What to Know

  • Kraken parent Payward has joined Anthropic’s Project Glasswing, a cybersecurity initiative focused on the defensive use of restricted frontier AI models.
  • Payward has gained access to Claude Mythos 5, an artificial intelligence model designed to help find and fix software vulnerabilities.
  • The Wyoming-based company plans to deploy Mythos 5 across its environments in the coming weeks.
  • Findings from the deployment are expected to feed into Payward’s existing security program.
  • Payward said vulnerabilities discovered in third-party open-source software will be shared with the relevant project maintainers.
  • Project Glasswing includes major technology firms such as Amazon Web Services, Apple, Google, and Microsoft, as well as financial institutions such as JPMorganChase.
  • The move comes as AI is increasingly seen as both a defensive tool and a growing threat vector for crypto companies.

Payward Moves Frontier AI Into Crypto Security

Payward, the parent company of Kraken, has joined Anthropic’s Project Glasswing in a move that places one of crypto’s best-known exchange operators inside a cybersecurity initiative built around advanced artificial intelligence. The company’s participation gives it access to Claude Mythos 5, a frontier AI model designed for defensive security work, including finding and fixing software vulnerabilities before attackers can exploit them.

The development is notable because crypto platforms operate in an environment where security failures can have immediate and highly visible consequences. Exchanges, custody systems, wallet infrastructure, and settlement operations run continuously, making resilience a core requirement rather than a back-office concern. By using a model built to analyze code at scale, Payward is positioning AI as part of a broader defensive layer aimed at reducing the window between the existence of a flaw and its discovery by security teams.

Payward said it plans to deploy Claude Mythos 5 across its environments in the coming weeks. The company expects discoveries from that work to feed into its existing security program, suggesting the model will not operate as a standalone replacement for human security review, but as an additional tool for vulnerability discovery, triage, and remediation support.

What Project Glasswing Adds

Project Glasswing is Anthropic’s initiative that allows selected firms to use restricted frontier AI models to help secure critical software and infrastructure against cyber threats. The program already includes major technology companies such as Amazon Web Services, Apple, Google, and Microsoft, along with financial institutions such as JPMorganChase. Payward’s inclusion brings a crypto-native company into that circle, reflecting the degree to which digital asset infrastructure increasingly overlaps with broader financial technology and cybersecurity priorities.

Access to Claude Mythos 5 has initially been limited to organizations that operate or defend critical infrastructure. Payward said the move follows the U.S. government making Mythos 5 available to U.S. organizations involved in operating and defending critical infrastructure. Anthropic launched Project Glasswing in April 2026 and has since expanded it across technology and finance, while continuing work on safeguards for broader access to Mythos-class cybersecurity capabilities.

The restricted-access structure matters because the same capabilities that allow powerful AI systems to identify vulnerabilities can raise concerns if used without appropriate safeguards. A tool that can scan code quickly and reason about potential weaknesses may help defenders close gaps, but similar automation could also be misused by attackers seeking to accelerate discovery of exploitable bugs. Project Glasswing is therefore framed around carefully managed defensive deployment rather than open-ended release.

Open-Source Disclosure Could Benefit the Wider Ecosystem

Payward said vulnerabilities found in third-party open-source software will be disclosed to the relevant project maintainers. That approach could have implications beyond the company’s internal defenses because crypto infrastructure often depends on shared libraries, open-source tools, and widely used software components. When flaws are identified and responsibly disclosed upstream, patches can potentially benefit multiple projects and users rather than only one platform.

Open-source software is deeply embedded in digital asset infrastructure, from developer tooling to network services and internal systems. This creates both strength and risk. Public code can be scrutinized by many contributors, but vulnerabilities in widely adopted components can also propagate across the industry. A defensive AI model that helps identify such weaknesses may therefore produce ecosystem-level benefits if findings are handled through responsible disclosure channels and maintainers are given the opportunity to address issues before public exposure.

For crypto companies, the stakes are amplified by the direct connection between software security and asset protection. Even when a flaw does not involve blockchain consensus or private keys, weaknesses in supporting systems can still create operational risk, expose sensitive information, or enable social-engineering pathways. The broader security picture includes code quality, access controls, infrastructure hardening, monitoring, and incident response, all of which can be strengthened when vulnerability discovery becomes faster and more systematic.

AI Raises the Stakes for Crypto Defenders

AI is becoming an important force on both sides of the cybersecurity equation. For defenders, advanced models can help review code, identify patterns, explain vulnerabilities, and suggest fixes. For attackers, AI can lower the cost of searching for weaknesses, automating reconnaissance, generating convincing phishing content, and scaling social-engineering attempts. This dual-use nature is especially relevant to crypto, where successful attacks can be highly lucrative and where targets often include exchanges, custodians, decentralized applications, infrastructure providers, and individual users.

Crypto has long faced sophisticated adversaries, and the adoption of AI by attackers may make old problems faster and more persistent. Phishing messages can become more personalized and convincing. Malicious actors can automate parts of vulnerability research. Attack chains can be refined with less manual effort. As those risks grow, market participants and security teams are increasingly looking at AI not as an optional enhancement, but as a necessary defensive response to changing threat conditions.

Payward’s move reflects that broader race. Claude Mythos 5 is described as Anthropic’s most advanced model for defensive cybersecurity, with capabilities intended to analyze code at scale, identify vulnerabilities, and help developers fix them. In practical terms, such tools can support human experts by surfacing areas that deserve review, accelerating patch development, and adding another layer of scrutiny to complex codebases and infrastructure environments.

Critical Infrastructure Framing for Crypto Platforms

Payward has argued that crypto platforms face security challenges similar to other critical financial infrastructure. That framing centers on the operational demands of exchanges, custody services, and settlement rails. These systems are expected to remain available, process activity continuously, and protect assets and data in a threat environment where attackers only need one exploitable weakness while defenders must keep searching for all of them.

Payward co-CEO Arjun Sethi captured that imbalance by saying that security has always been an unfair game because an attacker needs to find one flaw, while a defender has to find all of them first, every single day. He said frontier AI is the first thing that flips that asymmetry. The comment reflects a growing belief among security leaders that advanced AI can help defenders move from reactive review toward more continuous and scalable vulnerability discovery.

That view does not eliminate the need for conventional cybersecurity discipline. AI-driven review still depends on sound engineering practices, careful validation, secure development workflows, and human judgment. Models can generate leads, identify suspicious patterns, and assist with remediation, but organizations still need processes to verify findings, prioritize fixes, test patches, and manage disclosure. The most effective use of AI in cybersecurity is likely to be integrated into existing security operations rather than treated as a complete replacement for expert teams.

Why This Matters for Crypto Markets

For crypto users and market participants, security remains a foundational issue. Confidence in exchanges and custody providers depends not only on liquidity, product access, and regulatory positioning, but also on the perception that platforms can defend against evolving cyber threats. A high-profile AI security deployment by Kraken’s parent company signals that major crypto firms are continuing to invest in defensive capabilities as attackers gain more advanced tools.

The broader market impact is less about a single model deployment and more about the direction of travel. If frontier AI becomes a standard part of security programs at major platforms, vulnerability discovery could become faster, patch cycles could improve, and open-source dependencies may receive more scrutiny. At the same time, the dual-use nature of AI means the industry may face a continuing escalation in which attackers and defenders both adopt more capable systems.

Anthropic has said it plans to expand access to Mythos-class cybersecurity capabilities as safeguards for wider use are developed. That suggests Payward’s participation may be part of a larger shift in how critical technology and finance organizations use frontier AI. For crypto, where software reliability and asset security are tightly connected, the defensive use of AI is likely to remain a central theme as platforms seek to stay ahead of increasingly automated threats.

Frequently Asked Questions (FAQs)

What did Payward announce?

Payward, the parent company of Kraken, joined Anthropic’s Project Glasswing and gained access to Claude Mythos 5, a frontier AI model designed to support defensive cybersecurity work by finding and helping fix software vulnerabilities.

What is Claude Mythos 5?

Claude Mythos 5 is Anthropic’s most advanced model for defensive cybersecurity. It is designed to analyze code at scale, identify software vulnerabilities, and assist developers in addressing security flaws.

What is Project Glasswing?

Project Glasswing is Anthropic’s initiative that gives selected organizations access to restricted frontier AI models for securing critical software and infrastructure against cyber threats.

How will Payward use the model?

Payward plans to deploy Claude Mythos 5 across its environments in the coming weeks, with findings feeding into the company’s existing security program.

Will Payward share vulnerability findings?

Payward said vulnerabilities found in third-party open-source software will be disclosed to the relevant project maintainers, which could help improve security across software used by the wider crypto ecosystem.

Why is AI important for crypto security?

AI can help defenders analyze code faster and identify weaknesses, but it can also help attackers automate vulnerability discovery, phishing, and social-engineering campaigns. That makes defensive AI increasingly important for crypto companies.

Which organizations are involved in Project Glasswing?

Project Glasswing includes technology companies such as Amazon Web Services, Apple, Google, and Microsoft, along with financial institutions such as JPMorganChase. Payward’s participation adds a major crypto company to the initiative.

Why does Payward compare crypto platforms to critical infrastructure?

Payward argues that exchanges, custody systems, and settlement rails operate around the clock and face security demands similar to other critical financial infrastructure, making proactive defense essential.

Photo by Brett Sayles on Pexels