Home Crypto Crypto firms turn to Anthropic AI to find security flaws

Crypto firms turn to Anthropic AI to find security flaws

0
6
Crypto firms turn to Anthropic AI to find security flaws
Crypto firms turn to Anthropic AI to find security flaws

Crypto projects, including Ethereum developer Nethermind and Bitcoin wallet ZEUS, have applied to use Anthropic’s new AI security scanner to identify software vulnerabilities before attackers can exploit them.

Anthropic launched its free Open Source Software (OSS) Scanner on October 8. The service uses advanced AI models, including Claude Mythos, to examine code, identify potential security weaknesses and send reports directly to participating developers.

The applications from crypto projects show growing interest in using AI to protect software that handles blockchain transactions, private keys and digital asset payments.

The scanner is part of Anthropic’s wider effort to use AI for cybersecurity research. Unlike traditional security reviews, the service can send automated findings without waiting for a human to verify each report.

Crypto projects apply for AI security scans

Nethermind, which develops software used by the Ethereum network, submitted an application requesting security scans across its code repository.

The team could use the reports to identify potential weaknesses in its Ethereum execution client, which processes transactions and supports network operations. However, applying for access does not mean the project has already completed an audit or received approval from Anthropic.

Bitcoin and Lightning wallet ZEUS also applied for the service. Its request covers software related to payments, private keys and Lightning Network connections.

ZEUS is a self-custodial wallet, meaning users retain control of their Bitcoin rather than handing custody to a third party. Finding and fixing vulnerabilities in this type of software is particularly important because security weaknesses can put users’ funds at risk.

VirtEngine, a decentralized cloud computing marketplace built using the Cosmos SDK, also submitted an application.

Anthropic reviews applications individually, considering each project’s importance to infrastructure, exposure to remote attacks and the number of other systems that depend on its software.

crossorigin="anonymous">

The company has not announced when these crypto projects might be approved or when they would receive their first security reports.

Anthropic reports thousands of potential vulnerabilities

Anthropic said its AI models identified more than 29,000 potential vulnerabilities in widely used open-source projects over the previous six months.

The company had manually reviewed around 6,000 of those findings, leaving thousands more awaiting assessment.

To help manage that workload, Anthropic introduced an automated system that sends vulnerability reports directly to participating software developers. The scanner uses its strongest models, including Claude Mythos, to identify weaknesses and suggest possible fixes.

However, not every finding will be a confirmed security problem. Automated reports can contain incorrect severity ratings, duplicate known issues or flag code that does not create a genuine vulnerability.

Anthropic’s early testing showed promising results. External penetration testers reviewed 97 high-severity and critical findings across 48 projects. Of those, 85 met the company’s standards for coordinated vulnerability disclosure.

Eleven of the remaining findings were genuine issues that duplicated existing reports or known vulnerabilities, while one was invalid.

The scanner can provide examples showing how a weakness might be reproduced, explanations of the affected code and suggested patches where available.

Developers must still review the findings and decide whether changes are necessary. Anthropic will also continue its existing human-reviewed disclosure process for projects that cannot handle large numbers of automated reports.

Crypto security concerns are growing

The launch comes as blockchain companies face increasing pressure to identify and fix software weaknesses.

In August, Bitcoin swap provider Boltz suspended its services after reporting months of attacks that it described as AI-assisted. The company said attackers were identifying weaknesses faster than its team could investigate and repair them.

Boltz halted swap services on August 3 after several exploits. The team said its self-custodial design prevented customer funds from being exposed, although the incidents caused operational losses.

The shutdown also affected services that relied on Boltz infrastructure, including ZEUS, which temporarily disabled swap functionality. ZEUS separately took some infrastructure offline following a cybersecurity incident.

Another initiative, Bitcoin Red Team, reported identifying 4,962 potential vulnerabilities across 390 Bitcoin-related projects during around 30 hours of AI-assisted code reviews in August.

The review classified 720 findings as high or critical severity. Those findings still required verification before they could be treated as confirmed vulnerabilities.

Anthropic’s security work has also attracted larger crypto businesses. Payward, the parent company of Kraken, joined the Claude Mythos security program in August to examine its systems for potential weaknesses.

The company said it planned to scan its environments and share validated findings affecting third-party open-source projects with their maintainers.

Anthropic expands its cybersecurity program

The OSS Scanner is part of Anthropic’s broader cybersecurity initiative, announced on October 8 to help improve software security and protect critical infrastructure.

The company has also introduced a program focused on defending infrastructure such as power grids, transportation networks and industrial systems. Its partners include CrowdStrike, Accenture, Deloitte and Palo Alto Networks.

Approved open-source projects can receive regular security scans at no cost. Developers can apply through the OSS Scanner GitHub repository, but acceptance is not guaranteed.

Anthropic will consider whether a project plays a critical role in infrastructure or user security and whether its maintainers can review and address the reported issues.

For crypto developers, the service could provide another way to identify weaknesses in software handling transactions, private keys and blockchain infrastructure. However, the usefulness of its findings will depend on developers verifying the reports and fixing confirmed problems.