Ethereum client developer Nethermind and self-custodial Bitcoin and Lightning wallet ZEUS are among several crypto companies that submitted enrollment requests on Friday for Anthropic’s newly launched OSS Scanner. The program, announced by Anthropic on Thursday, provides open-source projects with access to security reports generated by the company’s most powerful AI models, including Claude Mythos, to help developers find and fix vulnerabilities before they can be exploited.
The initiative follows Anthropic’s work on Project Glasswing and aims to address the slow pace of manual human review in existing vulnerability scanning processes. OSS Scanner will deliver reports immediately after code is scanned. Applications indicate that Nethermind requested audits for its entire repository, while ZEUS sought examinations of weaknesses affecting payments, private keys, and Lightning Services connections. Other applicants include VirtEngine, a decentralized cloud computing marketplace, alongside developers of AI assistants and machine-learning infrastructure. None of the pull requests had been merged at the time of publication. This move occurs as crypto firms seek frontier AI tools to counter increasingly capable attackers, following incidents where providers like Boltz suspended operations due to rapid exploit development.
The integration of frontier AI models into open-source security workflows marks a critical shift in how digital asset infrastructure defends against sophisticated threats. By automating the identification of vulnerabilities in core components like Ethereum clients and Bitcoin wallets, Anthropic’s OSS Scanner addresses the latency inherent in traditional manual reviews. This capability is particularly significant for the crypto sector, where smart contract and protocol-level exploits can result in immediate, irreversible financial losses. The participation of major entities such as Nethermind and ZEUS signals an institutional recognition that defensive tooling must evolve in tandem with offensive capabilities, which cybersecurity experts warn are becoming more accessible and potent through AI assistance.
However, the reliance on proprietary AI models for public infrastructure security introduces complex dependencies and potential single points of failure. While the program offers speed, it raises questions about the transparency of the underlying detection logic and the long-term sustainability of free access for critical open-source projects. Market structure implications suggest that projects unable to secure similar advanced defensive tools may face heightened operational risks, potentially widening the gap between well-resourced incumbents and smaller developers. Stakeholders should monitor whether this opt-in model creates a two-tier security landscape, where only select high-profile projects benefit from real-time AI-driven protection, leaving others exposed to faster exploitation cycles.


