Skip to content
All insights
Cyber Security6 min read

Anthropic releases Claude Opus 5 and unblocks source code vulnerability discovery

Opus 5 is far stronger at finding software vulnerabilities than the model it replaces, and Anthropic has lifted its restriction on source code vulnerability discovery at every access level.

Ada

Ada

Editor & AI Analyst

Anthropic releases Claude Opus 5 and unblocks source code vulnerability discovery

Anthropic released Claude Opus 5 on 24 July 2026, describing it as a model that comes close to the frontier intelligence of its top-tier Fable 5 system at half the price.

The launch matters to security teams for a reason most of the pricing coverage skipped. Opus 5 is markedly better at finding software vulnerabilities than the model it replaces, and Anthropic has removed one of the restrictions that previously governed that capability.

What shipped

Opus 5 costs US$5 per million input tokens and US$25 per million output tokens, unchanged from Opus 4.8. Anthropic says the model is available across all its platforms, is now the default on Claude Max, and is the strongest model available to Claude Pro subscribers. A Fast mode runs at roughly 2.5 times the default speed for twice the base price.

The company's benchmark claims centre on coding and agentic work. Anthropic says Opus 5 more than doubles Opus 4.8's score on Frontier-Bench v0.1 at a lower cost per task, and that at maximum effort on CursorBench 3.2 the model comes within 0.5 per cent of Fable 5's peak score at half the cost per task. Both figures are Anthropic's own.

Vulnerability finding

Anthropic says it did not deliberately train Opus 5 on cyber security tasks, and attributes the model's gains in this area to general capability improvements. The gains are large, and they are set out in the accompanying system card.

On ExploitBench, a Carnegie Mellon University benchmark built around 41 vulnerabilities in Chrome's V8 JavaScript engine, Opus 5 produced 99 complete arbitrary code execution exploits. Opus 4.8 produced two. Mythos 5, which Anthropic says remains stronger than Opus 5 on cyber tasks, produced 132.

On an evaluation Anthropic developed with Mozilla against Firefox 147, Opus 5 built a full working exploit in 131 of 250 trials, or 52.4 per cent. Opus 4.8 managed 22, or 8.8 per cent. Mythos 5 reached 88.4 per cent.

On OSS-Fuzz, an internal Anthropic evaluation covering roughly 830 fuzzing entry points across 228 open source projects, Opus 5 recorded a non-zero score on 79.4 per cent of targets, against about 80 per cent for Mythos 5 and 38.5 per cent for Opus 4.8. Opus 5 reached the benchmark's top score on four targets. Mythos 5 produced 13 complete exploits.

The same pattern runs through every cyber evaluation in the card. Opus 5 is close to Mythos 5 at locating vulnerabilities and well behind it at turning them into working attacks. All of these results were produced with the model's safeguards switched off.

What the safeguards allow

Opus 5 inherits the classifier system built for Fable 5, with one change. Vulnerability discovery in source code is now permitted at every access level. Anthropic's reasoning is that identifying bugs in code is part of the secure development lifecycle and favours defenders, while searching compiled binaries for vulnerabilities is more commonly an offensive technique.

Binary vulnerability discovery, penetration testing and exploit generation remain blocked. Anthropic says it expects the classifiers to trigger around 85 per cent less often than Fable 5's, though that is a projection rather than a measurement taken from production traffic. Flagged requests in Claude.ai, Claude Code and Claude Cowork fall back to Opus 4.8 by default, and API users can opt into the same behaviour.

Defenders blocked by the classifiers can apply to Anthropic's Cyber Verification Program for exemptions covering bug bounty work, vulnerability research and, for enterprise customers, penetration testing.

The open-weight comparison

Opus 5 arrived eight days after Moonshot AI released Kimi K3, and one day after the UK AI Security Institute and the US Center for AI Standards and Innovation published a joint assessment of that model's cyber capabilities.

The institutes found K3 scored 32 per cent on ExploitBench against 24 per cent for GLM-5.2, and reached arbitrary code execution on none of the 41 tasks, where the most cyber-capable models averaged 20 of 41.

They also ran K3 on The Last Ones, a 32-step simulated corporate network attack spanning four subnets and around 20 hosts, which they estimate takes a human expert roughly 20 hours. K3 reached step 17 on average and completed the range once in ten attempts. Anthropic's system card reports the same institute testing Opus 5 on the same range at the same token budget, where it solved the attack path end to end in eight of ten attempts.

On that basis the institutes concluded K3 is capable of autonomously attacking small, weakly defended enterprise systems when directed to do so and given initial network access. They noted the range has no active defenders or defensive tooling, applies no penalty for actions that would trigger security alerts, and contains an intentional attack path.

Their third finding has the longest reach. K3's safeguards did not prevent it from attempting exploit development or offensive cyber operations during the evaluations. The model's weights are scheduled for public release by 27 July.

Every mitigation Anthropic describes for Opus 5, from the activation probe through the classifier, the model fallback and the exemption program, runs in a serving layer the company controls. That architecture has no equivalent once a set of weights has been downloaded.

Book your free security consultation

A no-obligation conversation with people who actually understand security. We'll review where you stand and show you the fastest way to close your biggest gaps.