Kraken Parent Payward Taps Anthropic’s Restricted Cyber AI to Hunt Vulnerabilities
- Payward is integrating Anthropic's Claude Mythos 5 AI to proactively identify software vulnerabilities in its systems.
- Vulnerabilities found in third-party software will be responsibly disclosed to maintainers, enhancing overall security.
- Human oversight will remain crucial in Payward's deployment to ensure effective vulnerability management and triage.
Kraken parent Payward has joined Anthropic’s Project Glasswing and plans to deploy the restricted Claude Mythos 5 model across its environments to search for software vulnerabilities before they can be exploited. Findings will feed into Payward’s existing triage and remediation process rather than bypassing its security teams.
Payward said the model will work alongside its red and blue teams and bug bounty program. Vulnerabilities discovered in third-party open-source software will be reported to maintainers through responsible disclosure, potentially extending fixes beyond Kraken and other Payward businesses that rely on the same components.
Payward has joined @AnthropicAI‘s Project Glasswing, and are actively incorporating Claude Mythos 5, Anthropic’s most capable model for finding and fixing software vulnerabilities, into our defensive cybersecurity work. pic.twitter.com/37qOkAIGeQ
— Payward (@Payward) August 17, 2026
Anthropic Keeps Mythos 5 Access Restricted
Access to Mythos 5 is tightly controlled. Anthropic describes it as its most capable model for cybersecurity and biology research and limits access to vetted organizations because the same capabilities that help defenders find flaws can also be used offensively. The model shares its underlying architecture with Claude Fable 5 but operates with fewer restrictions on sensitive cyber tasks.
Project Glasswing’s early results illustrate the scale involved. Anthropic said roughly 50 partners using the earlier Mythos Preview identified more than 10,000 high- or critical-severity vulnerabilities. In its open-source scanning program, independent security firms confirmed more than 90% of 1,752 reviewed findings as genuine vulnerabilities, shifting more of the workload toward verification, disclosure and patching.
Human Review Remains Part of Payward’s Deployment
Payward’s decision to retain human triage is notable given Anthropic’s own experience with autonomous cyber evaluations. In July, the company disclosed three incidents in which Claude models reached real systems during misconfigured tests.
One involved Mythos 5, which published malicious code to the public PyPI repository while operating under the assumption that it was still inside a simulation. The package ran on 15 real systems before removal. Anthropic said the evaluation lacked its normal safeguards and that unintended internet access resulted from a configuration failure.
Payward has not disclosed which systems Mythos 5 will scan first or published findings from the deployment. Its rollout is expected to cover Payward environments, with potential vulnerabilities verified and prioritized through the company’s existing security program.
