Loading prices…
STKR NewsSTKR News0 of 3 free this month
AI

Kraken Parent Payward Joins Glasswing, Gets Access to Claude Mythos to Hunt Security Flaws

Kraken's parent company is tapping into Anthropic's private Glasswing initiative, using a specialized Claude model to find vulnerabilities before the bad guys do.

Originally on Decrypt
AB

Adrian Boysel

Contributor

Aug 17, 2026

4 min read

Photo illustration / STKR News

The Defensive AI Arms Race

In the crypto world, security isn't just a feature; it is the entire product. If your exchange goes down or your keys are compromised, your brand is dead. That is why Payward, the entity behind Kraken, just announced it is joining Anthropic's Project Glasswing. They are getting their hands on a specialized AI model called Claude Mythos, specifically tuned to hunt for security flaws.

For those of us building in this space, this isn't just another corporate partnership announcement. It is a signal that the tools we use to defend our code are finally catching up to the tools hackers have been using for the last eighteen months. We have seen how generative AI can be used to write malicious scripts or social engineering emails. Now, we are seeing the defense industry put some weight behind the counter-move.

What is Project Glasswing?

Project Glasswing is Anthropic's attempt to provide a controlled environment for high-stakes security testing. Instead of just using the public version of Claude that you use to write emails or summarize whitepapers, Glasswing members get access to "Mythos." This is a model designed with higher reasoning capabilities specifically for vulnerability research.

The goal here is simple but difficult: identify software vulnerabilities that human auditors might miss. By giving a company like Kraken access to these tools, Anthropic is essentially crowdsourcing the stress-testing of their most powerful defensive AI models. If Mythos can find a zero-day flaw in an exchange as mature as Kraken, it proves the model’s value.

The Founder's Dilemma: Trust vs. Verification

As a founder, I am always skeptical when a company says "AI will fix our security." Security is a process, not a product. However, the logic here is sound. We are reaching a point where the sheer volume of code in a modern exchange is too large for human eyes to audit in real-time. Continuous integration needs continuous auditing.

Kraken has always been one of the more transparent players when it comes to security, often highlighting their Proof of Reserves and internal red-teaming. By bringing in Claude Mythos, they are adding an automated red-team layer that works at machine speed. For builders, the takeaway is that "security by obscurity" is officially dead. If an AI can read your code and find a hole, a hacker will eventually do the same.

Why Claude Mythos Matters

  • Context Window: Security audits require looking at thousands of files simultaneously to see how data flows. Claude's large context window is uniquely suited for this.
  • Reduced False Positives: Traditional static analysis tools often flag things that aren't actually bugs. A reasoning model like Mythos is supposed to understand the intent behind the code.
  • Speed to Remediation: Finding a bug is half the battle; knowing how to patch it without breaking the rest of the stack is the other half.

The Skeptical Take: Is This Just PR?

We have to ask: does this actually make users safer, or is it just a way to look proactive? In the short term, it probably helps. But there is a risk of over-reliance. If developers start trusting the AI to catch their mistakes, they might get lazy with their own manual reviews. Security teams must treat Claude Mythos as a junior auditor—talented, fast, but still prone to hallucinations or missing the forest for the trees.

Furthermore, Anthropic is being very selective about who gets into Project Glasswing. This creates a divide between the "haves" who can afford these advanced defensive tools and the "have-nots"—the smaller startups and decentralized protocols that are often the most vulnerable. If the best defensive AI stays behind a gated garden, the broader ecosystem remains at risk.

The Impact on the Crypto Build-Cycle

If you are building a dApp or a new protocol right now, you should be looking at how to integrate similar workflows. You don't need a direct invite from Anthropic to start using LLMs for code review. While you won't have the specialized Mythos model, the current frontier models are already surprisingly good at spotting common logic errors in Solidity or Rust.

The shift we are seeing with Kraken is the move from "periodic audits" to "autonomous defense." In a few years, I expect this to be the standard. You won't just ship code to a repo; you will ship it to an AI gatekeeper that attempts to exploit it before the PR can even be merged.

"The goal isn't just to find bugs, it's to change the economics of the attack. If it costs more to find a flaw than the flaw is worth, you've won."

Final Thoughts for Builders

Kraken joining Glasswing is a smart move for their brand and their safety, but for the rest of us, it is a wake-up call. The tools for breaking things are getting better every day. If you aren't using the same level of technology to protect your users, you are falling behind. Don't wait for a specialized model to be handed to you. Start building AI-driven testing into your CI/CD pipelines today. The defense must be as innovative as the offense.


Read the original at Decrypt →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses