Ethereum client developer Nethermind and Bitcoin and Lightning wallet ZEUS are among the crypto-related groups that have requested access to a new security service launched by AI company Anth
Ethereum client developer Nethermind and Bitcoin and Lightning wallet ZEUS are among the crypto-related groups that have requested access to a new security service launched by AI company Anthropic. The program, called OSS Scanner, is designed to help open-source projects identify vulnerabilities earlier—before attackers can exploit them.
Anthropic rolled out OSS Scanner on Thursday and invited open-source maintainers to opt in on Friday for vulnerability reporting. The service uses Anthropic’s strongest models, including Claude Mythos, to generate security findings that participating projects can use to patch code more quickly. According to Anthropic, it will review repositories once their code is scanned and provide reports to enrolled teams.
Key takeaways
- OSS Scanner is an opt-in vulnerability reporting service aimed at accelerating how open-source teams discover and fix security weaknesses.
- Anthropic says reports are generated by its top models, including Claude Mythos, to give maintainers an early defensive edge.
- Nethermind and ZEUS are among the crypto applicants, with requests covering full repository security and wallet-related attack surfaces such as payments and private key handling.
- Anthropic plans case-by-case evaluation based on factors like infrastructure importance, user risk, exposure to remote attacks, and dependency chains.
- The move reflects widening concern over AI-driven exploitation, as several crypto firms have reported incidents where attackers moved faster than teams could patch.
Anthropic launches opt-in vulnerability reports for open source
Anthropic introduced OSS Scanner as an extension of its earlier work on Project Glasswing. In its announcement, the company described OSS Scanner as a service that scans open-source code and produces vulnerability reports after analysis. While Anthropic said it already performs regular vulnerability scanning and sends reports after human review, it also acknowledged a key limitation: manual review can be slow, preventing the organization from sharing issues as quickly as maintainers might need.
OSS Scanner’s core goal is speed and usability. Anthropic says the service will generate reports based on its strongest models and deliver them to participating projects as soon as repositories have been scanned. That “scan-to-report” workflow is especially relevant for projects where a small coding flaw can become high-impact once public attackers notice it.
According to Anthropic, enrollment is not automatic. The company stated the program is assessed on a case-by-case basis, taking into account the importance of the software to infrastructure and user security, how likely it is to be targeted by remote attackers, and how many users or downstream projects rely on it.
Crypto projects ask for audits via OSS Scanner
OSS Scanner submissions for the first cohort show concrete crypto-specific use cases. Pull requests to Anthropic’s OSS Scanner GitHub repository indicate that Nethermind has asked for audits covering its entire repository. The request positions the Ethereum client developer as a critical piece of infrastructure, where vulnerabilities can have outsized consequences across the ecosystem.
ZEUS, a self-custodial Bitcoin and Lightning wallet, has also requested review. Its application focuses on weaknesses that could affect payments, private key handling, and connectivity to Lightning services—areas that are particularly sensitive because they combine user funds, secret material, and network interactions.
Another crypto-related applicant is VirtEngine, described as a decentralized cloud computing marketplace structured as a Cosmos SDK chain. Other submissions in the initial set come from developers building AI assistants, agent-security tooling, and machine-learning infrastructure, alongside projects providing software development tools, cloud storage, and energy-system controls.
At the time of publication, none of the pull requests had been merged, indicating that enrollment review and acceptance were still in progress rather than fully finalized.
Why the timing matters as attackers gain speed
The program lands during a period when cybersecurity teams across crypto have been forced to adapt to faster-moving threats. Earlier coverage cited how access to frontier AI is increasingly viewed as a strategic advantage for defenders—and that uneven availability can widen the gap between attackers and those trying to patch vulnerabilities in time.
Anthropic’s warning alongside the launch echoed that concern. In a statement published on Thursday, the company said AI may tilt toward attackers in the near term because exploitation can become cheaper and more efficient, while verification and fixing vulnerabilities remains slow and dependent on people.
That dynamic has already surfaced in multiple crypto incidents this year. According to earlier reporting, Bitcoin swap provider Boltz suspended operations in August after a wave of AI-assisted hacking attempts, saying attackers were developing exploits faster than its team could patch. Separately, crypto-payment service PayPerQ reported repeated attacks it suspected were AI-powered.
Against that backdrop, OSS Scanner’s pitch—automating vulnerability reporting with high-end models while reducing the bottleneck of purely human review—appears aimed at shrinking the time between “issue discovered” and “issue fixed.” For maintainers, that timing difference can determine whether a vulnerability stays a private issue or becomes a publicly exploited one.
What to watch next for OSS Scanner adopters
While OSS Scanner provides a mechanism to generate security reports, the practical impact for projects like Nethermind and ZEUS will depend on several moving parts: how quickly scans are completed, what kinds of vulnerabilities the models prioritize, and how reliably maintainers can turn findings into patched releases. Anthropic’s case-by-case evaluation criteria also suggest that the service may initially focus on the most risk-relevant software rather than offering uniform coverage across all applicants.
For readers and builders in crypto, the next indicators are straightforward: whether accepted projects receive timely reports, how the findings compare to what teams previously detected with slower workflows, and whether faster vulnerability reporting changes how quickly critical issues are mitigated across open-source infrastructure.
As AI-enabled attacks continue to evolve, OSS Scanner’s early crypto participation will be an important test of whether model-assisted vulnerability reporting can help open-source maintainers keep pace with attackers—especially in systems where delays can translate directly into real-world risk.
This article was originally published as Crypto Teams Submit Proposals for Anthropic’s AI Security Scanner on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.