
Kraken parent company Payward has officially joined Anthropic's Project Glasswing initiative, with its security team now incorporating Claude Mythos 5 into its defensive cybersecurity operations. According to Payward's latest announcement, the Wyoming-based company gained restricted access to Claude Mythos 5 on August 17, 2026, and plans to scan all Payward environments for software vulnerabilities within the coming weeks. This implementation represents a significant step forward from the company's earlier plans to deploy the model in the coming weeks, as reported by Payward. The company's infrastructure supports digital asset trading, custody and settlement services that remain available continuously, though the announcement does not specify whether Mythos 5 will receive access to production systems or isolated testing environments.
Project Glasswing represents Anthropic's initiative launched in April 2026, which provides restricted frontier AI models to selected organizations for securing critical software and infrastructure. As reported by Payward, the project already includes major technology companies such as Amazon Web Services, Apple, Google, and Microsoft, as well as financial institutions like JPMorgan Chase. The U.S. government made Mythos 5 available to U.S. organizations that operate and defend critical infrastructure, enabling Payward's participation. Partners in the initiative have since identified thousands of security flaws classified as high or critical severity, demonstrating the effectiveness of frontier AI in vulnerability detection. According to Anthropic, the project was launched after finding that advanced AI models could outperform nearly all humans at identifying and exploiting software vulnerabilities. The company later expanded Project Glasswing to approximately 150 organizations across more than 15 countries.
According to Payward's latest announcement, the company's security team is now actively using Claude Mythos 5 to scan Payward environments for software vulnerabilities at machine scale. The model's capabilities complement Payward's existing security infrastructure, which includes dedicated red and blue teams, independent bug bounty researchers, and ISO 27001 and SOC 2 certifications. Findings will enter Payward's existing security review process rather than automatically producing software changes, with the company not yet publishing a coordinated disclosure policy for the initiative. The company also intends to share vulnerabilities found in third-party open-source software with relevant project maintainers through responsible disclosure practices, potentially benefiting the broader cryptocurrency ecosystem. This approach aligns with Payward's argument that crypto platforms face security challenges similar to other critical financial infrastructure.
The partnership addresses growing cybersecurity threats in the cryptocurrency industry, where AI is emerging as a growing threat to crypto companies, giving attackers tools to find vulnerabilities faster and automate attacks. As reported by Payward, this raises the stakes for an industry already a frequent target for hackers, while fueling a race to deploy similar defensive technology. Kraken now joins the exclusive group of organizations with access to Mythos 5, which is considered too risky for unrestricted use due to its advanced cyber capabilities. Payward co-CEO Arjun Sethi emphasized that "security has always been an unfair game" and that frontier AI represents the first technology to "flip that asymmetry." According to Sethi, "A model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit." The initiative is intended to strengthen security across infrastructure serving millions of customers while contributing security improvements back to the broader crypto ecosystem.
The deployment faces practical challenges, as false positives remain a concern when AI systems review complex software. As reported by crypto.news, the Ethereum Foundation found that AI-generated vulnerability reports still required independent human validation, particularly when agents examined complex protocol code. Payward has not yet published performance targets or disclosed the cost of its Mythos 5 access, and the company did not specify how frequently the model will scan systems or whether it will review new code before deployment. Anthropic requires Mythos 5 customers to accept thirty-day data retention for safety monitoring, though Payward has not explained what code or system information will be submitted. The next verifiable updates will include confirmed vulnerabilities, completed patches or public disclosures coordinated with affected open source projects. Whether the model improves Payward's security will depend on the quality of its findings, human verification processes, and the speed of subsequent patches.