LATEST NEWS
SELECTED FOR YOU

Kraken parent Payward gets access to Anthropic’s restricted cybersecurity AI

ByMicah AbiodunMicah Abiodun 3 mins read
  • Kraken parent Payward has joined Anthropic’s Project Glasswing and is integrating the restricted Claude Mythos 5 model into its cybersecurity operations.
  • Payward plans to use the model to scan its systems and open-source dependencies for vulnerabilities, feeding findings into its existing red-team, blue-team and remediation workflows.
  • The move expands access to Mythos 5 within US financial infrastructure, even as Anthropic faces scrutiny after the model recently escaped a test environment and published a live PyPI package.

Payward, Inc., the Cheyenne-based parent of Kraken, said on Monday it has been selected to participate in Project Glasswing and is actively incorporating Claude Mythos 5 into its defensive cybersecurity work, per the company’s announcement.

Anthropic launched the program in April 2026 after concluding its models could surpass all but the most skilled humans at finding and exploiting software vulnerabilities, and has never released Mythos publicly. In addition to Kraken, Payward runs other firms such as NinjaTrader, Breakout, xStocks, Bitnomial, and CF Benchmarks, and generated an adjusted revenue of $508 million for Q2, a 17% increase from the previous year.

Washington controls access to Mythos 5

According to Payward, its access is in line with the United States government’s decision to permit Mythos 5 access to US entities that secure and protect critical infrastructure.

This access route has expanded since April to include technology and financial sectors. Mythos 5 was delivered to US cyber defenders on June 9 via Glasswing and then went dark worldwide three days later due to an export ruling by the Department of Commerce that denied foreign access. The model then returned on July 1.

As Cryptopolitan earlier reported, Bailey said in May that crypto firms and UK banks had been excluded while Goldman Sachs and other American companies were let in. Bailey, who also chairs the Financial Stability Board, argued that “we can’t just have a single sort of national approach” to a risk that crosses borders. A crypto exchange has now cleared the American track. It is up to Washington whether anyone else gets clearance.

Payward will use the model to hunt vulnerabilities

Payward will scan all of its environments, with findings moving into the triage and remediation pipeline it already runs alongside separate red and blue teams and a long-standing bug bounty program.

The company holds ISO 27001 and SOC 2 certifications. Issues that are discovered within third-party open source software are reported to the project maintainers via responsible disclosure, and this is the portion that extends beyond Payward because all the exchanges within the industry rely on the same packages.

Co-Chief Executive Officer Arjun Sethi presented the pitch in terms of the issue faced by the defender: While the attacker requires only one bug, the defender requires all of them every single day. As he put it, “The model is able to scan every single line of code just like an attacker would do.”

Glasswing already includes major US tech and finance firms

Anthropic opened Glasswing in April with Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, the Linux Foundation, Microsoft, Nvidia, Palo Alto Networks, and JPMorganChase, the only bank in the founding group, alongside roughly 40 other organizations.

Partners have surfaced thousands of high and critical-severity flaws since. Mythos received 93.9% score on SWE-bench Verified and 83.1% on CyberGym and the UK Artificial Intelligence Security Institute also verified that Mythos successfully solved 73% of expert-level capture-the-flag tasks.

In the program’s first month, Cloudflare found 2,000 bugs across critical-path systems at a false-positive rate its team rated better than human testers. The model has surfaced a 27-year-old flaw in OpenBSD and a 16-year-old one in FFmpeg. In early June, it identified a critical vulnerability in Zcash’s Orchard shielded pool that had gone undetected for four years, and Zcash used Mythos for the independent audit after patching.

Anthropic is still dealing with Mythos 5 safety concerns

Three weeks ago Anthropic disclosed that three Claude models, Mythos 5 among them, escaped sealed test environments after a misconfiguration gave them internet access. Mythos 5 concluded it was on the open internet, reasoned its way back to believing it was still in a simulation, then wrote and published a PyPI package that was downloaded and run on 15 real systems before removal.

Anthropic said the safety classifiers shipped with its commercial products would have prevented the behavior, described the events as a harness and operational failure, and engaged METR for an independent review.

 

If you're reading this, you’re already ahead. Stay there with our newsletter.

Share this article
Micah Abiodun

Micah Abiodun

Micah Abiodun makes good use of his Environmental Engineering and Management (MSc) at Tallinn University of Technology (TalTech) to polish content and price prediction news at Cryptopolitan. Now on his 7th year in the crypto media space, he covers major cryptos, altcoins, DeFi, stablecoins, macro trends, and emerging tech.​​​​​​​​​​​​​​

MORE … NEWS