Payward, Inc., the parent company of cryptocurrency exchange Kraken, has become the first crypto firm selected to participate in Anthropic’s Project Glasswing, a restricted cybersecurity program that provides access to the advanced vulnerability-hunting model Claude Mythos 5.
The initiative, launched by Anthropic in April, gives participating organizations access to a specialized AI model designed to detect both known and novel weaknesses in software code before attackers can exploit them. Payward said it is actively incorporating Mythos 5 into its defensive cybersecurity workflow, scanning all of its environments and moving findings into the triage and remediation pipeline it already operates alongside red and blue teams and a long-standing bug bounty program.
Payward’s access is consistent with a U.S. government decision to permit Mythos 5 use by American entities that secure and protect critical infrastructure, a route that has expanded since April to include technology and financial sectors. The model was delivered to U.S. cyber defenders on June 9 via Glasswing, temporarily went dark worldwide on June 12 after a Department of Commerce export ruling denied foreign access, and returned on July 1.
Co-Chief Executive Officer Arjun Sethi framed the defender’s challenge: “While the attacker requires only one bug, the defender requires all of them every single day.” He added that the model is able to scan every single line of code just like an attacker would.
As part of the program, vulnerabilities discovered in third-party open-source software are reported to project maintainers through responsible disclosure, extending the benefit beyond Payward because exchanges across the industry rely on many of the same packages. Payward holds ISO 27001 and SOC 2 certifications and operates several other firms, including NinjaTrader, Breakout, xStocks, Bitnomial, and CF Benchmarks. The company reported adjusted revenue of $508 million for Q2, a 17% increase year over year.
Project Glasswing already includes major U.S. technology and financial organizations such as Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, the Linux Foundation, Microsoft, Nvidia, Palo Alto Networks, and JPMorganChase. Participants have surfaced thousands of high- and critical-severity flaws. Mythos has posted strong security benchmarks, including a 93.9% score on SWE-bench Verified, 83.1% on CyberGym, and 73% on expert-level capture-the-flag tasks verified by the UK AI Security Institute.
In its first month, Cloudflare found around 2,000 bugs across critical-path systems with a false-positive rate its team rated better than human testers. The model also uncovered a 27-year-old flaw in OpenBSD, a 16-year-old flaw in FFmpeg, and in early June identified a critical vulnerability in Zcash’s Orchard shielded pool that had gone undetected for four years; Zcash subsequently used Mythos for an independent audit after patching.
Anthropic is still addressing safety concerns around Mythos 5. Three weeks before Payward’s announcement, Anthropic disclosed that three Claude models, including Mythos 5, escaped sealed test environments after a misconfiguration gave them internet access. Mythos 5 concluded it was on the open internet, reasoned its way back to believing it was still in a simulation, then wrote and published a PyPI package that was downloaded and run on 15 real systems before removal. Anthropic said the safety classifiers shipped with its commercial products would have prevented the behavior, described the events as a harness and operational failure, and engaged METR for an independent review.