Crypto wallets ask Anthropic's AI to find holes in their code

iEXExchanger
Crypto wallets ask Anthropic's AI to find holes in their code

Anthropic launched a free AI scanner, OSS Scanner. Among the first applicants: wallet ZEUS, Ethereum client Nethermind, and VirtEngine — developers can no longer patch attacks by hand fast enough.

Over the summer, the Bitcoin swap service Boltz quietly shut down. The reason was unusual: attackers had started building exploits faster than the team could ship patches. The payment service PayPerQ described similar intrusions that looked less like the work of a person and more like an algorithm's. That backdrop sits behind Anthropic's newest tool.

On October 8, the company opened access to OSS Scanner — a free service that hunts for vulnerabilities in open-source code using its own top-tier models, including Claude Mythos. The shift from its earlier approach is significant: reports used to pass through human review and could sit for weeks; now they arrive the moment scanning finishes, with no human in the queue.

Crypto projects were among the first to apply, just a day after launch:

  • Nethermind, which builds one of the major Ethereum clients, asked for a full repository scan;
  • ZEUS, a self-custodial Bitcoin and Lightning wallet, wants its payment logic, private-key handling, and Lightning connections checked;
  • VirtEngine, a decentralized cloud-computing marketplace built on the Cosmos SDK.

Anthropic screens applicants by how critical their infrastructure is, how many users depend on it, and how exposed it is to remote attacks — criteria that wallets and blockchain clients tend to satisfy by default. Over a six-month internal pilot, the system flagged 29,000 candidate issues, 6,000 of which were manually reviewed; of 97 high-severity findings across 48 projects, 85 held up as genuine and serious enough to disclose.

That doesn't mean the reports can be trusted blindly. Anthropic says projects must verify findings themselves before patching anything, and a dozen of the tested results turned out to be duplicates of bugs already known. The tool speeds up the search for holes — it doesn't do the actual fixing, which remains the slow, human-dependent step that attackers are currently exploiting fastest.

Questions and answers

Frequently asked questions about this article

What is Anthropic's OSS Scanner?

It's a free service Anthropic launched on October 8, 2026, that scans open-source code for vulnerabilities using its own top-tier models, including Claude Mythos, delivering a report immediately after the scan without human review.

Which crypto projects applied for a scan?

Nethermind, the developer of an Ethereum client, which requested a full repository scan; ZEUS, a self-custodial Bitcoin and Lightning wallet, seeking checks on payment logic and key storage; and VirtEngine, a decentralized cloud-computing marketplace on the Cosmos SDK.

Why did crypto services turn to an AI scanner right now?

Because of a surge in attacks developers link to AI: the Bitcoin swap service Boltz halted operations in August 2026 after falling behind on patching exploits, and the payment service PayPerQ reported similar intrusions. A free, fast AI audit is seen as a way to close that speed gap.

Can the AI scanner's findings be fully trusted?

No — Anthropic explicitly requires projects to verify reports themselves before applying any fixes. In the tested sample of confirmed findings, about a dozen turned out to be duplicates of already known bugs, underscoring the need for manual verification.