October 9, 2026
Anthropic has launched a free service that lets open-source projects get security scans from its strongest AI models — and the first applicants are already lining up, including crypto projects eager to have AI hunt for bugs in code that handles money. The new OSS Scanner, announced October 8 as part of Anthropic’s broader “Cyber Mission,” delivers fully automated vulnerability reports at no cost.
How OSS Scanner works
OSS Scanner is an opt-in service, inspired by Google’s OSS-Fuzz, that gives enrolled open-source projects periodic security scans from Anthropic’s most capable models, including Claude Mythos. Each report includes a self-contained proof-of-concept, an explanation with a code bisection where possible, and a candidate patch when one is available.
The key trade-off: reports are fully model-generated with no human review. Anthropic says that enables faster, more frequent scanning, but some reports will contain inaccuracies — such as a wrong severity rating. The company expects a true-positive rate above 90%, and projects without the capacity to triage findings will continue to receive human-verified reports under Anthropic’s coordinated vulnerability disclosure process. Maintainers enroll by submitting a pull request to Anthropic’s oss-scanner GitHub repository, with eligibility decided case by case.
The early results are genuinely impressive
To validate the service, Anthropic had expert penetration testers review 97 critical and high-severity findings across 48 projects: 85 (88%) met the bar for its disclosure process, 11 were real but duplicated known issues, and just one was a false positive. Over the last six months, Anthropic’s models flagged more than 29,000 candidate vulnerabilities, roughly 6,000 of which were manually reviewed and triaged.
Maintainer feedback, quoted in Anthropic’s announcement, is striking. wolfSSL’s Todd Ouska said that of the 74 reports received, all but two were valid — and five became official CVE entries. PostgreSQL’s Noah Misch said an unusually high fraction of findings uncovered real defects, with several fixes usable nearly as-is. OpenSSL’s Anton Arapov said the reports his organization received were as good as or better than those from human reviewers.
Who’s signing up first
According to CoinTelegraph, crypto projects were among the first to apply: Ethereum developer Nethermind requested full repository scanning, while Bitcoin wallet ZEUS asked for checks covering payments, private keys, and Lightning connections. Other applicants include AI-assistant developers, agent-security tools, and energy-system software.
OSS Scanner is the second leg of Anthropic’s Cyber Mission, alongside a Critical Infrastructure Defense Program backed by 11 founding partners — Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation — targeting power grids, water systems, and transportation networks. The effort builds on April’s Project Glasswing initiative, which committed up to $100 million in model usage credits to open-source security. Anthropic’s forecast: within two years, AI will favor defense over offense in cybersecurity.
Why it matters
Security is the AI application where the offense-defense balance matters most right now. Attackers are already using frontier models to find vulnerabilities faster — Anthropic is betting that giving defenders the same tools, for free, tips the scales. The crypto sign-ups make sense: code that holds money is the highest-value target in open source.
From the “everything AI, tested” angle: the numbers here are doing the heavy lifting — a 1-in-97 false positive rate and near-human parity per OpenSSL is the kind of evidence that moves this from marketing into real utility. The real test is whether small, under-resourced projects — the ones that can’t afford security teams — actually enroll and can act on the reports.
FAQ
What is Anthropic’s OSS Scanner?
A free, opt-in service that scans open-source repositories for security vulnerabilities using Anthropic’s strongest models, including Claude Mythos, and sends fully automated reports with proof-of-concepts and candidate patches.
Is it really free?
Yes. Anthropic says the service is kept free through its Defender Advantage Fund, and it’s separate from its paid Claude Security enterprise product.
Are the reports reliable?
Mostly. Anthropic expects a true-positive rate above 90%, and expert reviewers found 88% of a test batch met disclosure standards. But reports come without human review, so maintainers must verify before trusting a fix.
How does a project enroll?
Core maintainers submit a pull request to Anthropic’s oss-scanner GitHub repository; eligibility is based on the project’s impact on infrastructure and user security.
Sources: Unite.AI, Anthropic (red.anthropic.com), CoinTelegraph, CryptoNews.

