Over the summer, the Bitcoin swap service Boltz quietly shut down. The reason was unusual: attackers had started building exploits faster than the team could ship patches. The payment service PayPerQ described similar intrusions that looked less like the work of a person and more like an algorithm's. That backdrop sits behind Anthropic's newest tool.
On October 8, the company opened access to OSS Scanner — a free service that hunts for vulnerabilities in open-source code using its own top-tier models, including Claude Mythos. The shift from its earlier approach is significant: reports used to pass through human review and could sit for weeks; now they arrive the moment scanning finishes, with no human in the queue.
Crypto projects were among the first to apply, just a day after launch:
- Nethermind, which builds one of the major Ethereum clients, asked for a full repository scan;
- ZEUS, a self-custodial Bitcoin and Lightning wallet, wants its payment logic, private-key handling, and Lightning connections checked;
- VirtEngine, a decentralized cloud-computing marketplace built on the Cosmos SDK.
Anthropic screens applicants by how critical their infrastructure is, how many users depend on it, and how exposed it is to remote attacks — criteria that wallets and blockchain clients tend to satisfy by default. Over a six-month internal pilot, the system flagged 29,000 candidate issues, 6,000 of which were manually reviewed; of 97 high-severity findings across 48 projects, 85 held up as genuine and serious enough to disclose.
That doesn't mean the reports can be trusted blindly. Anthropic says projects must verify findings themselves before patching anything, and a dozen of the tested results turned out to be duplicates of bugs already known. The tool speeds up the search for holes — it doesn't do the actual fixing, which remains the slow, human-dependent step that attackers are currently exploiting fastest.



