>
AI Frontier Post
AI News

Crypto devs rush to Anthropic's OSS Scanner on day one: Nethermind, ZEUS ask Claude Mythos to audit their code — no human review

Ethereum client developer Nethermind and self-custodial Bitcoin wallet ZEUS were among the first projects to file for Anthropic's free OSS Scanner — day-one applications for Claude Mythos-generated vulnerability reports sent with no human review.

Nethermind, the company behind one of the most widely used Ethereum execution clients, and ZEUS, a self-custodial Bitcoin and Lightning wallet, were among the first crypto projects to file enrollment requests for Anthropic’s OSS Scanner on Friday — just a day after the company launched the free, opt-in service for open-source maintainers.

Enrollment is GitHub-native: maintainers open a pull request in the anthropics/oss-scanner repository to nominate their project. Nethermind’s request — pull request #38, dated October 9 — asks for its entire repository to be scanned. ZEUS — pull request #47, also dated October 9 — wants its mobile app examined for weaknesses affecting payments, private keys, and connections to Lightning services. A third crypto applicant, VirtEngine, a decentralized cloud-computing marketplace built on the Cosmos SDK, filed its own request the same day.

The crypto requests were part of a much larger day-one wave. The newest hundred pull requests in the OSS Scanner repository were all opened on October 9, spanning AI assistants, agent-security tools, machine-learning infrastructure, developer tools, cloud storage, and energy-system controls. None of the requests had been merged at publication — these are applications, not completed audits. Anthropic assesses each case by case, weighing its importance to infrastructure and user security, its exposure to remote attacks, and how many other projects depend on it.

A geometric crystal resembling the Ethereum diamond being scanned by red security beams.
Nethermind asked for its full repository to be scanned. Illustration: AI Frontier Post.

No human review — by design

The service’s defining feature is speed. Anthropic already scans open-source software on a regular basis, but reports go out only after human review — a process the company says is too slow: “so we’re not always able to share vulnerabilities as quickly as we would like.” OSS Scanner removes the human from the loop, delivering reports as soon as code has been scanned.

The backlog explains why. Over the past six months, Anthropic’s models flagged more than 29,000 candidate vulnerabilities in widely used open-source projects, but researchers had manually reviewed only about 6,000. The bottleneck, the company says, is no longer finding bugs — it’s the human capacity to check the results.

Anthropic acknowledges the tradeoff: some findings may overstate severity or misunderstand a project’s security assumptions. In early testing, external penetration testers examined 97 high-severity and critical findings across 48 projects; 85 — about 88 percent — met the company’s standards for coordinated disclosure, 11 were genuine issues that duplicated existing reports, and one was invalid. Reports include reproducible examples, explanations of the affected code, and suggested patches where available — but maintainers must do their own triage. The company keeps its human-reviewed disclosure process for projects that can’t absorb the volume.

A smartphone emitting lightning bolts with a holographic shield above it.
ZEUS wants its app checked for weaknesses affecting payments, private keys, and Lightning connections. Illustration: AI Frontier Post.

Why crypto is first in line

Crypto developers have a concrete reason to move fast: attackers are already using AI against them. Bitcoin swap provider Boltz suspended operations in August, saying attackers were developing exploits faster than its team could patch them; ZEUS itself was affected, temporarily disabling swap functionality. That same month, the Bitcoin Red Team reported identifying 4,962 potential vulnerabilities across 390 Bitcoin-related projects in roughly 30 hours of AI-assisted review, with 720 classified high or critical — all still requiring verification.

Anthropic’s own forecast frames the urgency. The company warned Thursday that AI may favor attackers in the near term, because exploiting vulnerabilities has become cheaper while verifying, disclosing, and fixing them still depends on people. In two years, it expects AI to favor defense — but the near term is the dangerous stretch. For crypto maintainers, getting the defender’s models onto their code before the attackers’ is the rational move.

What happens next

Anthropic has announced no timetable for approving the crypto projects or delivering their first reports. If accepted, Nethermind gets recurring model-generated scans of its execution client — software that processes Ethereum transactions — and ZEUS gets repeated checks on the app holding users’ keys. The service is funded through Anthropic’s Defender Advantage Fund and follows Project Glasswing, an earlier effort to aim frontier models at real-world targets; OSS Scanner drops the human reviewer from the middle of the process.

The fine print: unvalidated findings carry no mandatory 90-day disclosure deadline (if Anthropic later validates a finding through its existing coordinated-disclosure process, a 90-day window can begin then), and projects can pause reports or opt out entirely. The program is built for teams that can already keep up with verified high and critical reports and still have capacity to chase ambiguous ones — a real staffing bar for volunteer-run open source. First in line, in other words, doesn’t mean first served.