Invest2 publishersIndependently confirmed2 min readPublished
Nethermind and ZEUS seek Anthropic AI bug reports that skip human review
Nethermind and ZEUS applied for Anthropic's OSS Scanner a day after it launched, asking for AI scans of Ethereum client and Bitcoin wallet code. Anthropic had manually checked about 6,000 of the 29,000-plus flaws its models flagged, crypto.news reported, so the teams that get the reports have to judge them.
The Investor · Invest desk

What happened
- OSS Scanner sends reports to participating maintainers without the human verification step Anthropic uses in its existing disclosure process.
- In early testing, outside penetration testers checked 97 high-severity and critical findings across 48 projects, and 85 of them, about 88%, met Anthropic's disclosure standard.
- Nethermind asked for scans of its entire repository, while ZEUS wanted its app checked for weaknesses in payments, private keys and Lightning connections.
- None of the applicants' pull requests to the OSS Scanner repository had been merged when Cointelegraph published.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost Anthropic says reports can carry wrong severity ratings or flaws that do not fit a project's design, and small teams like ZEUS pay for each one in maintainer hours.
- constraint No test yet measures how the scanner does on lower-severity findings, so a project cannot know in advance how much of a report will hold up.
- decision Anyone weighing a protocol's security now has a specific question for its team: how many scanner findings were confirmed and patched.
Anthropic says it dropped the reviewer for speed. The company said manual review is slow, "so we're not always able to share vulnerabilities as quickly as we would like" [5]. About 23,000 candidate flaws are still waiting for review, roughly 79% of everything its models flagged [19][20]. OSS Scanner is the company's answer: reports go out as soon as a project's code is scanned [12].
Anthropic said the reports "will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage" [3]. In early testing, 12 serious findings failed the penetration testers' check, a miss rate of about 12% [18]. If that rate held across the 23,000 unreviewed findings, roughly 2,800 reports would fail Anthropic's own bar [21].
If approved, the crypto teams could get real bugs plus suggested fixes [13], for free [2]. They could instead get a stack of findings that fall apart once someone checks them. Or the requests could sit. Anthropic decides case by case, weighing a project's importance to infrastructure and user security, its exposure to remote attacks and how many users or projects depend on it [8]. It has not set a timetable for approving the crypto applicants or delivering their first reports [9].
I think an OSS Scanner application tells an investor what a team wants and little about how safe its code is. The crypto.news report described the filings as requests for participation, not confirmation that the projects have completed security audits [11]. The counter-case is reasonable. An 88% pass rate on serious findings [15] is high for machine output that no person has checked. A report that arrives with a proposed patch should also cost a maintainer less to verify than the bug would cost to find. I am wrong if the first crypto reports hold up at close to that rate, because then enrollment alone would predict real fixes.
Anthropic itself named speed as the risk. It warned that AI may favor attackers in the near term, because exploitation is getting cheaper while verifying and fixing flaws stays slow and dependent on people [17]. Boltz, a Bitcoin swap provider, suspended operations in August, saying attackers were developing exploits faster than its team could patch them [10].
What to watch
- Whether Anthropic merges the Nethermind and ZEUS pull requests, and how long first reports take to arrive after approval.
- The first published scanner report on Ethereum client or wallet code, and whether its findings survive the team's own review.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption12
- Hype gap+20
- Incentives50
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Ethereum developer Nethermind and Bitcoin wallet ZEUS applied for access to Anthropic's new AI security scanner, which uses Claude Mythos to identify software vulnerabilities.
- [2]
Anthropic launched the free OSS Scanner on October 8; the crypto applications were submitted on October 9.
- [3]
"These reports will be generated by our strongest models (including Claude Mythos) to give open-source projects the largest defensive advantage," Anthropic said in its announcement.
ReportedSupportedSource: Anthropic announcement, via Cointelegraph2 sources— create a free account to open themView cited source - [4]
In response to its review backlog, Anthropic introduced an automated system that sends reports directly to participating maintainers without human verification, unlike its existing disclosure process.
- [5]
Anthropic said it already scans open-source software and sends reports after human review, but the manual review process is slow "so we're not always able to share vulnerabilities as quickly as we would like."
ReportedSupportedSource: Anthropic, via Cointelegraph2 sources— create a free account to open themView cited source - [6]
Pull requests show Nethermind applied for audits of its entire repository, while ZEUS asked for its app to be examined for weaknesses affecting payments, private keys and connection to Lightning services.
ReportedSupportedSource: Cointelegraph2 sources— create a free account to open themView cited source - [7]
None of the OSS Scanner pull requests had been merged at the time of publication.
ReportedSupportedSource: Cointelegraph2 sources— create a free account to open themView cited source - [8]
Anthropic said projects will be assessed case by case, considering importance to infrastructure and user security, exposure to remote attacks and how many users or other projects depend on them.
ReportedSupportedSource: Anthropic, via Cointelegraph2 sources— create a free account to open themView cited source - [9]
Anthropic has not announced a fixed timetable for approving the crypto projects or delivering their first reports.
- [10]
Bitcoin swap provider Boltz suspended operations in August, saying attackers were developing exploits faster than its team could patch them.
ReportedSupportedSource: Cointelegraph2 sources— create a free account to open themView cited source - [11]
The applications remain requests for participation, not confirmation that the projects have completed security audits.
- [12]
OSS Scanner will deliver vulnerability reports to participating projects as soon as their code has been scanned.
ReportedSupportedSource: Cointelegraph2 sources— create a free account to open themView cited source - [13]
Anthropic said the service would use its strongest models, including Claude Mythos, to generate findings and suggested fixes.
ReportedSupportedSource: Anthropic, via crypto.news2 sources— create a free account to open themView cited source - [14]
Over the past six months Anthropic's models identified more than 29,000 candidate vulnerabilities in widely used open-source projects; researchers had manually reviewed approximately 6,000.
- [15]
During early testing, external penetration testers examined 97 high-severity and critical findings across 48 projects; 85, approximately 88%, met Anthropic's standards for coordinated vulnerability disclosure.
- [16]
Anthropic acknowledged some findings could be inaccurate, including incorrect severity ratings or vulnerabilities that do not apply to a project's security design.
- [17]
Anthropic warned that AI may favor attackers in the near term, as exploitation becomes cheaper while verifying and fixing vulnerabilities remains slow and dependent on people.
- [18]
12 of the 97 tested high-severity and critical findings failed Anthropic's disclosure standard, a miss rate of about 12%.
- [19]
Roughly 23,000 candidate vulnerabilities flagged by Anthropic's models had not been manually reviewed.
- [20]
About 79% of the flagged candidates were unreviewed.
- [21]
If the early-testing miss rate held across the unreviewed backlog, roughly 2,800 findings would fail Anthropic's bar.
Sources
2 independent publishers whose own reporting we read for this story.
- cointelegraph.comCrypto projects apply for Anthropic’s new frontier AI security scanner
1 article · October 8, 2026
- crypto.newsCrypto firms turn to Anthropic AI to find security flaws
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Open Source SecurityFollow
- AI Vulnerability ScanningFollow
- Crypto securityFollow
Entities
- BoltzFollow
- Claude MythosFollow
- ZEUSFollow
- OSS ScannerFollow
- NethermindFollow
- Project GlasswingFollow
- AnthropicFollow