Crypto Projects Apply for Anthropic OSS Security Scanner

Crypto Projects Apply for Anthropic OSS Security Scanner

Crypto infrastructure developers including Nethermind, ZEUS and VirtEngine have applied to join Anthropic’s newly launched OSS Scanner, a free service that uses the company’s strongest AI models to search open-source software for security vulnerabilities. The program is designed to accelerate vulnerability discovery by sending model-generated findings directly to maintainers without waiting for Anthropic’s normal human-review process.

According to Anthropic’s official OSS Scanner announcement, participating projects receive periodic scans using frontier models including Claude Mythos. Each report can contain a reproducer, vulnerability explanation and proposed patch when available. Unlike Anthropic’s coordinated vulnerability disclosure program, OSS Scanner reports are delivered without human validation and can contain false positives, incorrect severity assessments or incomplete fixes.

Crypto Infrastructure Projects Seek Early Access

Nethermind submitted an enrollment request on October 9 covering its entire Ethereum execution-client repository, including production projects, plugins and tools. Its application notes that the client processes untrusted peer-to-peer traffic, transactions, blocks and EVM bytecode, creating multiple remotely exposed security boundaries. The pull request remains an application rather than evidence that an Anthropic scan has already been completed.

ZEUS submitted a separate request for its self-custodial Bitcoin and Lightning wallet, which operates embedded Lightning nodes and can manage remote Lightning infrastructure. VirtEngine also applied, describing its software as a Cosmos SDK and CometBFT blockchain node handling escrow, settlement and identity workflows. All three applications were still open in Anthropic’s GitHub repository at the latest verified snapshot.

Anthropic says eligibility is assessed case by case, prioritizing established projects with substantial impact on infrastructure or user security. Factors include exposure to remote attacks and the number of users or downstream projects that depend on the software. Maintainer identity is also manually verified before enrollment, meaning submitting a GitHub pull request does not automatically grant access to the scanner.

The applications arrive as crypto developers face an increasingly asymmetric security environment. Concerns that AI can accelerate both exploit discovery and defensive analysis have already become part of the industry’s broader debate over AI-assisted cyber risk. Other ecosystems have responded by expanding structured security programs, including Solana’s STRIDE initiative. OSS Scanner addresses the discovery side of that problem, but remediation capacity remains with the maintainers receiving its reports.

29,000 Findings Show Scale and Verification Bottleneck

Anthropic says its models discovered more than 29,000 candidate vulnerabilities across open-source projects during the six months preceding the OSS Scanner launch. Its disclosure dashboard recorded 29,439 candidates and more than 6,000 findings reaching human triage or review stages. Those candidates should not be treated as 29,000 confirmed security flaws, because candidate findings are generated before validation.

The company says human review has become the principal bottleneck. Maintainers have already requested thousands of unverified reports from Anthropic rather than waiting for full triage, prompting the fast-track model behind OSS Scanner. Anthropic says early tests with dozens of projects produced hundreds of reports and included vulnerability chains capable of unauthenticated remote code execution. The new service effectively trades pre-delivery verification for speed, placing more responsibility on maintainers to determine which findings are real and which patches are safe.

That tradeoff is particularly material in crypto, where security bugs can expose keys, transaction execution or network infrastructure directly. Previous incidents involving compromised wallet software and bridge validation failures illustrate how small implementation weaknesses can translate into financial losses when vulnerable code reaches production. Faster discovery can reduce exposure only if maintainers can validate, prioritize and deploy fixes before attackers independently identify the same weakness.

Anthropic explicitly acknowledges the dual-use problem. Its strongest cyber capabilities can help defenders find vulnerabilities, but similar model capabilities can also reduce the cost and time required to develop exploits. For crypto projects applying to OSS Scanner, the measurable development is therefore access to faster automated vulnerability discovery, not proof that their code has become secure or that AI-generated auditing can replace human review.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px