Nethermind and ZEUS Sign Up for Anthropic's Free AI Bug Scanner
Two crypto projects just signed up for AI security audits — and neither of them is paying a cent.
Ethereum client developer Nethermind and ZEUS, a self-custodial Bitcoin and Lightning wallet, are among the first applicants to OSS Scanner, a program Anthropic launched to give open-source projects vulnerability reports from its most powerful models. The enrollment requests landed a day after the service opened.
What each report actually contains
Every scan returns a proof of concept showing how a bug could be exploited, plus a written explanation and a suggested fix where one exists. There is a catch: the reports are model-generated and sent without human review, so some will carry inaccuracies such as a wrong severity rating. Anthropic expects a true-positive rate above 90% and says it will keep improving both accuracy and fix quality over time. The service costs enrolled projects nothing.
Who applied, and what they asked for
Nethermind requested audits covering its entire repository. ZEUS asked for its app to be examined for weaknesses affecting payments, private keys and its connection to Lightning services. VirtEngine, a decentralized cloud computing marketplace built as a Cosmos SDK chain, applied as well. Developers of AI assistants, agent-security tools and machine-learning infrastructure are also in the queue, and none of the pull requests had been merged at the time of publication.
Why crypto teams are lining up
Crypto builders have spent this year getting hit by attackers who move faster than they can patch. Boltz, a non-custodial Bitcoin swap service, suspended operations in August after a rise in automated AI-assisted probing of its infrastructure. The protocol said it did not believe the asymmetry would reverse, and warned users not to expect swaps to resume soon. Its API stayed open to process refunds, and no user funds were ever at risk because the swaps are non-custodial.
Anthropic's own read is blunt: exploiting vulnerabilities has gotten cheaper, while verifying and fixing them stays slow and dependent on people. Its forecast is that AI favors defense within two years. Small crypto teams are betting they cannot wait that long.
How the queue gets decided
Anthropic says projects are assessed case by case, weighing how important they are to infrastructure and user security, how exposed they are to remote attacks, and how many other projects lean on them.