Cryptocurrency companies, including Ethereum developer Nethermind and Bitcoin wallet ZEUS, have applied to use Anthropic's newly launched AI security scanning service. This service utilizes Claude Mythos to identify software vulnerabilities, with the aim of detecting issues before attackers can exploit them.
- Ethereum developer Nethermind and Bitcoin wallet ZEUS have applied to use the free security scanning service provided by Anthropic.
- Anthropic indicates that its scanner uses Claude Mythos and will send automated vulnerability reports without any manual review.
- Nethermind requests to scan the code repository, while ZEUS wishes to check payments, private keys, and Lightning related content.
- Anthropic claims to have identified 29,000 potential vulnerabilities, of which only about 6,000 have currently undergone internal manual review.
Anthropic launched a free OSS Scanner on October 8th, allowing eligible open-source projects to receive automated reports to identify potential security vulnerabilities. Applications submitted on October 9th showed that encryption developers have an increasing interest in using advanced AI tools to check and process code related to transactions, private keys, and blockchain infrastructure.
This project continues the Project Glasswing plan of Anthropic. That plan allowed some organizations to obtain powerful AI models for cybersecurity research. Unlike its existing disclosure process, the new service will send the findings directly without waiting for manual verification.
Encrypted developers apply to use Claude Mythos security scanning
Ethereum client developer Nethermind is one of the earliest blockchain projects to seek participation, submitting on Friday GitHub pull request #38. This application requested a security scan of their code repository, where the developer maintains software for interacting with the Ethereum network.
Nethermind develops Ethereum execution clients, which are responsible for processing blockchain transactions and supporting the operation of the network. If Anthropic approves the application, the team will receive a report generated by AI, which is used to identify potential weaknesses in the code.
Bitcoin and the Lightning wallet, as well as the ZEUS wallet, have also submitted separate applications, hoping to have their mobile applications and components that handle payments, private keys, and Lightning connections inspected. This self-hosted wallet allows users to manage Bitcoin while retaining control over their funds.
The decentralized cloud computing market VirtEngine built on the basis of Cosmos SDK has also submitted an application to join through another GitHub. This project develops infrastructure for decentralized computing services, so its software may also become the target of scanning.
These applications are currently only in the request phase and do not indicate that the security audits for these projects have been completed. Anthropic will evaluate each application individually, taking into account its importance to the infrastructure, its vulnerability to remote attacks, and how many other systems rely on its software.
Other applicants also include AI assistants, developers of security tools, machine learning infrastructure, and cloud storage systems. Anthropic has not yet announced a fixed timeline for approving encryption projects or delivering the first batch of reports.
Anthropic claims that the AI scanner has detected thousands of security vulnerabilities
Anthropic indicates that after it was found that its AI model could identify potential software defects faster than researchers could do through manual review, OSS Scanner was developed.
In the past six months, the company claims that its model has identified over 29,000 potential vulnerabilities in widely used open-source projects. Researchers have manually reviewed approximately 6,000 of these findings, with a large number of results still waiting to be evaluated.
For this reason, Anthropic has launched an automated system that directly sends reports to the participating maintainers. The company stated that this service will utilize its strongest models, including Claude Mythos, to generate findings and recommended solutions for repairs.
Anthropic stated in the announcement: 'These reports will be generated by our strongest models (including Claude Mythos).'
Unlike traditional security audits that involve manual review before disclosure, OSS Scanner generates reports without any human verification. Anthropic also acknowledges that some of the findings may not be accurate, including errors in the severity grading, or that certain vulnerabilities may not apply to the security design of the project.
In early tests, external penetration testers examined 97 high-severity and critical findings across 48 projects. Anthropic reported that 85 of these findings, approximately 88%, met their coordinated vulnerability disclosure standards.
Among the remaining 12 findings, 11 are actual issues, either duplicating existing reports or matching known vulnerabilities. Another 1 finding is invalid.
The company stated that their scanners will provide reproducible examples of identified vulnerabilities, descriptions of the affected code, and recommended patches when available. Participating encryption developers must review these findings on their own before deciding whether modifications are necessary.
For projects that are unable to handle a large number of automated reports, Anthropic will continue to maintain the existing manual vulnerability disclosure process.
AI After auxiliary attacks, concerns about encryption security rise
Prior to this release, blockchain companies had reported several attack incidents involving automated tools or what is suspected to be assistance from AI.
In August, Bitcoin exchange service provider Boltz suspended operations after several months of experiencing AI assisted attacks. The company stated that attackers were able to identify vulnerabilities faster than developers could investigate and fix them.
Boltz ceased its exchange services on August 3rd due to several reported incidents of controlled exploitation. The team stated that their self-managed design prevented the exposure of customer funds, but the company incurred operational losses as a result.
This interruption affected services that rely on the infrastructure of Boltz, including ZEUS. After the service was shut down, the exchange function of that wallet was temporarily disabled. Additionally, another cybersecurity incident involving ZEUS prompted the team to take some infrastructure offline for review.
Another security initiative Bitcoin Red Team indicates that during an approximately 30-hour AI auxiliary code review in August, 4,962 potential vulnerabilities were discovered in 390 Bitcoin-related projects.
This Bitcoin security review classified 720 findings as high severity or critical level, but these issues still require further verification before they can be confirmed as vulnerabilities.
Anthropic The earlier Project Glasswing initiative has already attracted mature industry participants. In August, Kraken, the parent company Payward, joined Claude Mythos's security program to identify software vulnerabilities in their systems.
The company stated that it plans to scan its own environment and share the verified findings that affect third-party open-source projects with the maintainers of those projects.
Anthropic Expand the scope of use of AI network security tools
OSS Scanner is part of Anthropic Cyber Mission. This initiative was announced on October 8th and aims to support software security and the protection of critical infrastructure.
In addition to scanning services, Anthropic has also launched Critical Infrastructure Defense Program, providing AI models, engineering support, and threat research for organizations that need to protect power grids, transportation networks, and industrial systems.
The partners of this plan include CrowdStrike, Accenture, Deloitte, Palo Alto Networks, and several other cybersecurity and technology companies.
For open-source developers, Anthropic provides free regular security scans for approved projects. Maintainers can apply through the published registration templates in the GitHub repository of OSS Scanner.
Qualification assessment will take into account whether the project has a "critical impact" on infrastructure and user security, as well as whether the team has the capability to review and address the reported vulnerabilities.
Anthropic has not yet announced how many crypto projects will ultimately be accepted. Approved maintainers will receive reports generated by the model through this service, while the company will still provide disclosures with manual review through existing security processes.












