Anthropic Launches “OSS Scanner” to Proactively Identify Code Vulnerabilities in Open-Source Projects
San Francisco, CA – Artificial intelligence company Anthropic has unveiled “OSS Scanner,” a new opt-in service designed to allow open-source software projects to request scans of their code for vulnerabilities using Anthropic’s most advanced AI models, including the undisclosed Claude Mythos. The initiative, launched on Thursday, October 9th, saw immediate interest from prominent cryptocurrency-related projects, with Nethermind, ZEUS, and VirtEngine submitting applications within the first 24 hours.
The move comes as the cybersecurity landscape faces increasing pressure from AI-assisted attacks, prompting projects to seek an edge in patching defensive gaps before malicious actors can exploit them.
A Faster Approach to Vulnerability Detection
OSS Scanner is an evolution of Anthropic’s previous Project Glasswing. Historically, Anthropic would periodically scan open-source software for vulnerabilities, but each discovery required a manual review before it could be reported, a process that proved to be slow. In an official announcement, Anthropic explained that the pace of manual review meant they “could not always share vulnerabilities as quickly as possible.” OSS Scanner aims to significantly shorten this defensive window by delivering scan reports directly to participating projects immediately after completion.
Early Adopters Seek Critical Audits
Among the first to apply is Nethermind, a developer of Ethereum client software, which has requested an audit of its entire codebase on GitHub. ZEUS, a Bitcoin and Lightning wallet, is seeking to identify weaknesses that could impact payments, private keys, and Lightning services. VirtEngine, a decentralized computing market built on the Cosmos SDK, is another applicant. Anthropic will evaluate each request on a case-by-case basis, considering the project’s infrastructure importance, exposure to remote attacks, and user dependency before deciding whether to accept the audit.
The Growing Threat of AI-Powered Attacks
The urgency behind these applications is underscored by several AI-assisted attacks that have occurred this year. In August, Bitcoin exchange service Boltz temporarily suspended operations after attackers developed exploits faster than the team could patch them. Crypto payment service PayPerQ has also reported multiple suspected AI-driven attacks.
These incidents align with a warning issued by Anthropic in a cybersecurity mission statement released concurrently with the OSS Scanner announcement: in the short term, AI’s balance tips toward the attacker. AI lowers the barrier to entry for launching attacks, while verifying and fixing vulnerabilities still relies on human effort and cannot keep pace. The decentralized nature of crypto infrastructure, the inability to enforce client upgrades, and its 24/7 remote accessibility make it particularly vulnerable in this asymmetric environment.
A Defensive Advantage in an Asymmetric Landscape
Anthropic positions OSS Scanner as a “defensive advantage,” leveraging its most powerful models to identify vulnerabilities that attackers might exploit in open-source projects. This direction resonates with the current sentiment in the crypto community. Ethereum researcher Justin Drake has repeatedly called for a “shelter-in-place” mode, expressing concerns that AI’s advancements in cryptography and vulnerability discovery could outpace defensive upgrade capabilities.
Structural Challenges and Future Outlook
However, OSS Scanner also highlights a structural issue: access to frontier AI models remains limited. The service is currently offered unilaterally by Anthropic and operates on an application and review basis, meaning not all projects will receive audit resources. As attackers gain access to AI capabilities through lower barriers, the long-term asymmetry will persist if defenders rely solely on the goodwill of a few AI companies to patch vulnerabilities.
Key questions for the crypto community moving forward include whether OSS Scanner will expand to offer access to more models or APIs for developers to conduct their own scans. It remains to be seen if other AI companies, such as OpenAI, Google, and xAI, will introduce similar services. The ultimate concern is whether AI-powered defense will become an exclusive “security privilege” affordable only to large corporations.



