TL;DR
- Anthropic launched OSS Scanner, an opt-in service that gives open-source projects free vulnerability reports generated by its strongest AI models without prior human review.
- Nethermind, ZEUS and VirtEngine submitted enrollment requests, while Anthropic says the scanner can speed disclosure but may produce incorrect, duplicated or overstated findings.
- In testing, 85 of 97 critical or high-severity findings met Anthropic’s coordinated disclosure bar, highlighting signal while preserving the need for maintainer validation.
Crypto projects are moving to test Anthropic’s new OSS Scanner, an opt-in service giving eligible open-source maintainers security scans from the company’s strongest AI models at no cost. In its official launch, Anthropic said reports are delivered directly from models, including Claude Mythos, without human review. Nethermind, Bitcoin and Lightning wallet ZEUS, and cloud project VirtEngine submitted enrollment requests after launch. The appeal is speed: maintainers can receive potential vulnerabilities sooner, but they must also validate model-generated findings themselves. The rollout expands the role of Web3 security tools as AI-assisted auditing advances.
Frontier AI Moves Deeper Into Open-Source Security
Anthropic says OSS Scanner grew out of Project Glasswing, where its models scanned open-source software for weaknesses. Over six months, the company identified more than 29,000 candidate vulnerabilities but manually reviewed roughly 6,000, creating a disclosure bottleneck. Nearly 5,000 unverified reports were later sent directly to maintainers who requested everything available. OSS Scanner is designed to remove that human-review bottleneck for projects willing to accept raw model output and handle triage internally. The service complements the growing use of AI for vulnerability detection across crypto and open-source development.

Anthropic tested an early version across dozens of projects and asked penetration testers to review 97 critical or high-severity findings spanning 48 projects. Eighty-five, or 88%, met the bar for its coordinated vulnerability disclosure process. Of the remaining 12, 11 were real issues that duplicated known bugs or scanner findings, while one was invalid. The validation results suggest strong signal at the highest severity levels, but Anthropic explicitly warns that reports can still be wrong, duplicated or assigned inflated severity. That caveat matters for crypto teams considering frontier models after concerns over AI-driven smart contract vulnerabilities.
Enrollment is limited to eligible open-source projects with critical impact on infrastructure or user security, and Anthropic says applications are assessed case by case. Nethermind requested scanning for its full repository, while ZEUS sought review of code affecting payments, private keys and Lightning service connections. VirtEngine also applied, alongside projects outside crypto. None of the cited enrollment requests had been merged at publication. For crypto developers, the scanner offers earlier access to defensive analysis, but participation does not replace engineering review, remediation or coordinated disclosure. The demand also reflects concern that AI security asymmetry could favor attackers if defenders cannot match machine-speed vulnerability discovery.





