« All posts

Visa Turns Claude Mythos on Its Payment Network, Then Open-Sources the Harness

Visa used Anthropic's Claude Mythos to stress-test its payment network, then open-sourced the harness and its new Mean Time to Adapt metric.

Visa aimed Anthropic's Claude Mythos at the infrastructure behind its global payment network — spanning more than 200 countries, nearly 5 billion credentials, and 175 million merchant locations — as part of Anthropic's Project Glasswing initiative. Presenting at VB Transform 2026, Visa's President of Technology Rajat Taneja described how the model chained minor weaknesses into working exploit paths that typically surface only late in penetration testing, while zero-trust controls and network segmentation broke those chains before any real exposure materialized.

Rather than treat the exercise as a one-off scan, Visa built the Visa Vulnerability Agentic Harness, now in its fifth generation, as a governed pipeline spanning four phases and eleven stages, from threat modeling through exploit-chain synthesis to fix validation. The harness requires deterministic multi-agent voting before a finding advances and is designed to be model-agnostic, though full remediation currently depends on Anthropic's file-editing tools. Visa published the harness on GitHub along with a white paper outlining 12 non-negotiable practices for critical infrastructure.

The company also introduced Mean Time to Adapt, a new metric tracking inventory freshness, exploitable attack paths remaining after each release, and validation cycle time — replacing legacy measures like raw CVE closure counts that can mask growing exposure. Visa is now extending these AI-specific security expectations, including continuous vulnerability validation and living software bills of materials, across its supplier ecosystem.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work