TLDR
- Kraken’s parent corporation Payward has become a member of Anthropic’s Project Glasswing, securing access to the Claude Mythos 5 AI cybersecurity platform.
- The crypto firm intends to conduct comprehensive vulnerability scans across its entire software infrastructure in the upcoming weeks.
- Confirmed security flaws discovered in third-party open-source projects will be reported to the appropriate maintainers.
- Since its April 2026 debut, Project Glasswing has grown to encompass approximately 150 participating entities spanning 15 nations.
- Access to Mythos 5 remains limited to approved organizations due to the model’s dual-use potential for exploit development.
The parent company behind cryptocurrency exchange Kraken, known as Payward, has officially joined Anthropic’s Project Glasswing initiative. This partnership grants Payward access to Claude Mythos 5, which represents Anthropic’s premier AI-powered cybersecurity defense tool.
On August 17, Payward made the announcement public. The organization intends to implement Mythos 5 throughout its technology stack in the weeks ahead to conduct comprehensive vulnerability assessments.
The Claude Mythos 5 system possesses the capability to analyze code at massive scale, detect security weaknesses, and recommend remediation strategies. Anthropic maintains tight restrictions on model access since these same features could potentially assist malicious actors in developing functional exploits.
The technological infrastructure operated by Payward enables continuous digital asset trading, custody operations, and settlement functions. According to the company, cryptocurrency platforms encounter security threats comparable to those facing other mission-critical financial systems.
According to Payward co-CEO Arjun Sethi, this AI model fundamentally shifts the cybersecurity landscape. “A model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit,” Sethi explained.
Results from these automated scans will be integrated into Payward’s established security assessment workflows. The company has not disclosed whether Mythos 5 will analyze active production environments or work with isolated code repositories.
Human Review Still Required
According to Payward, all AI-identified issues will undergo human verification before receiving official vulnerability status. False positive results remain a documented challenge when artificial intelligence systems analyze sophisticated software systems.
The Ethereum Foundation arrived at comparable conclusions during its internal AI security evaluations. Researchers determined that AI-generated vulnerability assessments still required separate human verification, particularly for intricate protocol implementations.
Payward has committed to reporting confirmed vulnerabilities found in external open-source dependencies to the respective project teams. However, the company has yet to release a formalized responsible disclosure framework or specify timelines for this coordination process.
About Project Glasswing
Project Glasswing was introduced by Anthropic during April 2026. Initial participants included major technology and financial firms such as Amazon Web Services, Apple, Cisco, Google, JPMorganChase, and Microsoft.
The program has grown substantially to include roughly 150 participating organizations representing over 15 different countries. Prospective members must satisfy stringent security criteria before obtaining access privileges.
According to reports, Anthropic’s previous Mythos Preview iteration identified over 10,000 vulnerabilities rated as high or critical severity in commonly deployed software packages. The company’s public disclosure portal indicated a 90.8% accuracy rate for confirmed findings, although only 97 documented vulnerabilities had received upstream patches by May 2026.
Payward received authorization following a U.S. government ruling that permitted Mythos 5 distribution to entities responsible for operating and securing critical infrastructure systems.
Anthropic mandates that Mythos 5 users agree to 30-day data retention protocols for security oversight purposes. Payward has not publicly specified which code repositories or system data will be transmitted during vulnerability scanning operations.
The company has not announced specific performance metrics or benchmarks. According to Payward, scan results will supplement its current security framework rather than trigger automatic code modifications.


