
Research by VulnCheck shows that fewer than 2 percent of AI-assisted vulnerability discoveries have been weaponized, contradicting widespread concerns that frontier AI models are dramatically tilting the balance in attackers' favor. While AI is helping security researchers uncover more flaws at scale, the actual exploitation rate mirrors that of traditionally discovered vulnerabilities, suggesting the threat has been overhyped relative to current evidence.
Summaries like this, in your inbox every morning.
Sign up free →What happened
VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, cross-referencing them against its Known Exploited Vulnerability database. Just 14 vulnerabilities, or 1.3 percent, have been confirmed as exploited in the wild—almost identical to the rate across all vulnerabilities in VulnCheck's dataset.
Why it matters
The findings contradict claims that frontier AI models are handing attackers a major advantage by producing instantly weaponizable bugs. Instead, the data suggests AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion that attackers actually exploit. Security researcher Patrick Garrity notes that AI-assisted vulnerability discovery has real value for defenders, giving them an opportunity to patch flaws before attackers can weaponize them.
What to watch
Anthropic's Project Glasswing identified 23,019 vulnerability candidates when unveiled in April, yet only 126 have been published as CVEs and just one has been confirmed exploited in the wild. VulnCheck also identified 495 known exploited vulnerabilities during the first half of 2026, with content management systems accounting for roughly one-third of them and AI products themselves becoming an increasingly attractive target for attackers.
Anthropic's Project Glasswing, unveiled in April with substantial media attention and security warnings, claimed to have uncovered tens of thousands of potential security flaws using AI-assisted vulnerability discovery. The project's stated premise was alarming: frontier AI models could identify vulnerabilities that attackers could rapidly weaponize, potentially allowing them to hijack systems, disrupt operations, or steal data. However, new research by VulnCheck paints a far more modest picture of the threat in practice.
VulnCheck's analysis examined 1,061 publicly attributed AI-assisted vulnerability discoveries from both Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, cross-referencing them against VulnCheck's Known Exploited Vulnerability (KEV) database. The findings were striking: just 14 vulnerabilities, or 1.3 percent, have been confirmed as exploited in the wild. This rate is almost identical to the baseline exploitation rate across all vulnerabilities tracked in VulnCheck's broader dataset, undermining the core claim that AI-discovered bugs are inherently more dangerous.
Project Glasswing itself serves as the flagship example of this gap between projection and outcome. Claude Mythos identified 23,019 vulnerability candidates—a staggering number that fueled concerns about AI-accelerated exploitation. Yet only 126 of those have been published as CVEs (the official vulnerability registry), and just one has been confirmed as exploited in the wild. Anthropic's public disclosure record has seen little movement since the project's April launch, raising questions about the real-world impact of the hundreds of thousands of candidate flaws that remain unpublished.
Security researcher Patrick Garrity, in findings shared with The Register, offered a more nuanced interpretation. Rather than dismissing AI-assisted discovery as a failure, he argued it provides genuine value for both defenders and attackers—but primarily as a force multiplier for finding more vulnerabilities, not for making individual flaws more exploitable. "AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there," Garrity wrote. He stopped short of declaring the threat entirely overblown but was direct about the disconnect: "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today... the impact has been real but modest."
Meanwhile, attackers remain active across the threat landscape. VulnCheck identified 495 known exploited vulnerabilities during the first half of 2026, with content management systems accounting for roughly one-third and network edge devices remaining a persistent target. Notably, AI products themselves are increasingly under attack as criminals look beyond using AI and begin hunting for weaknesses in the rapidly expanding AI software stack. The net result is that while AI has changed how security researchers discover flaws, it has not yet produced the weaponization surge that early warnings predicted.
The narrative around AI-assisted vulnerability discovery has centered on fears that frontier models would hand attackers a decisive edge—the ability to rapidly find and exploit zero-day flaws at scale. Anthropic's Project Glasswing, announced in April with warnings that AI could allow attackers to "hijack systems, disrupt operations, or steal data," epitomized this concern. Yet VulnCheck's analysis of real-world outcomes reveals a significant gap between the rhetoric and the evidence. While Anthropic's model identified tens of thousands of vulnerability candidates, the public disclosure record has stalled, with only 126 reaching CVE status and a single confirmed exploitation.
The reason appears straightforward: volume does not equal potency. AI is democratizing the ability to discover security flaws—a genuinely useful capability for defenders—but it is not making those flaws inherently more exploitable. The 1.3 percent exploitation rate for AI-discovered vulnerabilities matches the baseline rate across all vulnerabilities, suggesting that the bottleneck for attackers is not finding bugs but weaponizing them. Garrity's assessment that AI-assisted discovery "has been overhyped relative to the evidence available today" reflects this reality, while leaving room for future risk as AI capabilities mature. For now, the most immediate impact appears to be shifting the arms race in defenders' favor by compressing the time window between discovery and patching.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion



Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime