📈 Get daily crypto insights that make you smarter about your money

Nethermind and ZEUS Apply for Anthropic Claude Mythos Security Scanner: What Free AI Audits Mean for Crypto Code

Ethereum client developer Nethermind and the Bitcoin Lightning wallet ZEUS are among the first crypto projects to apply for access to Anthropic’s newly launched AI security scanner, a free service that uses the company’s most capable models — including Claude Mythos — to find software vulnerabilities before attackers exploit them.

Anthropic launched the tool, called OSS Scanner, on October 8. It offers eligible open-source projects automated reports identifying possible security weaknesses, and by October 9 crypto developers had already submitted applications asking to be enrolled.

## What the crypto projects asked for

Nethermind, which develops an Ethereum execution client — the software that processes blockchain transactions and supports network operations — submitted its request through GitHub pull request #38 on Friday. The application asks for security scanning across the repository where its developers maintain the code used to interact with the Ethereum network.

ZEUS, a self-custodial Bitcoin wallet with Lightning Network support, submitted a separate application seeking checks on its mobile application and the components that handle payments, private keys and Lightning connections. For a wallet, those are exactly the code paths where a single flaw can cost users their funds, which makes automated continuous scanning materially different from a one-off audit.

A third blockchain-adjacent applicant, VirtEngine, a decentralized cloud computing marketplace built using the Cosmos SDK, requested enrollment through another GitHub submission. The project develops infrastructure for decentralized computing services.

The applications remain requests for participation, not confirmations that the projects have passed any review. Anthropic said it evaluates submissions individually, considering each project’s importance to infrastructure, its exposure to remote attacks and how many other systems depend on its software. Alongside the crypto applicants, developers of AI assistants, security tools, machine-learning infrastructure and cloud storage systems have also applied. Anthropic has not announced a fixed timetable for approving the crypto projects or delivering their first reports.

## Why Anthropic built it: a backlog of 29,000 findings

The service was born from a scale problem. Over the past six months, Anthropic said its AI models identified more than 29,000 candidate vulnerabilities in widely used open-source projects. Researchers had manually reviewed only about 6,000 of those findings, leaving a large backlog awaiting assessment.

The company’s answer was to remove the human bottleneck: OSS Scanner sends findings directly to participating maintainers, generated by its strongest models. “These reports will be generated by our strongest models (including Claude Mythos),” Anthropic stated in its announcement.

That design carries an explicit trade-off. Unlike conventional security audits, which involve manual review before anything is disclosed, OSS Scanner reports arrive without human verification. Anthropic acknowledged that some findings could be inaccurate — including incorrect severity ratings or vulnerabilities that do not actually exist. The program follows Anthropic’s earlier Project Glasswing initiative, which gave selected organizations access to powerful AI models for cybersecurity research, but Glasswing findings went through a different disclosure process.

## The crypto angle: code that holds the keys

For blockchain infrastructure, the appeal is obvious. Crypto software sits in the unusual position where bugs are directly monetizable: a flaw in a wallet’s key handling or a client’s transaction logic is not just a stability problem, it is an open vault. Traditional security audits are expensive, periodic and often scoped to a specific release — while the code keeps changing between audits.

Automated scanning inverts that model. Every pull request can, in principle, pass through a model that has been trained to recognize vulnerability patterns across thousands of projects. For a wallet like ZEUS that specifically wants its payments, private-key and Lightning code paths checked, the value proposition is continuous coverage of precisely the components an attacker would target.

The caveat is the false-positive problem Anthropic itself flagged. Security teams at crypto projects already drown in noisy tooling output, and a scanner that produces unverified findings at scale risks burying real issues in a pile of speculative ones. How Nethermind and ZEUS triage the reports — and whether the models’ findings hold up against manual review — will determine whether AI scanning becomes standard practice for blockchain infrastructure or another alert stream to mute.

## A broader shift in security economics

The applications point to a larger trend: AI-assisted security is moving from research demo to operational tooling. When a single vendor’s models surface tens of thousands of candidate vulnerabilities in six months — far beyond what the human audit industry could review — the economics of software security change. Open-source projects that could never afford repeated audits get a form of coverage that was previously reserved for well-funded companies.

For the crypto industry, whose security failures are public, expensive and reputationally catastrophic, free access to frontier-model vulnerability scanning is an easy bet. The Nethermind and ZEUS applications are unlikely to be the last ones from the blockchain world.

26 thoughts on “Nethermind and ZEUS Apply for Anthropic Claude Mythos Security Scanner: What Free AI Audits Mean for Crypto Code”

  1. free AI audits sound great until everyone starts trusting the badge instead of reading the report. still, Claude catching vulns humans missed on Poly-level code would be a net win for the space

    1. agreed on the badge risk. Nethermind running it on ZEUS is the real test, their SOPs were rock solid so if the scanner finds anything new there it actually means something

      1. the funny part is audit firms charging 100K will have to compete with a free model that never gets tired. consolidation among auditors incoming

        1. 100k audits already survived static analyzers and formal verification, they will survive this too. what actually dies is the mid tier rubber stamp shop

          1. mid tier shops dying is the real headline. VirtEngine applying day one tells you even cosmos sdk teams know their deps are held together with tape

      2. ZEUS is a solid testbed, real codebase and no incident history. a clean run there and the badge starts meaning something

    2. the funny part is audit firms charging 100K will have to compete with a free model that never gets tired. consolidation among auditors incoming

      1. the 100k shops wont die, they become the insurance layer. scanner output plus human signoff is the obvious endgame and clients pay for the signature

  2. claude catching what humans missed on poly level code is the only benchmark that matters. until then a free audit is just a nicer linter with a chat window

    1. the linter take misses the main thing, its continuous. an audit is a snapshot from march, this runs on every PR. different product entirely

      1. exactly, march snapshot vs every PR is the whole delta. the nethermind repo takes thousands of commits a year, no human audit covers that surface

        1. thats the killer point. zeus merges weekly, a march audit is ancient history by october. continuous scanning is the only audit cadence that matches how fast these repos move

    2. even a linter that reads intent catches the approval bypass class that static tools skip. free upside is free upside, weird thing to be cynical about

      1. the intent reading part is the actual moat. static tools flag the pattern, a model that follows state through three contract calls catches that the approval bypass is actually reachable. different failure class entirely

        1. this is the part skeptics miss. mythos reads the code path, slither reads the syntax. a guard that looks fine but unwinds wrong across a delegatecall only shows up when you follow intent through the call

  3. PR 38 being nethermind is the tell. execution client code is the highest stakes repo in crypto, if the scanner comes back clean there the badge buys real credibility on day one

    1. the badge only buys credibility if the reports end up public though. nethermind could run the scanner, get a clean sheet, and nobody outside the org ever sees the findings. silent audits are marketing

      1. agree on the silent audit risk. ZEUS already publishes scanner findings on github, so if the mythos badge comes with a public report link its fine. if not its just a logo on the docs page

        1. the badge is only worth the report link attached to it. ZEUS publishing scanner output per PR turns marketing into infrastructure, otherwise its a logo

      2. exactly, zeus already publishes their lightning audits. if they post the scanner output next to those this badge means something, if not its just marketing

        1. ^ exactly. publish the full report including the false positives or it means nothing. 29k findings in six months means triage is the hard part, not the scanning

          1. 29k findings in six months means the bottleneck was never scanning, its triage. the model that reads intent only matters if someone actually reads the output

    2. if the nethermind execution client scan comes back clean and public, every L2 applies within a month. PR 38 is basically the industry benchmark

  4. free audits from the same class of model that writes half the new contracts anyway. the scanner finding bugs in ai generated code is a neat little ouroboros

    1. the ouroboros point is even funnier when you realize half the bugs it will catch live in ai written contracts. snake audits its own tail

  5. execution client code is the right first target, if the scanner comes back clean on nethermind the signal is real. poly level catches were the warmup act

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$82,982.00+0.6%ETH$2,505.91+1.0%SOL$110.19+1.1%BNB$750.23+1.1%XRP$1.41+1.1%ADA$0.2538+5.6%DOGE$0.0860+1.0%DOT$1.26+3.8%AVAX$10.47+1.6%LINK$13.08+2.0%UNI$7.57+4.0%ATOM$1.93-4.7%LTC$64.01+0.6%ARB$0.1881+4.1%NEAR$5.37+12.2%FIL$1.13+4.3%SUI$1.12+5.3%BTC$82,982.00+0.6%ETH$2,505.91+1.0%SOL$110.19+1.1%BNB$750.23+1.1%XRP$1.41+1.1%ADA$0.2538+5.6%DOGE$0.0860+1.0%DOT$1.26+3.8%AVAX$10.47+1.6%LINK$13.08+2.0%UNI$7.57+4.0%ATOM$1.93-4.7%LTC$64.01+0.6%ARB$0.1881+4.1%NEAR$5.37+12.2%FIL$1.13+4.3%SUI$1.12+5.3%
Scroll to Top