The Kraken parent company Payward disclosed that it had joined Project Glasswing of Anthropic on 17 August and had been granted restricted access to Claude Mythos 5 for defensive cyber security purposes. The company plans to scanned its software environment in the coming weeks.

Anthropic limits Mythos 5 to an approved body, as such models can help to detect loopholes or can be used to generate available attack paths. According to Anthropic, clients using the model are required to accept data retention for 30 days for security monitoring.

Start scanning in a few weeks.

According to Payward, Claude Mythos 5 will be used to examine security weaknesses in the company ' s various software environments. These systems support operations such as digital asset transactions, hosting and settlement. According to the company, the problems identified in the model would enter the existing security review process and would not directly trigger code changes.

However, Payward did not indicate the first scanners, nor did he disclose the deployment schedule and access costs. Similarly, the company did not state whether the model would be exposed to the production system, a copy of the source code or the controlled test environment.

AI participation in code review continues to be a real problem. Models may mischaracterize unreachable code paths as loopholes or repeat existing problems. Therefore, the eventual existence of an effective loophole still needs to be manually verified. A similar conclusion was reached by the Etherwood Foundation when testing AI security agents.

Project Glasswing is open only to review bodies

Anthropic launched Project Glasswing in April 2026 and opened its network security model in advance to some infrastructure providers and software maintenance. The first participants included Amazon Web Services, Apple, Cisco, CrowdStrike, Google, JP Morgan Chase, Microsoft, Nvidia, Palo Alto Networks and Linux Foundation.

Anthropic has since extended the project to more than 15 countries and about 150 institutions. According to the company, participants must meet security requirements before they can be granted access. Only after the United States Government lifted its temporary export restrictions did Anthropic resume Mythos ' visits to United States institutions that were partially cleared.

Payward stated that the access was related to the United States allowing Mythos 5 to be opened to institutions that operated and protected critical infrastructure. However, the public information does not indicate that the United States Government has officially classified all digital asset platforms as critical infrastructure, and that the position of Payward has been expressed more generally.

Open source loophole will notify maintainer

Payward also indicated that if the results of the scan were to confirm the impact on the third-party open source project, the company would disclose the leak to the counterpart maintainer. However, the company has not yet published a complete coordinated disclosure policy, such as the length of time the maintainer can recover, which issues will be publicly disclosed, and how the project will be addressed if the projecter fails to respond.

Anthropic describes Claude Mythos 5 as one of its strongest models in the direction of cybersecurity and biological research, which can be used to check codes, identify weaknesses, recommend patches and assist approved researchers in testing the use path. Anthropic previously disclosed that the early version of Project Glasswing had found more than 10,000 high-risk or serious-level problems in commonly used software, but that the data did not imply that the model was initially found to be fully effective and that subsequent review by an external security team was still required.

Payward was also involved in security research disputes in the past. Prior to Kraken ' s repair of a filling gap, there had been open disagreement with the security company CertiK on the related testing and withdrawal of funds.

Additional information:Payward has not yet indicated the frequency of the scan nor has it disclosed whether the new code will be included in the review process before it is online. Follow-up verifiable progress included, inter alia, the number of identified gaps, the completion of repairs and coordinated disclosure with affected open source projects.