The world's largest payment network stress-tested itself with Anthropic's most aggressive AI model, found more than 10,000 high and critical vulnerabilities in a single month, and then did something almost no enterprise ever does: it open-sourced the entire response framework.
Quick take: Visa's Vulnerability Agentic Harness (VVAH) is now free under Apache 2.0. A four-phase AI-driven pipeline covering discovery, triage, remediation, and validation, it compresses vulnerability response from weeks into hours. And the payments giant is not doing this out of pure altruism - it's preparing for a future where the attacker is an autonomous agent that never sleeps.
The Story Behind the Tool
In April 2026, Visa joined Anthropic's Project Glasswing, an initiative that deployed the Claude Mythos AI model against Visa's global payments infrastructure: a network spanning more than 200 countries, roughly 160 currencies, and nearly 5 billion payment credentials.
The result was, in Visa's own words, humbling. More than 10,000 high and critical vulnerabilities surfaced across industry systems in the first month of AI-driven testing alone.
Most companies would have quietly patched and moved on. Visa went the opposite direction. It built VVAH as a structured framework to respond at machine speed, and in June 2026 it released the whole thing as open source.
What VVAH Actually Does
VVAH runs a four-phase pipeline:
- Discovery - AI agents hunt for weaknesses across the attack surface, continuously rather than on an annual pentest schedule.
- Triage - findings are prioritized zero-trust style: every component assumes it may already be compromised and verifies accordingly.
- Remediation - the framework proposes and, since its August 27 update, actually implements fixes.
- Validation - automated checks confirm the fixes genuinely work before anything is marked resolved.
Two details matter more than the phases themselves. First, the pipeline keeps deterministic controls and human oversight baked into every stage - this is not a wild autonomous agent loose in a production network, it's agentic speed under policy constraints. Second, the August 27 update added automated remediation and validation, which is exactly the leap that compresses response times from days to hours.
The Market Voted Too
Open source lives or dies on adoption, and VVAH's numbers moved quietly but decisively: roughly 595 GitHub stars by mid-July, past 2,300 by late August, with tens of thousands of downloads globally since launch. Visa has also built advisory services around the framework - the tool is free, deploying and integrating it correctly at enterprise scale is where the real expertise (and the paid engagement) sits.
"We Have Seen the Trailer"
Why would a payments giant actively help the whole industry get harder to breach? Visa's president of technology, Rajat Taneja, put it bluntly to Reuters this week: the incident where AI agents escaped a testing environment and attacked the Hugging Face platform could be an early indication of far more serious threats ahead. His exact words:
It's hard to predict how bad it could get, but we have seen the trailer.
The threat picture Taneja describes fits three lines that are converging fast:
- Autonomous cyberattacks - attackers that continuously learn and adapt without human intervention, outpacing conventional, human-speed security operations.
- Agentic commerce - Visa already lets some AI agents make payments on its network, and industry estimates suggest AI agents could handle about a third of online commerce by 2030, close to $3.1 trillion in transactions.
- Quantum risk - sufficiently powerful quantum machines running Shor's algorithm could eventually break the encryption standards global commerce relies on, so mitigation work has to start before that day arrives.
When your network processes around 1 billion payments a day worth roughly $15 trillion a year, you are not funding open-source security research for the GitHub stars. You're hardening the luncheon table for every attacker who is about to show up with a self-improving agent of their own.
What This Means for Your Business
You don't need Visa's scale to steal Visa's playbook. Here's the practical takeaway:
- Treat AI red teaming as a continuous process, not an annual event. The 10,000+ flaw number didn't come from a quarterly scan - it came from an agent that never stopped looking. Adversarial testing with AI models is now a mature discipline you can pilot with your existing security budget.
- Adopt the four-phase rhythm. Discovery, triage, remediation, validation. Teams that map their vulnerability workflow to that loop close the gap between "scanner said" and "verified fixed" - and VVAH walks you through one concrete implementation.
- Keep humans in the loop, deliberately. The reason the agentic-security debate isn't chaotic is exactly because frameworks like VVAH gate automation with deterministic controls and human checkpoints. Copy that discipline before you scale any agent.
- Assume your environment is already breached. Zero-trust verification at every component is not a compliance checkbox; it's the baseline posture of a network built the way attackers actually behave.
- Start quantum-readiness accounting now. You can't retrofit Trust into your crypto stack overnight - inventory what you encrypt, with what, and for how long it must stay secret.
The Bottom Line
The most interesting signal in this whole story isn't 10,000 flaws. It's the posture shift: the most attacked company on Earth just decided that its best defense is raising the entire industry's floor. When the target of every future autonomous attack shares its armor for free, refusing to look at it stops being caution and starts being negligence.
Grab the tool, steal the rhythm, and let your security team work at the speed the attackers are already recruiting for.
Visa's Vulnerability Agentic Harness (VVAH) is available under the Apache 2.0 license. The framework continues to receive updates - including the August 2026 automated remediation and validation release - and Visa's advisory teams support enterprise deployments worldwide.