Payward joins Anthropic's AI cyber defence project
Tue, 18th Aug 2026 (Today)
Payward has joined Anthropic's Project Glasswing and is using Claude Mythos 5 in its cybersecurity work.
The move gives Payward's security team access to Anthropic's defensive AI model through a programme focused on protecting critical software used by large organisations.
Payward, the parent company of Kraken, will use Mythos 5 to scan its environments for software vulnerabilities. Any issues it identifies will feed into the company's existing triage and remediation process, where they will be verified, prioritised and fixed alongside findings from internal security teams and its bug bounty programme.
Anthropic created Project Glasswing to work with organisations responsible for infrastructure used by large numbers of people. Partners in the initiative have already uncovered thousands of security flaws classed as high or critical severity since the programme began, the group said.
Payward's admission follows a US decision to make Mythos 5 available to organisations that operate and defend critical infrastructure. Anthropic said participation has expanded beyond the programme's initial scope to include technology and finance groups.
For Payward, the programme adds another layer to a security operation in place for more than a decade. The company has maintained ISO 27001 and SOC 2 certifications for years and runs a bug bounty scheme that pays independent researchers to identify weaknesses.
Inside the business, red and blue teams test the company's systems on an ongoing basis. The red team probes for weaknesses as an attacker might, while the blue team focuses on detection, containment and hardening in response to what is found.
Open source focus
Findings affecting third-party open source software will be reported to project maintainers under responsible disclosure practices. That means flaws found during work with the Anthropic model may be passed upstream so patches can be made available more broadly across software used by crypto companies and others.
Payward said this reflects its emphasis on open source contribution and its view that shared code should be improved at source where possible. The approach could extend the impact of any discoveries beyond Payward's own systems.
Arjun Sethi, Co-chief Executive Officer of Payward, set out the company's view of the balance between attackers and defenders in software security.
"Security has always been an unfair game. An attacker needs to find one flaw. A defender has to find all of them, first, every single day. Frontier AI is the first thing that flips that asymmetry. A model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit," said Arjun Sethi, Co-chief Executive Officer of Payward.
Payward operates financial infrastructure used by millions of customers worldwide, making cybersecurity a central concern for the business. The company said the work it does on shared open source software beneath its products will be returned to maintainers so fixes can spread through the wider ecosystem.
"Millions of people run their financial lives on our infrastructure, and what we find in the shared open source code beneath it goes back upstream, so the entire ecosystem hardens with us. Defence has to compound as fast as offense. Anything slower is losing," said Sethi.
Broader backdrop
The announcement highlights how companies that manage financial and technical infrastructure are bringing AI tools into cyber defence. Anthropic's premise for Project Glasswing is that advanced models can identify exploitable weaknesses at a pace that may exceed most human researchers, increasing pressure on defenders to adopt similar tools before attackers do.
Payward said the model's output will not replace its existing security processes but will flow into them. That includes the review and repair processes already used for issues found by internal teams and external researchers.
The company also described itself as a financial infrastructure group built around a shared architecture that supports Kraken and other products, including NinjaTrader, Breakout, xStocks, Bitnomial and CF Benchmarks. In this case, however, the immediate significance is that one of the larger names in digital asset infrastructure is adding AI-based vulnerability discovery to its defensive security workflow.
Project Glasswing partners have surfaced thousands of software vulnerabilities classed as high- or critical-severity since the initiative launched, according to Anthropic.