Payward, the Wyoming-based parent company of cryptocurrency exchange Kraken, announced Monday that it has joined Project Glasswing, Anthropic's invite-only cybersecurity initiative, becoming the first major crypto exchange operator granted access to the program. The company plans to deploy Claude Mythos 5 — Anthropic's frontier model built to identify and help fix software vulnerabilities at scale — across its internal environments in the coming weeks.
Project Glasswing launched in April 2026 as a defensive coalition pairing Anthropic with organizations that operate critical infrastructure, including Amazon Web Services, Apple, Google, Microsoft and JPMorgan Chase. Anthropic's own account of the program says participants have already surfaced more than 10,000 high- or critical-severity vulnerabilities across member organizations' systems since launch, and the initiative has since expanded to roughly 150 additional participating organizations.
Why Payward Wanted In
Payward's pitch for access rested on the argument that crypto exchanges face security demands comparable to traditional critical financial infrastructure: they run continuously, hold liquid assets, and represent unusually lucrative targets for attackers. The company said Mythos 5's findings will feed directly into its existing security program, with vulnerabilities discovered in third-party open-source software shared back with the relevant maintainers rather than kept in-house.
Payward co-CEO Arjun Sethi framed the deployment as an attempt to rebalance a historically lopsided fight.
Security has always been an unfair game. An attacker needs to find one flaw. A defender has to find all of them, first, every single day. Frontier AI is the first thing that flips that asymmetry.
A Wider Industry Push
Related: Coldcard Wallet Attack Still Active as Pre-2026 Seeds Stay Compromised
Payward's move follows a broader scramble among crypto firms to secure access to Anthropic's most capable security tooling. More than 40 companies — including Coinbase, Block, BitGo and Ark Invest — signed an open letter earlier this year asking AI labs for expanded access to cyber-capable models, and Coinbase has separately been reported to be in talks with Anthropic over its own access to Claude Mythos. Anthropic has said access remains restricted for now to organizations that operate or defend critical infrastructure, with a broader rollout planned only as additional safeguards are developed.
For now, Anthropic's own research offers a reminder of why exchanges are moving quickly: the company has previously shown that AI agents can autonomously find and exploit smart contract vulnerabilities, generating millions of dollars in simulated losses in controlled testing. That dual-use risk — the same capability that helps defenders can, in principle, help attackers — is part of why access to Mythos 5 remains tightly vetted rather than broadly available.