Newsroom
9 October, 2026 / News / AI / Tags: scanner, anthropic, mythos, findings, claude

Ethereum and Bitcoin teams apply for free automated security scans using Claude Mythos as AI-driven threats rise
Several cryptocurrency development teams have applied for access to a new free vulnerability scanning service from Anthropic, the artificial intelligence company behind Claude models. The applications arrived one day after the launch of OSS Scanner, an opt-in program designed to deliver automated security reports to open-source projects.
Ethereum client developer Nethermind, Bitcoin and Lightning wallet ZEUS, and decentralized computing project VirtEngine are among the early crypto-related applicants. Their requests target software that handles blockchain transactions, private keys, payments and network connections.
Anthropic introduced OSS Scanner on October 8 as part of its broader Cyber Mission. The service allows approved open-source maintainers to receive vulnerability reports generated by the company’s strongest models, including Claude Mythos. Unlike previous processes that required human review before disclosure, the scanner produces and sends findings as soon as code analysis is complete.
The company developed the tool after its models identified more than 29,000 candidate vulnerabilities across widely used open-source projects over a six-month period. Researchers manually examined only about 6,000 of those findings, creating a backlog that limited timely sharing.
In early testing, external penetration testers reviewed 97 high-severity and critical findings from 48 projects. Anthropic reported that 85 of those findings, or roughly 88 percent, met its standards for coordinated vulnerability disclosure. Of the remaining 12, 11 were genuine issues already known or duplicated, and one was invalid.
The scanner supplies reproducible examples of potential weaknesses, explanations of affected code and suggested patches when available. Participating teams must still evaluate the findings themselves. Anthropic will maintain its existing human-reviewed disclosure process for projects that cannot manage high volumes of automated reports.
On October 9, Nethermind filed a request for scanning of its full repository. The company develops an Ethereum execution client that processes transactions and supports network operations. ZEUS, a self-custodial Bitcoin and Lightning wallet, asked for examination of its mobile application and components that manage payments, private keys and Lightning connections. VirtEngine, a decentralized cloud computing marketplace built with the Cosmos SDK, also submitted an application.
Anthropic evaluates requests individually. Criteria include a project’s importance to infrastructure and user security, exposure to remote attacks, and the number of users or dependent systems that rely on the software. At the time of the applications, none of the related GitHub pull requests had been merged, indicating that review and approval remain in progress.
Applicants outside the crypto sector include developers of AI assistants, agent-security tools, machine-learning infrastructure, software development utilities, cloud storage systems and energy-system controls.
The timing of the applications coincides with growing reports of automated or suspected AI-supported attacks on blockchain services. In August, Bitcoin swap provider Boltz suspended operations after stating that attackers were identifying and developing exploits faster than its team could investigate and repair them. The company’s self-custodial design limited exposure of customer funds, though it absorbed operational losses. The interruption temporarily affected related services, including swap functionality in ZEUS, which later took some infrastructure offline following a separate cybersecurity incident.
A separate initiative known as Bitcoin Red Team reported identifying 4,962 potential vulnerabilities across 390 Bitcoin-related projects during roughly 30 hours of AI-assisted code reviews in August. Of those, 720 were classified as high or critical severity, though verification remained necessary.
Anthropic has stated that AI may favor attackers in the near term because exploitation becomes cheaper and faster while verification and remediation still depend on human effort. Earlier this year the company also granted selected organizations, including the parent company of exchange Kraken, access to Claude Mythos models under its Project Glasswing program for cybersecurity research.
OSS Scanner forms one component of Anthropic’s Cyber Mission, announced alongside the scanner launch. The company also introduced a Critical Infrastructure Defense Program that supplies AI models, engineering support and threat research to organizations protecting power grids, transportation networks and industrial systems. Partners include cybersecurity and technology firms such as CrowdStrike, Accenture, Deloitte and Palo Alto Networks.
For open-source maintainers, the scanning service is offered at no cost once projects are approved. Enrollment occurs through a published template in the OSS Scanner GitHub repository. Anthropic has not disclosed how many crypto projects it expects to accept or provided a fixed timetable for delivering the first reports to approved teams.
Approved participants will receive model-generated findings directly. The company continues to stress that maintainers remain responsible for reviewing results and deciding on any necessary code changes.









