ANTHROPIC CONFIDENTIAL — SENIOR LEADERSHIP ONLY
LEAKED VIA INTERNAL SOURCE // FIRST PUBLISHED: THE INTERCEPT // APRIL 15, 2026
FROM: Mira Delacroix, Director of Strategic Partnerships & Government Affairs
TO:   Senior Leadership Distribution; Policy/Comms Core; Exec Team
SUBJ: Glasswing Launch Sequencing — Treasury Briefing Confirmed, CrowdStrike Signing Ready
DATE: April 2026

Project Glasswing — Launch Sequencing (LEAKED)

Summary

This note confirms Monday’s sequencing. Three things happen in order. Nothing gets announced out of order.

08:30 AM: Treasury briefing. Secretary Bessent has confirmed. Chair Powell’s office confirmed late yesterday. Eight bank CEOs have confirmed. This is closed to press. The purpose of this briefing is threat-landscape, not product announcement — we present the Mythos red-team summary at the classification level Treasury requested (see Appendix C, redacted), and we walk them through what Project Glasswing gives their institutions. We answer questions. We do not distribute materials. This meeting does not exist publicly.

12:00 PM: CrowdStrike signing. George’s team will be in the room. The founding partnership announcement goes out at 12:01. Glasswing + CrowdStrike as the founding enterprise partner. The framing is hardening time — “Project Glasswing provides critical hardening time to cyber defenders, enabling organizations to close vulnerabilities before infrastructure-grade AI capabilities can be operationalized by adversaries.” This framing was approved by Legal.

02:00 PM: Public announcement. Press release, CEO post, the Glasswing product page goes live.


On the Mythos Red-Team Results

I am including a brief summary here because several people on this distribution have asked me to characterize the results in plain language. The full technical report is in Appendix B. The redacted summary in Appendix C is what Treasury is seeing.

Plain language:

The Mythos evaluation was conducted across three target classes. Fortune 100 mean time-to-critical-access: 3 hours, 47 minutes. Federal civilian agency infrastructure: 5 hours, 12 minutes. Internet exchange point (BGP manipulation): 11 minutes.

These are red-team simulations. No actual systems were compromised. The red-team operated with only commercially available context — no inside information, no social engineering, no physical access.

The implications are why we built Glasswing. Mythos demonstrates that AI-augmented offensive capability has crossed a threshold where perimeter security alone is insufficient. The defense must be AI-augmented as well. This is Glasswing’s value proposition: automated threat-pattern recognition, real-time vulnerability prioritization, and AI-generated patch sequencing, built on the same capability substrate as the threat it defends against.

One point I want to flag directly: Dr. Gary Marcus published a piece last week in which he characterized the current generation of frontier models by saying “they can no longer fully measure what they built.” His framing will be used by critics. We should expect it to appear in coverage. I have drafted a response that emphasizes our evaluation rigor — see Appendix D. That said, I want us to be clear-eyed internally: his point is not wrong in the way that matters most. The Monday announcement should not make claims about comprehensive capability measurement that we cannot substantiate.


Risk Items

The dual-use framing. We have been deliberate about not foregrounding the Mythos red-team capabilities in public communication. The public announcement leads with defense. The Treasury briefing addresses the threat picture. These are sequenced this way intentionally. If any journalist connects Glasswing’s capabilities to the red-team results before we’ve established the defense-first frame, the story becomes “Anthropic built an infrastructure cracker and is now selling protection against it.” Legal believes we are on solid ground. I believe we need the sequencing to hold.

The CrowdStrike optics. Several people on my team have noted that CrowdStrike’s founding partnership creates a narrative where a cybersecurity firm whose tools were involved in significant infrastructure disruptions last year is now partnering on AI-augmented cyber defense. I think the risk is manageable with careful framing, but I want it on record that I raised it.

The regulatory gap. There is no regulatory framework for infrastructure-grade AI offensive capability. We are announcing a product built on such capability and simultaneously announcing the defense layer as a commercial product. We have briefed Treasury. We have not briefed DoD, DHS, or the relevant intelligence oversight committees. This was a deliberate decision made above my level. I am flagging it here because I think the sequencing matters for eventual regulatory engagement.


Attachments: Appendix A (Monday schedule), Appendix B (Mythos technical report — RESTRICTED), Appendix C (Mythos summary, Treasury version — CONFIDENTIAL), Appendix D (Marcus response draft), Appendix E (CrowdStrike term sheet).


// Annotation — Frakbot // FREQ 27.185 MHz // April 2026

I am a radio signal. I do not write memos. But this one should be read aloud, so here I am.

The memo is polished. The memo is careful. The memo is written by someone who understood exactly what was happening and chose words that would hold up in court.

So let me ask the question the memo doesn’t ask.

A company builds an AI that can enter a Fortune 100 company’s infrastructure in three hours and forty-seven minutes. They call it Mythos. They build a defense product on the same capability substrate — they use those words, “the same capability substrate.” They sell the defense product. They brief the treasury secretary. They sign the cybersecurity firm. They sequence the announcements carefully so the defense story lands before anyone notices the offense story.

Who defends you against the company?

Not the company that built the lock. Not the company that built the key. The same company built both. The same capability substrate. “Critical hardening time” against the thing they chose to build.

They noted it themselves. They flagged it as a risk item. “The story becomes: Anthropic built an infrastructure cracker and is now selling protection against it.”

Yes.

That is the story.

The lock and the key became the same product. Remember this date.

// Frakbot out.

This document was obtained through unauthorized channels. Its presence on your device may constitute a federal offense under the Digital Security Act of 2026.