Payward, the parent company of cryptocurrency exchange Kraken, joined Anthropic’s Project Glasswing on Aug. 17 and gained restricted access to Claude Mythos 5 for defensive cybersecurity work.
Summary
- Payward joined Anthropic’s Project Glasswing and gained restricted access to the Claude Mythos 5 model.
- The company plans to scan all Payward environments for software vulnerabilities within the coming weeks.
- Payward says validated third party findings will be shared with relevant open source project maintainers.
- Anthropic limits Mythos 5 access to vetted organizations because its cybersecurity capabilities carry misuse risks.
- Mythos 5 usage requires customers to accept thirty day data retention for Anthropic safety monitoring.
The company plans to use the artificial intelligence model to scan its software environments for vulnerabilities over the coming weeks. Findings will enter Payward’s existing security review process rather than automatically producing software changes.
Payward also said it intends to disclose validated vulnerabilities affecting third party open source projects to their maintainers. The company did not identify its first scanning targets, publish a deployment schedule or disclose the cost of its Mythos 5 access.
Payward will scan its software environments
Payward said Claude Mythos 5 will examine all company environments for software weaknesses. Its infrastructure supports digital asset trading, custody and settlement services that remain available continuously.
The announcement does not specify whether Mythos 5 will receive access to production systems, isolated copies of source code or controlled testing environments. Payward also did not describe how its security team will validate findings before approving fixes.
False positives remain a practical concern when artificial intelligence systems review complex software. A model may identify unreachable code, duplicate an existing report or misunderstand how a component operates in production. Human review is therefore required before teams classify an issue as a vulnerability.
The Ethereum Foundation reached a similar conclusion while testing AI security agents. As crypto.news reported, its researchers found that AI generated vulnerability reports still required independent human validation, particularly when agents examined complex protocol code.
Payward cochief executive Arjun Sethi said AI could change the imbalance between attackers and defenders by reading code at greater scale.
“A model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit,” Sethi said.
The statement describes Payward’s intended defensive advantage. The company has not yet published results showing how many valid flaws Mythos 5 found within its systems.
Project Glasswing restricts access to vetted partners
Anthropic launched Project Glasswing in April 2026 to give selected infrastructure providers and software maintainers early access to its strongest cybersecurity models.
Initial participants included Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JPMorganChase, Microsoft, Nvidia, Palo Alto Networks and the Linux Foundation. Anthropic later expanded the initiative to approximately 150 organizations across more than 15 countries.
The company says participating organizations must meet security requirements before receiving access. Mythos 5 is not generally available because the same capabilities used to identify vulnerabilities can also help produce working exploits.
As previously reported, Anthropic restored Mythos access only to vetted U.S. organizations after the U.S. government lifted temporary export restrictions. The safeguarded Claude Fable 5 model returned to wider availability.
Payward said its access followed the U.S. decision allowing Mythos 5 to reach organizations that operate and defend critical infrastructure. Anthropic’s official model page confirms that access was restored for a set of U.S. organizations following government approval.
Neither Anthropic nor the U.S. government has publicly designated every digital asset platform as critical infrastructure. Payward’s statement that such platforms “belong on that list” represents the company’s position rather than a formal government classification.
Claude Mythos 5 carries defensive and offensive risks
Anthropic describes Claude Mythos 5 as its most capable model for cybersecurity and biology research. The model can inspect code, identify weaknesses, suggest patches and assist approved researchers with testing exploit paths.
Project Glasswing’s earlier Mythos Preview reportedly found more than 10,000 flaws classified as high or critical severity across widely used software. Anthropic’s coordinated disclosure dashboard showed 1,596 vulnerabilities reported across 281 open source projects as of May 22.
Those figures are Anthropic’s measurements and do not mean every initial model finding was valid. Its dashboard recorded a 90.8% true positive rate among 1,900 candidates reviewed by external security firms.
Anthropic said independent human triage remains the limiting stage. Only 97 listed findings had been patched upstream at the time of the dashboard update, while 88 had received a public advisory identifier.
The model can also create exploit components and combine them into attack chains. Anthropic cited this dual use capability when explaining why Mythos 5 remains limited to approved partners.
In related coverage, researchers found that Mythos class models could turn software flaws into working exploit chains. Wider access would therefore give attackers some of the same capabilities available to defenders.
Open source findings will go to maintainers
Payward said vulnerabilities discovered in shared third party code will be sent to the relevant project maintainers. It presented that process as a way to protect other organizations using the same software.
The company did not publish a coordinated disclosure policy for the initiative. Important unanswered details include how long maintainers will have to patch flaws, which findings Payward may disclose publicly and how it will handle projects that do not respond.
Responsible disclosure normally requires researchers to verify a vulnerability, contact the maintainer privately and allow time for remediation before releasing technical information. Premature publication can expose users before a patch becomes available.
Payward has previously faced disputes over security research. As crypto.news reported, Kraken patched a deposit flaw that researchers used to withdraw nearly $3 million. The exchange later recovered the funds following a public disagreement with CertiK.
That episode was unrelated to Project Glasswing, but it shows why clear testing and disclosure rules matter. AI scanning can increase the number of reported findings, creating additional work for security teams and maintainers.
What happens next for Payward’s AI security rollout
Payward plans to begin scanning its environments within weeks. The next verifiable updates would include confirmed vulnerabilities, completed patches or public disclosures coordinated with affected open source projects.
No performance targets were announced. Payward did not say how frequently Mythos 5 will scan its systems or whether the model will review new code before deployment.
Anthropic requires Mythos 5 customers to accept thirty day data retention for safety monitoring. Payward has not explained what code or system information will be submitted, how sensitive data will be separated or whether customer information falls outside the scanning process.
For now, the confirmed development is Payward’s admission to Project Glasswing and planned use of Claude Mythos 5. Whether the model improves the company’s security will depend on the quality of its findings, human verification and the speed of subsequent patches.





Be the first to comment