Crypto Developers Turn to Anthropic's AI Security Scanner

Anthropic's free OSS Scanner, powered by Claude Mythos, is drawing applications from crypto projects like Nethermind and ZEUS. The AI tool has flagged thousands of candidate vulnerabilities and aims to speed open-source security, but maintainers must validate findings.

.1 Comments
Crypto Developers Turn to Anthropic's AI Security Scanner

6 Minutes

Follow on Google

Anthropic's OSS Scanner draws interest from Ethereum and Bitcoin projects

Anthropic's newly released OSS Scanner is attracting attention from major crypto developers seeking faster, AI-driven vulnerability detection. Projects such as Ethereum client developer Nethermind and Bitcoin wallet ZEUS applied for access to the free scanner, which runs on Anthropic's most capable models, including Claude Mythos, and automatically generates reports that flag potential software weaknesses before attackers can exploit them.

Why crypto teams are applying for AI-powered scanning

Developers maintaining code that handles transactions, private keys and network infrastructure face intense pressure to find and patch bugs quickly. Traditional human-led audits can take weeks or months, and high-profile incidents driven by automated or AI-assisted attacks have raised the stakes for blockchain projects. The OSS Scanner promises rapid, continuous analysis of open-source repositories, which makes it appealing to teams responsible for critical infrastructure.

Nethermind submitted a GitHub pull request requesting repository-wide scanning to identify possible flaws in its Ethereum execution client. ZEUS, a self-custodial Bitcoin and Lightning wallet, applied for checks specifically targeting payment flows, private key handling and Lightning Network connectivity. Another applicant, VirtEngine, a decentralized cloud marketplace built on the Cosmos SDK, asked Anthropic to evaluate its infrastructure code.

How Anthropic's scanner works and what it reports

Anthropic says its OSS Scanner leverages Claude Mythos among its strongest models to process open-source code and produce automated vulnerability reports. Unlike traditional disclosure processes that wait for human validation, the scanner can send findings directly to maintainers without prior manual review. Each report is designed to include reproducible examples, affected code paths and suggested patches or mitigations when available.

The company reported that, over the past six months, its models flagged roughly 29,000 candidate vulnerabilities across widely used open-source projects. Of those, researchers manually reviewed approximately 6,000 findings, leaving a sizable backlog. To scale coverage, Anthropic launched the OSS Scanner on October 8 to provide qualifying projects with model-generated reports at no cost.

Accuracy, validation and the role of maintainers

Anthropic acknowledges the risks inherent in automated discovery. The scanner can produce false positives, incorrect severity ratings or findings that don't apply to a project's security model. In early testing, external penetration testers evaluated 97 high-severity or critical findings across 48 projects; 85 of those, roughly 88%, were judged to meet coordinated disclosure standards. Eleven others were duplicates of known issues, and one was invalid.

Because of this margin of error, participating crypto teams must review and validate scanner output before taking action. Anthropic will continue its existing human-reviewed vulnerability disclosure channel for projects that prefer or require human triage prior to reporting.

Crypto security context: why timing matters

The OSS Scanner rollout comes amid a surge in AI-assisted security incidents in the blockchain sector. In August, Bitcoin swap provider Boltz suspended swap services after a series of automated attacks that exploited software weaknesses faster than teams could respond. Boltz reported that its self-custodial architecture protected customer funds, but the firm still faced operational losses and service interruptions that affected dependent projects, including ZEUS.

Separately, the Bitcoin Red Team used AI-assisted reviews to scan hundreds of Bitcoin-related repositories and reported nearly 5,000 potential issues in roughly 30 hours, with 720 classified as high or critical severity pending verification. Those episodes illustrated how attackers and defenders alike are adopting automated tooling and machine learning to accelerate code review and exploit discovery.

Project Glasswing and broader cybersecurity efforts

OSS Scanner expands on Anthropic's earlier Project Glasswing, which provided select organizations access to powerful models for cybersecurity research. Glasswing already drew participation from established industry players, including Payward (Kraken's parent company), which used Claude Mythos to audit its environments and to share validated findings affecting third-party open-source dependencies.

Anthropic is positioning OSS Scanner as part of a broader Cyber Mission initiative announced on October 8. Alongside free scans for approved open-source projects, the company introduced a Critical Infrastructure Defense Program that pairs AI models, engineering support and threat research for organizations that manage power grids, transportation, industrial control systems and other critical services. Partners named in the initiative include CrowdStrike, Accenture, Deloitte and Palo Alto Networks.

Enrollment criteria, limitations and next steps for crypto projects

Anthropic evaluates OSS Scanner applications on several criteria: whether the project has critical impact on infrastructure and user security, its exposure to remote exploitation, and the maintainers' capacity to review and act on automated reports. Applications submitted on October 9, such as those from Nethermind and ZEUS, reflect growing interest from blockchain developers to quickly surface issues in code that manages consensus, execution, wallet custody and payment channels.

However, application does not equal approval. Anthropic reviews submissions individually and has not published a fixed timetable for acceptance or report delivery. It also has not stated how many crypto projects it will ultimately onboard.

Operational implications for maintainers

For open-source maintainers, acceptance into the OSS Scanner program will mean a steady stream of model-generated findings. That can be a double-edged sword: faster detection of real vulnerabilities, but also the administrative burden of triaging false positives and coordinating disclosures. Anthropic will route automated reports to approved maintainers, who must then validate issues, patch code as needed and pursue coordinated disclosure if appropriate.

Teams that prefer curated or human-reviewed outputs can continue using Anthropic's traditional disclosure channel instead of the automated scanner.

What this means for blockchain security going forward

Anthropic's move to scale automated vulnerability detection underscores a shifting landscape in which AI plays an increasingly central role in both offense and defense. For the crypto ecosystem, rapid AI-assisted scanning could shorten the window between vulnerability discovery and remediation, potentially reducing the number of high-impact exploits. At the same time, widespread adoption of automated tools raises questions about resource allocation, false-positive management and responsible disclosure practices.

For projects like Nethermind and ZEUS, gaining timely insights into code that governs transactions, key management and Lightning connectivity could improve resilience. But maintainers will need clear workflows to validate AI findings, prioritize fixes, and communicate with users and dependent projects.

Final considerations

Anthropic's OSS Scanner represents one of the most ambitious attempts to apply large-scale AI models to open-source security at speed. Its success will depend on balancing automated detection with human expertise, and ensuring that vulnerable projects have the capacity to act on often large volumes of reports. As attackers continue to experiment with automation and AI, defenders in the crypto space may need every advantage they can get — including scalable model-driven scanning paired with disciplined, human-led response processes.

The applications from Nethermind, ZEUS and others highlight increasing demand from blockchain developers for advanced AI tools to safeguard networks, wallets and infrastructure. Whether the OSS Scanner becomes a mainstay of crypto security practices will hinge on report quality, enrollment policies and the community's ability to turn AI-generated findings into timely, reliable remediation.

Sourcecrypto.news
Zoya Akhtar
"I’m Zoya, and crypto is my playground. I dive deep into blockchain trends, DeFi, and how digital assets shape our future economy."

Leave a Comment

Comments (1)

coinflux

Automated reports straight to maintainers? sounds risky. False positives, alert fatigue, and what about secrets ending up in reports, who vets the model output properly