AI

NYSE Confirms Use of Anthropic's Project Glasswing to Detect and Fix Cyber Flaws

NYSE President Lynn Martin told Congress the exchange used Anthropic's Project Glasswing to quickly fix multiple cyber vulnerabilities, Bloomberg reported.

By Tim Editorial

NYSE Confirms Use of Anthropic's Project Glasswing to Detect and Fix Cyber Flaws
anthropic.com

The New York Stock Exchange has acknowledged in a congressional setting that it uses Anthropic's Project Glasswing to identify and correct cyber vulnerabilities in its systems. Bloomberg Technology reported the disclosure on the basis of testimony from NYSE President Lynn Martin, who said the exchange employed the project to find and quickly repair what the article described as "a variety of cyber vulnerabilities." The phrase indicates that more than one flaw was found and that the flaws were of different kinds. Bloomberg did not specify the nature of the weaknesses, the systems affected, or how long repairs took. The available information only establishes that vulnerabilities were discovered and handled quickly. The news report rests on two documented facts. First, Bloomberg covered Martin's remarks before Congress.

Second, Anthropic publicly describes Project Glasswing on its official website, meaning the project is not an invention of a single exchange executive. However, the assertion that Glasswing successfully helped NYSE find and repair flaws is Martin's statement as carried by Bloomberg. It is not a formal written statement from Anthropic. Bloomberg's article did not include written responses from NYSE or Anthropic regarding the testimony. On its project page, Anthropic characterizes Glasswing as a coalition powered by "Claude Mythos Preview" to discover and fix vulnerabilities in software that the world depends on. The use of the term coalition in that official description indicates that the initiative involves more than one organization and relies on AI models from the Claude family.

The page does not explain the technical detection methodology, the names of coalition members, or how software is prioritized. What can be confirmed from the documentation is that Glasswing is focused on securing widely used, critical software. NYSE's adoption of Glasswing broadens the picture of the project's reach. While Anthropic's general description emphasizes software relied on globally, the NYSE case suggests the initiative is also being used to protect the internal systems of a financial market institution. The New York Stock Exchange is the primary U.S. stock exchange, providing a marketplace where buyers and sellers trade shares. A security breach in the exchange's systems could theoretically disrupt trading activity, yet Bloomberg's report contains no mention of operational disruption.

Neither does it connect the use of Glasswing to any specific hacking incident or to a change in exchange security procedures. Nothing in the reporting indicates that the identified vulnerabilities were exploited by outside parties before they were fixed. Martin delivered the information in a congressional forum rather than in a corporate press release. Her position as president of NYSE makes the statement directly representative of the exchange operator. Bloomberg did not identify which congressional committee invited her, the hearing's agenda, or the surrounding discussion. Despite that lack of detail, a disclosure made before legislators places the cooperation between NYSE and Anthropic into the public record, where it can be examined.

It also opens the possibility of follow up questions from lawmakers seeking technical details and security policies. From an artificial intelligence perspective, the NYSE example illustrates how AI models are being deployed for tasks requiring high precision. Searching for flaws in systems that handle stock trading demands accuracy, because a false positive can waste time and a missed vulnerability can provide an entry point for attackers. Anthropic's description says Glasswing is supported by Claude Mythos Preview and operates as a coalition, but it does not say how the model was trained or how its outputs were reviewed by humans. Bloomberg also does not describe the verification process that Glasswing findings underwent in the NYSE environment before any fixes were applied.

Martin's testimony leaves several other questions unanswered. It is not clear whether NYSE joined the Glasswing coalition as a participant like others, or whether it uses a custom configuration tailored to exchange systems. There is no explanation of how NYSE's data was handled when processed by the AI tool, whether a commercial relationship exists with Anthropic, or what role security specialists played in validating each finding. Anthropic's Project Glasswing page does not include an NYSE case study. Bloomberg quotes Martin without adding details about contractual mechanisms or the scope of work. It is therefore important to distinguish between layers of information in this news. Bloomberg reports that NYSE has admitted to using Glasswing, and that admission came from Martin before Congress.

The further statement that Glasswing succeeded in accelerating the discovery and repair of a variety of vulnerabilities is an assessment made by Martin, not one that independent parties have verified. By contrast, the existence of Project Glasswing and its description as a software security project can be checked directly through Anthropic's official documentation. No source in the report ties the matter to stock price movements, Anthropic's revenue, or any specific securities market policy. As of this writing, NYSE has not issued further announcements about the exact number of flaws, the systems repaired, or the timing of the next security audit. Additional information might emerge if Martin is questioned again by lawmakers or if Anthropic and NYSE release formal statements.

What is currently on the record is Martin's acknowledgment that the exchange uses Glasswing and her claim that various vulnerabilities were found and fixed quickly. This event also signals that market infrastructure institutions are beginning to open up to using artificial intelligence for cyber defense, although the technical specifics remain pending explanation.

Sources and references