Kraken parent Payward has joined Anthropic’s Project Glasswing, gaining access to Claude Mythos 5, a restricted AI model Anthropic built to find and help fix software vulnerabilities. The addition was reported within hours of each other on August 17 by CoinDesk, Crypto Briefing and Decrypt, all describing the same core move: Payward will point Mythos 5 at its own infrastructure and route findings into its existing security process.
The timing is what makes this more than routine vendor news. Decrypt reports that the announcement lands roughly a week after more than 40 Bitcoin and crypto companies — including Kraken itself, Ark Invest, Coinbase, Block and BitGo — signed an open letter organized by the Bitcoin Policy Institute, pressing Anthropic, OpenAI and other frontier labs to open trusted-access programs to qualified defenders. No outlet, including Decrypt, reports that Anthropic or Payward has explicitly tied the Glasswing selection to that letter. The sequence is documented; the causality is not.
According to CoinDesk, Payward intends to roll Mythos 5 out across its systems over the coming weeks, feeding results into its established security program. Crypto Briefing reports that scan results will move into Payward’s established triage and remediation process. Both CoinDesk and Decrypt report that vulnerabilities discovered in third-party open-source software will be disclosed to the relevant project maintainers, a practice Payward says could benefit other platforms running the same code.
Payward Co-CEO Arjun Sethi framed the value proposition in security terms familiar to the cyber industry. “Security has always been an unfair game. An attacker needs to find one flaw. A defender has to find all of them, first, every single day,” Sethi said, according to CoinDesk and Decrypt. “Frontier AI is the first thing that flips that asymmetry,” he added — a line also reported by Crypto Briefing, which carries an extended version of the quote in which Sethi says, “A model can read every line of code the way an attacker would, at machine scale, so we find the flaw before anyone can build the exploit.”
All three outlets agree on the basic facts: Payward has joined Project Glasswing, has access to Claude Mythos 5, will scan its own environments, and will disclose third-party open-source findings to maintainers. All three also agree Anthropic launched Project Glasswing in April 2026. On that spine, there is no disagreement to report — the divergence in this story is not about conflicting numbers but about which outlet had which piece of the wider picture.
CoinDesk is the only outlet to name Project Glasswing’s existing roster: Amazon Web Services, Apple, Google, Microsoft, and JPMorganChase. CoinDesk also alone reports that Payward is Wyoming-based, and attributes to Payward the claim that Mythos 5 became available to it after the U.S. government granted access to Mythos 5 for organizations that operate and defend critical infrastructure.
Crypto Briefing is the only outlet to detail what Mythos 5 is being layered onto. It reports that Payward’s existing program already includes dedicated red and blue teams, independent bug bounty researchers, and ISO 27001 and SOC 2 certifications — context that reframes Mythos 5 as an addition to a mature program rather than a first line of defense.
Decrypt is the only outlet to report the open-letter backstory in full, naming the Bitcoin Policy Institute as organizer and listing Kraken, Coinbase, Block, BitGo and Ark Invest among more than 40 signatories. Decrypt also reports that Mozilla said in April that Claude Mythos identified 271 vulnerabilities in Firefox during testing, and states that Payward is the first reported crypto company to join Project Glasswing and gain access to Claude Mythos 5. Decrypt further reports that Glasswing was expanded in June, and that Anthropic did not immediately respond to Decrypt’s request for comment.
Crypto Briefing and Decrypt both report that Glasswing partners have collectively identified thousands of vulnerabilities classified as high or critical severity, though neither outlet supplies a precise count.
Crypto exchanges have increasingly argued they should be treated as critical financial infrastructure facing the same AI-accelerated threat landscape as banks and cloud operators. CoinDesk’s reporting on Payward’s argument — that exchanges, custody systems and settlement rails run continuously and present attractive targets — fits that framing. What the three accounts together reveal is a possible feedback loop: an industry group demands access to frontier defensive AI, and within roughly a week, one of that group’s own signatories announces it has received exactly that access. Whether Payward’s selection was already in motion before the letter, or was accelerated by it, is not addressed in any of the three reports.
No primary document — a Payward press release, an Anthropic blog post, or the text of the Bitcoin Policy Institute letter itself — was available to any of the three outlets in this reporting; each account traces back to a company statement paraphrased independently by three newsrooms. The exact deployment timeline beyond CoinDesk’s “coming weeks” language is not specified. And whether other letter signatories — Coinbase, Block, BitGo, Ark Invest — have sought or received similar Glasswing access has not been reported by any outlet reviewed here.
Readers should watch for whether other signatories of the Bitcoin Policy Institute letter announce their own Glasswing access, whether Anthropic responds publicly to Decrypt’s outstanding request for comment, and whether Payward publishes any vulnerabilities or disclosures stemming from Mythos 5 scans, as it has said it will for third-party open-source code. Anthropic has said, according to CoinDesk, that it plans to expand access to Mythos-class cybersecurity capabilities as it develops safeguards for broader rollout — a process with no confirmed timeline in any of the current reporting.
Every fact above is attributed to one of these reports. Where they disagree, the article says so.