vulnerability scanning tends to catch the obvious stuff. Claude Mythos did something harder: it stitched together minor, individually unremarkable weaknesses into complete exploit chains, connecting dots that a human tester might not have linked until late in an engagement, or might have missed entirely.

Rajat Taneja, Visa’s president of technology, presented the results at VB Transform 2026 and made a point that deserves attention. His team moved away from traditional remediation metrics and replaced them with a concept they invented internally: Mean Time to Adapt. Patching is reactive. Adapting implies a continuous posture against a threat environment that is itself moving.