EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Payward strengthens cryptocurrency security with Claude Mythos 5

2026-08-18 12:56:58
Bookmark

Payward joins Anthropic's Project Glasswing and is approved to use Claude Mythos 5 for defensive cybersecurity work.

Payward, the parent company of cryptocurrency exchange Kraken, joined Anthropic's Project Glasswing on August 17 and gained restricted access to Claude Mythos 5 for defensive cybersecurity work.

Summary

Payward joined Anthropic's Project Glasswing and gained restricted access to the Claude Mythos 5 model. The company plans to scan all Payward environments for software vulnerabilities in the next few weeks and said verified third-party findings will be shared with maintainers of relevant open source projects. Anthropic has restricted Mythos 5 to vetted organizations because of the risk of abuse of its cybersecurity capabilities. Using Mythos 5 requires customers to accept a 30-day data retention for Anthropic to conduct security monitoring.

Payward will scan its software environment

The company plans to use artificial intelligence models to scan its software environment for vulnerabilities in the next few weeks. Scan results will enter Payward's existing security review process and will not automatically generate software changes. Payward also said it intends to disclose verified vulnerabilities that affect third-party open source projects to its defenders. The company did not specify targets for its first scans, did not publish a deployment timeline, or disclosed the cost of its Mythos 5 access.

Payward said Claude Mythos 5 will examine software vulnerabilities in all corporate environments. Its infrastructure supports digital asset trading, custody and settlement services, which need to remain continuously available. The announcement did not say whether Mythos 5 would gain access to production systems, isolated copies of source code or controlled test environments. Payward also did not say how its security team would verify the scan results before approving the fix.

False positives remain a real concern when artificial intelligence systems review complex software. Models may identify unreachable code, duplicate existing reports, or misunderstand how components behave in a production environment. Therefore, before the team classifies an issue as a vulnerability, a manual review is needed.

The Ethereum Foundation reached similar conclusions when testing AI security agents. Its researchers found that AI-generated vulnerability reports still require independent manual verification, especially when agents inspect complex protocol code. Arjun Sethi, co-CEO of Payward, said AI can change the imbalance between attackers and defenders by reading code on a large scale. "Models can read every line of code on a machine-scale like attackers can, so we can spot flaws before anyone builds a method to exploit them," he said. The statement described Payward's expected defensive advantages. The company has not released results showing how many effective vulnerabilities Mythos 5 found in its systems.

Project Glasswing is restricted to vetted partners only

Anthropic launched Project Glasswing in April 2026, aiming to give selected infrastructure providers and software maintainers early access to its strongest cybersecurity model. Initial participants include Amazon Cloud Services, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, Microsoft, Nvidia, Palo Alto Networks and the Linux Foundation. Anthropic later expanded the program to approximately 150 organizations in more than 15 countries.

Anthropic stated that participating organizations must meet security requirements before gaining access. Mythos 5 is not fully open because the same capabilities used to identify vulnerabilities can also help generate usable exploits. It has been previously reported that Anthropic restored access to Mythos only to censored U.S. organizations after the U.S. government lifted temporary export restrictions. The protected Claude Fable 5 model is reopened to a wider audience.

Payward said its access was obtained after the U.S. decided to allow Mythos 5 access to organizations that operate and secure critical infrastructure. Anthropic's official model page confirms that access has been restored to a group of U.S. organizations after obtaining government approval. Neither Anthropic nor the U.S. government have publicly designated all digital asset platforms as critical infrastructure. Payward's statement that such platforms "should be included on the list" represents the company's position rather than an official government classification.

Claude Mythos 5 combines defense and attack risks

Anthropic describes Claude Mythos 5 as its most capable model for cybersecurity and biological research. The model can examine code, identify weaknesses, suggest patches, and assist approved researchers in testing utilization paths. Early versions of Project Glasswing's Mythos Preview reportedly found more than 10,000 vulnerabilities classified as high or severe in widely used software. Anthropic's coordinated disclosure dashboard showed that as of May 22, 1596 vulnerabilities had been reported in 281 open source projects.

These numbers are Anthropic measurements and do not mean that every initial model finding is valid. Its dashboard records showed that of the 1900 candidate results reviewed by external security companies, the true positive rate was 90.8%. Anthropic said that independent manual classification remains a bottleneck. At the time of the dashboard update, only 97 of the listed findings had been patched upstream, while 88 had received public announcement identifiers.

This model can also create leverage components and combine them into attack chains. Anthropic cited this dual-use capability when explaining why Mythos 5 remains limited to approved partners. In related reports, researchers found that the Mythos class model can transform software defects into usable utilization chains. As a result, broader access rights will give attackers some of the same capabilities as defenders.

Open source discoveries will be submitted to maintainers

Payward said vulnerabilities discovered in shared third-party code will be sent to relevant project maintainers. The company describes the process as a way to protect other organizations that use the same software. Payward did not publish a coordinated disclosure policy for the program. Important and unanswered details include how long maintainers will have to patch the vulnerability, what findings Payward may make public, and how it will handle unresponsive items. Responsible disclosure typically requires researchers to verify vulnerabilities, contact defenders privately, and allow time to fix them before releasing technical information. A premature release may put exposed users at risk before the patch is available.

Payward has previously faced controversy over security research. It was previously reported that Kraken patched a deposit loophole that researchers used to withdraw nearly $3 million. The exchange recovered the funds after a public dispute with CertiK. The incident has nothing to do with Project Glasswing, but it illustrates why clear testing and disclosure rules are important. AI scans may increase the number of reported findings, creating additional work for security teams and maintainers.

What will happen next for Payward's AI security deployment

Payward plans to begin scanning its environment in the next few weeks. The next verifiable update will include identified vulnerabilities, completed patches, or public disclosures coordinated with affected open source projects. No performance goals were announced. Payward did not say at what frequency Mythos 5 would scan its systems, or whether the model would review new code before deployment. Anthropic requires Mythos 5 customers to accept a 30-day data retention for security monitoring. Payward did not say what codes or system information would be submitted, how sensitive data would be separated, and whether customer information would fall outside the scanning process. Currently, the confirmed progress is that Payward has joined Project Glasswing and plans to use Claude Mythos 5. Whether the model improves the company's security profile will depend on the quality of its discoveries, manual verification, and the speed of subsequent patches.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP