Kraken Parent Payward Joins Anthropic's Project Glasswing to Hunt Security Flaws With Claude Mythos 5
Key Takeaways
- •Payward, the parent company of Kraken, is the first reported cryptocurrency company to join Anthropic's Project Glasswing and gain access to the Claude Mythos 5 model for security work.
- •Vulnerabilities identified by Mythos 5 will be reviewed by Payward's security teams, and flaws found in third-party open-source software will be reported to the projects' maintainers.
- •Project Glasswing, launched in April and expanded in June, gives vetted organizations access to Anthropic's most capable cyber models, and its partners have uncovered thousands of high- or critical-severity vulnerabilities.
- •The announcement follows an open letter from more than 40 crypto companies, organized by the Bitcoin Policy Institute, demanding that frontier AI labs open trusted-access programs to qualified defenders.
- •Mozilla reported in April that Anthropic's Claude Mythos identified 271 vulnerabilities in Firefox during testing.

Kraken parent company Payward has joined Anthropic's Project Glasswing and will use Claude Mythos 5 to hunt for security flaws, becoming the first reported crypto company to join the project and gain access to the model.
Payward said Monday that Mythos 5 will scan its systems for vulnerabilities, with findings sent to its security teams for review and addressed through the company's existing security program.
"Selection gives Payward's security division early access to the same class of model, sharpening its ability to combat sophisticated software vulnerabilities and protect millions of customers across the globe," Payward wrote.
Flaws discovered in third-party open-source software will be reported to the projects' maintainers, the company said. Payward added that the approach could help protect its financial infrastructure and strengthen the open-source software used across the crypto industry. Much of that software is open by design — Bitcoin's reference client and Ethereum's node software are maintained as public projects — so fixes reported upstream flow to every platform and project that depends on them.
Project Glasswing is Anthropic's cybersecurity program, which gives vetted organizations access to the company's most capable cyber models for defensive security work. Launched in April and expanded in June, the program's partners have since uncovered thousands of high- or critical-severity vulnerabilities. Anthropic did not immediately respond to a request for comment from Decrypt.
The move follows an open letter sent last week to Anthropic, OpenAI, and other leading AI labs by more than 40 Bitcoin and crypto companies, including Kraken, Ark Invest, Coinbase, Block, and BitGo. Organized by the Bitcoin Policy Institute, the letter demanded that frontier labs open trusted-access programs to qualified defenders to help guard against threats, arguing that developers protecting open-source financial infrastructure need access to frontier AI to find and fix vulnerabilities before attackers can exploit them. The urgency behind that ask is rooted in the industry's track record: exchange breaches have repeatedly ranked among the largest digital thefts on record, including the February 2025 hack of Bybit, in which attackers drained roughly $1.5 billion in Ethereum — a theft US authorities attributed to North Korea's Lazarus Group.
The announcement comes amid growing evidence that AI models can be powerful tools for both finding and exploiting software vulnerabilities. In April, Mozilla reported that Anthropic's Claude Mythos identified 271 vulnerabilities in Firefox during testing. With Payward now inside Glasswing, the question the letter's signatories raised has a live test case: whether other crypto firms secure similar access, and whether the labs they petitioned expand their own trusted-access programs in response.
"Security has always been an unfair game. An attacker needs to find one flaw. A defender has to find all of them, first, every single day," Payward Co-CEO Arjun Sethi said. "Frontier AI is the first thing that flips that asymmetry. A model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit."