Nethermind, ZEUS and other crypto projects applied for Anthropic's new OSS Scanner, a service that uses frontier AI models to find software vulnerabilities before hackers do. As AI-powered attacks on crypto infrastructure rise, access to stronger defensive tools could decide which projects survive the next exploit.
What actually happened
Anthropic launched OSS Scanner on 8 October 2026, an opt-in service offering vulnerability reports from its most powerful AI models, including Claude Mythos, according to Cointelegraph. Crypto firms submitted enrollment requests the next day, 9 October 2026. Ethereum client developer Nethermind applied for an audit of its entire repository. Bitcoin and Lightning wallet ZEUS requested checks on payments, private keys and Lightning Service connections. VirtEngine, a decentralized cloud computing marketplace built as a Cosmos SDK chain, also applied. Anthropic said the reports "will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage." None of the pull requests had been merged at the time of publication.
How we got here
OSS Scanner builds on Anthropic's earlier Project Glasswing, which already scanned open-source code but relied on slow human review before sharing results. Crypto firms have faced a rising wave of AI-assisted attacks this year. Bitcoin swap provider Boltz suspended operations in August 2026, saying attackers built exploits faster than its team could patch them. Crypto payment service PayPerQ reported repeated attacks it suspected were AI-powered. Anthropic itself warned on 8 October 2026 that AI may favor attackers in the near term, since exploitation is getting cheaper while fixing vulnerabilities still depends on people.
Why this matters for you
For wallet users, faster vulnerability detection could mean fewer exploits draining funds before patches ship. For builders, OSS Scanner offers access to frontier model audits that smaller teams could not otherwise afford. For the wider ecosystem, uneven access raises a fairness question: projects accepted into the program gain a defensive edge over those left waiting. Anthropic said it will assess applicants case by case, weighing infrastructure importance, exposure to remote attacks and how many users depend on them. That selection process could shape which protocols stay resilient.
The bigger question
If AI models can find vulnerabilities faster than humans can review them, who decides which projects get protected first? Anthropic's case-by-case selection raises a broader question for the open-source world: can defensive AI access keep pace with attackers if it stays rationed instead of open to all?
What to watch
Watch whether Anthropic merges the pending pull requests from Nethermind, ZEUS and VirtEngine on the OSS Scanner GitHub repository. None had been merged as of 9 October 2026. Further applications from AI assistant developers, agent security tool builders and machine learning infrastructure projects are expected as the program grows. Bonuz will track how this access shapes security for wallets and hardware tied to Web3 identity.



