Crypto Projects Seek Anthropic AI Scanner
- Crypto projects including Nethermind and ZEUS are applying for Anthropic's new OSS Scanner to find vulnerabilities.
- Anthropic assesses applications individually based on infrastructure importance user security and remote attack exposure.
- The scanner uses Claude Mythos to send vulnerability findings directly to maintainers without prior human review.
Ethereum client developer Nethermind and Bitcoin and Lightning wallet ZEUS are among the crypto projects applying for Anthropic’s new OSS Scanner, which uses frontier AI models to search open-source code for security vulnerabilities.
Applications began arriving on Oct. 9, one day after Anthropic launched the free opt-in service. The scanner is designed to deliver vulnerability findings directly to maintainers as AI models become more capable of both discovering and exploiting software flaws.
Nethermind, ZEUS and VirtEngine Request Full Repository Scans
Nethermind has asked Anthropic to examine its repository, while ZEUS wants its self-custodial wallet checked for weaknesses involving payments, private keys and connections to Lightning services.
VirtEngine, a decentralized cloud computing platform built as a Cosmos SDK chain, has also applied. None of the crypto applications had been accepted when initially reported, meaning the projects had requested access but had not yet begun receiving OSS Scanner reports.
Anthropic will assess applications individually based on factors including infrastructure importance, user security, exposure to remote attacks and how many people or software projects depend on the code.
Claude Mythos Will Generate Security Reports Without Human Review
OSS Scanner uses Anthropic’s strongest models, including Claude Mythos, to conduct recurring scans at no cost to accepted open-source projects.
Reports can include a reproduction of the vulnerability, an explanation of the issue and a proposed patch when one is available. Unlike Anthropic’s existing coordinated disclosure process, OSS Scanner sends findings without prior human review, so maintainers can receive them faster.
Anthropic warns that reports can contain mistakes. In early testing, 85 of 97 high or critical findings reviewed by penetration testers met its disclosure standard, while 11 were valid but duplicated existing findings and one was invalid.
Anthropic Found More Than 29,000 Candidate Vulnerabilities in Six Months
Anthropic said its models identified more than 29,000 potential vulnerabilities across open-source projects during the past six months.
Human reviewers were able to triage only about 6,000 of those findings, creating a bottleneck the new scanner is designed to reduce.
For crypto developers, the applications provide access to frontier AI security models while preserving responsibility for verifying findings before acting on them.