PulseAugur
EN
LIVE 01:19:12

Anthropic's AI bug-finding claims questioned by VulnCheck analysis

A recent analysis by VulnCheck has raised questions about the accuracy and reconciliation of Anthropic's Project Glasswing bug disclosure ledger. The analysis found a significant discrepancy between Anthropic's claimed number of discovered vulnerabilities and those actually recorded in its public ledger, with only a small fraction marked as fixed. Furthermore, the ledger itself contains internal inconsistencies regarding the number of fixed vulnerabilities. The report also highlights a notable difference in severity ratings between Anthropic's AI and human maintainers, with the AI frequently flagging issues as critical or high severity, potentially leading to alert fatigue for maintainers. AI

IMPACT Highlights the need for verifiable data in AI's defensive capabilities, impacting policy arguments for frontier model development.

RANK_REASON Analysis of a company's public disclosure ledger regarding AI-found vulnerabilities. [lever_c_demoted from research: ic=1 ai=1.0]

Read on dev.to — Anthropic tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Anthropic's AI bug-finding claims questioned by VulnCheck analysis

How we ranked this

Signal score
15 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
Analysis of a company's public disclosure ledger regarding AI-found vulnerabilities. [lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

Full methodology in our editorial standards.

COVERAGE [1]

  1. dev.to — Anthropic tag TIER_1 English(EN) · Breach Protocol ·

    VulnCheck says Anthropic's Glasswing bug ledger shows 202 fixes from 26,153 claimed findings, and its numbers don't reconcile

    <p>Anthropic's public record of its AI-found software vulnerabilities shows only a small fraction of the findings the company claims, and its own figures disagree with each other, according to an analysis published on 8 September 2026 by Patrick Garrity of the vulnerability intel…