Kraken Parent Payward Gets Access to Anthropic AI to Hunt Security Flaws
Security

Kraken Parent Payward Gets Access to Anthropic AI to Hunt Security Flaws

August 18, 20263 min read

Payward, the parent company of exchange Kraken, has joined Anthropic's Project Glasswing and gained access to the Claude Mythos 5 model to hunt for vulnerabilities in its own code. The company announced the move on Monday, becoming the first reported crypto company to join the program. Access to tools like this had previously gone mostly to big tech firms rather than crypto market players.

What the Company Did

Payward will use Mythos 5 to scan its internal systems for vulnerabilities and send findings to its own security team for review. If the model finds a flaw in third-party open-source software, the company will report it to that project's maintainers instead of keeping the information to itself.

In its statement, the company said access to a model of this class sharpens its security division's ability to combat sophisticated software vulnerabilities and protect millions of customers worldwide.

The setup resembles a traditional bug bounty, but with a tool that works far faster than a human researcher. The model can check thousands of lines of code in the time it takes a staff engineer to review a single module. This is the first publicly confirmed case of a major crypto exchange openly acknowledging it uses an outside AI model to hunt for flaws in its own infrastructure, rather than relying solely on internal red-team work.

What Project Glasswing Is

Project Glasswing is Anthropic's program that gives vetted organizations access to its most capable cybersecurity models. Only a handful of tech companies outside Anthropic had access at first, and the June expansion opened the program to a wider set of organizations. According to Anthropic, partners in the program have already uncovered thousands of high- or critical-severity vulnerabilities.

Back in April, Mozilla researchers reported that Claude Mythos identified 271 vulnerabilities in Firefox during testing. That result became one of the arguments for the idea that AI models can effectively hunt for issues in large codebases.

Claude Mythos found 271 vulnerabilities in Firefox's code during testing at Mozilla, and that result is part of why crypto companies started pushing for access to the model.

Why the Industry Is Asking for AI Access

Payward's move follows an open letter sent last week to Anthropic, OpenAI, and other leading AI labs by more than 40 companies tied to Bitcoin and crypto. The letter was organized by the Bitcoin Policy Institute. Its authors argued that developers protecting open-source financial infrastructure need access to frontier models to find vulnerabilities before attackers do.

The companies' argument is backed by numbers. In just the first half of 2026, hackers pulled more than a billion dollars out of the crypto market, mostly through flaws in smart contracts and cross-chain bridges. In that environment, a speed advantage in finding vulnerabilities often marks the difference between a hack and none at all.

  • Ark Invest
  • BitGo
  • Block
  • Coinbase

Signatories also included representatives of major crypto exchanges alongside Kraken itself. Payward's co-CEO commented on the decision this way:

"Security has always been an unfair game. An attacker needs to find one flaw. A defender has to find all of them, first, every single day. Frontier AI is the first thing that flips that asymmetry: a model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit."

- Arjun Sethi, Payward Co-CEO, from a company statement, August 17, 2026

What Comes Next for Crypto and AI

The company's materials do not yet disclose how many vulnerabilities Payward has found with Mythos 5 or when to expect the first public results. Anthropic did not immediately respond to a request for comment.

What stands out is the fact itself: one of the major crypto exchanges has openly admitted it is handing part of its security work to an AI model instead of relying solely on its own team. For the rest of the market, that is likely a signal to take a closer look at similar programs.

Similar arrangements could well show up at other large players. Competition for access to the most capable AI models for infrastructure defense will likely only intensify, especially now that the first market participant has publicly confirmed this exact approach to vulnerability hunting.

Comments

Your email address will not be published. Required fields are marked *

or verify by email