Key Highlights
- Kraken’s parent company Payward has become part of Anthropic’s Project Glasswing initiative, securing access to Claude Mythos 5 AI cybersecurity technology.
- Payward intends to conduct comprehensive vulnerability scans across its entire software infrastructure in the upcoming weeks.
- Any confirmed security flaws discovered in open-source third-party software will be reported to the appropriate project developers.
- Since its April 2026 debut, Project Glasswing has grown to encompass approximately 150 organizations spanning 15 nations.
- Access to Mythos 5 requires rigorous vetting due to the model’s dual-use potential for both defensive and offensive cybersecurity applications.
Kraken crypto exchange’s parent entity Payward has secured membership in Anthropic’s Project Glasswing initiative. This partnership grants Payward access to Claude Mythos 5, representing Anthropic’s cutting-edge artificial intelligence solution designed for defensive cybersecurity operations.
The announcement came from Payward on August 17. According to the company’s statement, Mythos 5 will be implemented throughout its operational environments in the next several weeks to perform comprehensive software vulnerability assessments.
Claude Mythos 5 possesses the capability to analyze extensive codebases, detect security weaknesses, and recommend remediation strategies. Anthropic maintains strict control over model access since these same functionalities could potentially assist in developing functional security exploits.
The infrastructure maintained by Payward facilitates continuous digital asset exchange, custodial services, and settlement operations operating 24/7. According to the company, cryptocurrency platforms encounter security threats comparable to those facing other essential financial systems.
Arjun Sethi, Payward’s co-CEO, emphasized how the technology shifts the cybersecurity landscape. “This model analyzes code comprehensively like an attacker would, but at computational speed and scale, enabling us to discover vulnerabilities before malicious actors can weaponize them,” Sethi explained.
Results from vulnerability assessments will integrate into Payward’s established security evaluation procedures. The company hasn’t disclosed whether Mythos 5 will examine active production environments or work with segregated code repositories.
Human Validation Remains Essential
According to Payward, all AI-generated security findings must undergo human expert verification before receiving official vulnerability classification. Artificial intelligence systems analyzing sophisticated software are known to generate false positive results.
The Ethereum Foundation arrived at comparable conclusions through its independent AI security evaluation efforts. Researchers discovered that vulnerability reports produced by AI systems still require thorough human assessment, particularly when examining intricate protocol implementations.
Payward has committed to sharing confirmed vulnerabilities discovered in open-source third-party components with respective maintainers. However, the company hasn’t yet released a formal coordinated disclosure framework or specified timelines for this reporting mechanism.
Understanding Project Glasswing
Project Glasswing was introduced by Anthropic in April 2026. Initial participants featured major technology and financial institutions including Amazon Web Services, Apple, Cisco, Google, JPMorganChase, and Microsoft.
The program has subsequently grown to include roughly 150 participating organizations distributed across over 15 countries worldwide. Organizations seeking participation must satisfy stringent security criteria before obtaining access privileges.
According to reports, Anthropic’s earlier Mythos Preview iteration identified over 10,000 vulnerabilities rated as high or critical severity within commonly deployed software packages. The company’s public disclosure dashboard indicated a 90.8% accuracy rate for true positive findings among reviewed cases, although only 97 documented vulnerabilities had received upstream patches by May 2026.
Payward obtained access following a United States government authorization permitting Mythos 5 distribution to entities responsible for operating and protecting critical infrastructure systems.
Anthropic mandates that Mythos 5 users consent to a 30-day data retention period for security monitoring purposes. Payward hasn’t specified which code repositories or system data will be transmitted during vulnerability scanning operations.
The company hasn’t established specific performance metrics or targets. According to Payward, scan results will supplement its current security framework rather than triggering automatic code modifications.





