Back to News
SecurityAI Understanding briefing

Ethereum and Bitcoin projects seek early access to Anthropic's AI scanner

Nethermind and ZEUS submitted applications to Anthropic's new OSS Scanner, an automated service using Claude Mythos to identify vulnerabilities in open-source code without the delay of manual human review.

4 min readRead the linked source
Source-provided image accompanying Ethereum and Bitcoin projects seek early access to Anthropic's AI scanner
Source referenceSource recorded
Publisher
finance.biggo.com
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

What happened

Nethermind, an Ethereum execution client developer, and ZEUS, a Bitcoin and Lightning wallet, submitted enrollment requests to Anthropic's newly launched OSS Scanner. This automated service uses Anthropic's models, including Claude Mythos, to generate vulnerability reports for open-source projects, removing the manual verification bottleneck of previous initiatives. The applications were submitted one day after the program's launch, with no fixed timetable for approval or report delivery announced.

Nethermind and ZEUS submitted applications to Anthropic's OSS Scanner on Friday, one day after the service launched. Nethermind requested audits for its entire Ethereum execution client repository, while ZEUS targeted components handling payments, private keys, and Lightning network connections. VirtEngine, a decentralized cloud computing marketplace, also applied, joining a broader pool of applicants including developers of AI assistants and infrastructure tools.

The OSS Scanner is an evolution of Anthropic's earlier Project Glasswing, which relied on human review of AI-generated findings. The new service delivers automated reports immediately after scanning, addressing a backlog where Anthropic's models had identified over 29,000 candidate vulnerabilities in six months, but humans had only reviewed roughly 6,000. Anthropic states that this automation provides a 'largest defensive advantage' by allowing maintainers to address flaws before attackers can exploit them.

The applications are currently pending, with no pull requests merged at the time of reporting. Anthropic evaluates submissions based on infrastructure importance, exposure to remote attacks, and user dependency. The company has not announced a fixed timetable for onboarding or the number of crypto projects it will accept, leaving the immediate timeline for these specific teams uncertain.

Source details: finance.biggo.com ↗

Why it matters

The move signals that critical cryptocurrency infrastructure is actively seeking AI-driven defensive tools to counter the accelerating pace of AI-assisted attacks. By automating vulnerability detection, Anthropic aims to close the gap between the speed at which AI models find flaws and the slower pace of human remediation. This is particularly significant for crypto projects where unpatched vulnerabilities in core infrastructure can lead to immediate financial loss and network-wide instability.

The interest from crypto infrastructure developers reflects a growing concern that AI tools are enabling attackers to identify and exploit vulnerabilities faster than defenders can respond. Recent incidents, such as the suspension of Bitcoin swap provider Boltz due to AI-assisted attacks, have highlighted this asymmetry. ZEUS, which was affected by Boltz's shutdown, is now seeking proactive defense through automated scanning.

Anthropic's approach addresses a critical bottleneck in software security: the speed of human verification. While the company reports that 88% of high-severity findings in early testing met disclosure standards, it acknowledges that automated reports may contain inaccuracies or incorrect severity ratings. This trade-off is significant for projects like Nethermind, where a single flaw in critical infrastructure could ripple across the entire Ethereum network.

The initiative is part of the broader Anthropic Cyber Mission, which includes a Critical Infrastructure Defense Program partnering with firms like CrowdStrike and Palo Alto Networks. For the crypto sector, this represents a shift toward integrating advanced AI models directly into the security lifecycle of decentralized systems, potentially setting a new standard for how open-source maintainers manage risk in an era of AI-accelerated threats.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

System Requirements:
Best ArchitecturePure RAGRecommended pattern
Hallucination RiskVery LowGrounding efficacy
Update Cost$0 (Vector sync)Ongoing maintenance
Core takeaway: Fine-tuning teaches models how to speak (form, style, syntax); RAG teaches models what to say (verifiable facts). Never use fine-tuning alone for factual memory.
Interactive Concept Check+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

What to watch next

Monitor the approval status of Nethermind and ZEUS applications and the subsequent release of their first automated vulnerability reports. Watch for independent verification of the scanner's accuracy, as Anthropic acknowledges that unverified reports may contain inaccuracies. Additionally, observe whether other major crypto infrastructure projects join the program and how the industry responds to the potential trade-offs of automated security scanning.

The approval status of the Nethermind and ZEUS applications is the immediate next step. Since Anthropic has not provided a fixed timetable, the speed of onboarding will determine how quickly these projects can benefit from the scanner. Delays could leave them exposed to the same AI-assisted attack vectors that have affected other crypto services.

Independent verification of the scanner's output will be crucial. While Anthropic cites an 88% accuracy rate for high-severity findings in early testing, the real-world impact will depend on how reliably maintainers can distinguish genuine vulnerabilities from false positives. The crypto community may scrutinize the first public reports for accuracy and practical utility.

The broader adoption of OSS Scanner by other critical infrastructure projects will indicate whether this model of automated security scanning becomes a standard practice. If successful, it could reshape how open-source projects manage security risks, particularly in sectors where the cost of a breach is high and the pace of development is rapid.

Related guides & quizzes

Found this useful?