Payward joins Anthropic’s Project Glasswing to hunt software vulnerabilities with Claude Mythos 5

1 hour ago 21

Kraken’s parent company, Payward Inc., has joined a growing roster of major firms using Anthropic’s Claude Mythos 5 AI model to find and fix software vulnerabilities before hackers do. The announcement, confirmed on August 17, places one of crypto’s largest exchanges inside an invite-only cybersecurity initiative that has already flagged over 10,000 high or critical-severity flaws across participating organizations.

The program is called Project Glasswing, and it essentially gives vetted partners access to a version of Claude Mythos 5 with certain safety guardrails loosened specifically for security research.

What Project Glasswing actually does

Project Glasswing launched on April 7, 2026, as Anthropic’s structured approach to putting advanced AI in the hands of cybersecurity professionals. The concept is straightforward: let trusted organizations use Claude Mythos 5 to scan codebases, identify vulnerabilities, and report findings to the software maintainers responsible for patching them.

The initiative expanded significantly on June 2, when nearly 150 additional organizations were brought into the fold. The partner list reportedly includes heavyweights like AWS, Apple, and cybersecurity firm Tenable.

Claude Mythos 5 itself became available to certified cybersecurity users on June 9. What makes it distinct from standard Claude deployments is the lifted safeguards, allowing the model to reason about attack vectors, probe code for weaknesses, and simulate the kind of thinking a malicious actor might employ.

Why a crypto exchange cares this much about AI-powered security

Payward’s security team plans to use the AI model not just for internal code review but also to report discovered vulnerabilities back to the maintainers of the software they depend on. Exchanges rely on a sprawling ecosystem of open-source libraries, third-party integrations, and shared infrastructure, meaning a vulnerability in any of those dependencies can become an exchange’s problem very quickly.

The bigger picture for crypto security

The invite-only structure is deliberate. Anthropic clearly wants to avoid the scenario where its most capable model ends up being used by bad actors to find vulnerabilities for exploitation rather than remediation. Every participant goes through a vetting process before gaining access.

The company hasn’t yet shared specifics on the volume of vulnerabilities identified or the remediation timelines for reported flaws.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article