0x4611892e4611…46118931

ConfirmedSecurity482 vB180 sat/vB2 min decode

Crypto projects apply for Anthropic's OSS Scanner

Nethermind, ZEUS and VirtEngine applied Friday to Anthropic's new OSS Scanner, an opt-in program that uses Claude Mythos to generate vulnerability reports for open-source codebases before attackers exploit weaknesses.

Crypto projects apply for Anthropic’s new frontier AI security scanner
WitnessCrypto projects apply for Anthropic’s new frontier AI security scannerAI-generated

Outputs

  1. Anthropic launched OSS Scanner on Thursday as an opt-in service for open-source vulnerability reports.

  2. Nethermind, ZEUS and VirtEngine submitted enrollment requests on Friday via GitHub pull requests.

  3. Reports will be generated by Claude Mythos, one of Anthropic's strongest models.

  4. None of the pull requests had been merged at publication time, and Anthropic will assess projects on a case-by-case basis.

  5. Bitcoin swap provider Boltz suspended operations in August after AI-assisted exploits outpaced its patching capacity.

Three crypto projects submitted enrollment requests on Friday to Anthropic's OSS Scanner, an opt-in service launched Thursday that delivers vulnerability reports generated by the company's strongest models, including Claude Mythos.

Ethereum client developer Nethermind, Bitcoin and Lightning wallet ZEUS, and decentralized cloud computing marketplace VirtEngine are among the first wave of applicants, according to pull requests filed to the OSS Scanner GitHub repository. None had been merged at publication time.

What is OSS Scanner?

Anthropic described the program as a faster alternative to its existing workflow, which already scans open-source software for vulnerabilities but routes findings through human reviewers. The manual stage is slow, the company said, so vulnerabilities are not always shared quickly enough.

"These reports will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage," Anthropic wrote in its announcement.

OSS Scanner extends the company's earlier Project Glasswing work. Under the new program, Anthropic will deliver vulnerability reports to participating projects as soon as scanning completes, removing the human-review bottleneck for opt-in codebases.

Which crypto projects applied?

  • Nethermind requested audits across its entire repository. The team builds one of the most widely used Ethereum execution clients.
  • ZEUS asked for an examination of its self-custodial Bitcoin and Lightning wallet, with focus on payments, private-key handling and Lightning node connectivity.
  • VirtEngine applied for its Cosmos SDK-based decentralized cloud computing marketplace.

Applicants outside crypto include developers of AI assistants, agent-security tools, machine-learning infrastructure, software development tooling, cloud storage and energy-system controls.

How will Anthropic choose participants?

The company will assess projects on a case-by-case basis, weighing three factors:

  • Importance to infrastructure and user security
  • Exposure to remote attacks
  • Downstream dependencies on other projects and users

Anthropic has not published a timeline for processing requests or a queue length. The GitHub pull requests remain open, and the company has not confirmed acceptance for any applicant.

Why are crypto teams pushing for access?

The applications arrive as crypto firms report AI-assisted attacks outpacing defensive tooling. Bitcoin swap provider Boltz suspended operations in August, citing attackers who developed exploits faster than its team could patch them. Crypto payment service PayPerQ has reported repeated intrusions it suspects were AI-powered.

Anthropic acknowledged the imbalance on Thursday, warning that AI may favor attackers in the near term because exploitation grows cheaper while vulnerability verification and patching remain slow and people-dependent.

Uneven access to frontier models could leave defenders at a structural disadvantage as capable open-weight alternatives circulate widely, according to cybersecurity specialists cited in industry coverage.

What comes next?

Anthropic said it will notify accepted projects individually and begin delivering reports on a project-by-project basis. Crypto applicants will be watching for the first merged pull request as the signal that audits have started producing findings they can act on.

via anthropic.com (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles