Editorial illustration for Visa Open-Sources Mythos Tool After Testing AI on Its Own Payment Network
Visa Open-Sources Mythos AI Tool After Network Testing
Visa turned an AI model loose on the network that clears its transactions, and the results changed how the company thinks about testing its own infrastructure. Anthropic's Claude Mythos went after the systems underpinning nearly 5 billion payment credentials across more than 200 countries and territories, linking to over 175 million merchant locations and moving money in roughly 160 currencies. Rather than flagging isolated flaws, the model chained together minor weaknesses buried deep in the stack into exploit paths that would normally take a human pentesting team much longer to uncover.
Rajat Taneja, Visa's president of technology since 2019 and a former CTO at Electronic Arts, laid out what happened next at VB Transform 2026. Visa didn't just use the findings internally. On June 10, Taneja and Visa CISO Subra Kumaraswamy published a blog post announcing the release of the Visa Vulnerability Agentic Harness, the framework that governed the entire exercise, as open source on GitHub. A companion white paper spells out the architecture behind it, along with 12 practices Visa now treats as non-negotiable for anyone running critical infrastructure.
Finding vulnerabilities is no longer the hard part, Taneja argued. The real challenge is how quickly a team can confirm an issue is truly exploitable, fix it, and prove the attack path is closed rather than just showing a patch was applied.
Why this matters
Visa handing Mythos its own payment rails and then publishing the harness is a bigger signal than the bug count. A network moving money across 200 countries and 160 currencies is about as unforgiving a test bed as exists, and the fact that Claude Mythos chained minor weaknesses into exploit paths that normally surface only late in pen testing tells us something about where automated security research is heading. For developers and founders, the open-sourced harness matters more than the headline: it means teams outside Visa can now run the same style of system-wide, context-aware analysis against their own stacks instead of waiting for a red team to find the same issues in production.
For researchers, this is a real-world data point on whether models can generalize hardening knowledge across decades-old infrastructure, not a benchmark. The obvious question we'll be watching: who else adopts this harness, and does it get used to find flaws before attackers do, or after. Rajat Taneja framed it as testing hardening at AI speed.
Whether that pace favors defenders or just narrows the gap is still unproven.
Common Questions Answered
How did Visa use Anthropic's Claude Mythos to test its payment network?
Visa deployed Claude Mythos AI model against its own payment infrastructure to identify security vulnerabilities across systems managing nearly 5 billion payment credentials in over 200 countries and territories. The model was able to chain together minor weaknesses into complete exploit paths, demonstrating capabilities that typically only surface late in traditional penetration testing processes.
What was significant about the vulnerabilities Claude Mythos discovered in Visa's infrastructure?
Rather than finding isolated flaws, Claude Mythos chained together minor weaknesses buried deep in Visa's systems to create complete attack paths. This ability to link multiple small vulnerabilities into exploitable chains represents a significant advancement in how AI can conduct automated security research on complex payment networks.
Why did Visa decide to open-source the Mythos testing harness after discovering vulnerabilities?
Visa open-sourced the harness to signal the broader importance of automated security research capabilities to the developer community. By publishing the tool that enabled testing on a network processing money across 200 countries and 160 currencies, Visa demonstrated the real-world applicability and maturity of AI-driven security testing for critical infrastructure.
What does Taneja argue is the real challenge in vulnerability management beyond just finding bugs?
According to Taneja, finding vulnerabilities is no longer the difficult part; the real challenge is how quickly teams can confirm an issue is truly exploitable, fix it, and prove the attack path is closed. This shift emphasizes that vulnerability confirmation and remediation speed matter more than simply identifying and patching issues.
Further Reading
- Visa Releases Its AI-Powered Cyber Defense System to Open Source - Visa Perspectives
- Project Glasswing - Frontier AI - Visa
- Visa Reveals AI Model Found 10,000+ Zero-Day Vulnerabilities in Project Glasswing - KuCoin News
- Visa - vpf2026 #poweringconnections - LinkedIn
- Visa Inc. shares experience with Mythos tooling - LinkedIn