Frontier AI Is Splitting Crypto Security Into Haves and Have-Nots
Coinbase and a handful of others have Anthropic's restricted Mythos model in hand for cyber defense. Binance, Fireblocks, and Uniswap say they're still waiting — while AI-assisted exploits keep climbing.
By Jane Doe
Published on Aug 4, 2026
Quick Take
- Anthropic restricts its most cyber-capable model, Mythos, to a vetted group under a program called Project Glasswing — Coinbase, FIS, and HackerOne have confirmed access; Binance, still the largest exchange by volume, has not.
- OpenAI runs a similar split: verified defenders get "Trusted Access for Cyber" on GPT-5.5, while a more permissive GPT-5.5-Cyber is reserved for a smaller authorized pentesting group.
- Security executives largely accept restricted access as a reasonable starting point but argue the case weakens as open-source models close the capability gap.
- Two firms — Boltz and Coinkite — reported AI-linked exploit activity this month, underscoring the urgency defenders cite.
What Happened
A widening gap has emerged in who gets to use the most powerful available AI models for cybersecurity work — and crypto firms, which secure billions of dollars in digital assets, are largely on the outside looking in.
Coinbase said in June it had gained access to Anthropic's restricted Mythos model. Zcash's Zooko Wilcox said Anthropic separately used Mythos to audit the Zcash protocol at the request of Shielded Labs. Beyond that, access appears thin. Binance — the largest crypto exchange by daily trading volume — has not secured it despite reportedly pushing through multiple channels.
Anthropic's setup mirrors a broader industry pattern. Mythos 5 reportedly runs on the same underlying model as Anthropic's publicly available Fable 5, minus the guardrails that limit sensitive cybersecurity work. OpenAI operates a comparable split: verified defenders can use GPT-5.5 through a "Trusted Access for Cyber" track, while a more permissive GPT-5.5-Cyber variant is kept for a smaller, vetted group doing authorized penetration testing.
Anthropic's gated pathway for this kind of access is called Project Glasswing — described as a program for giving vetted cyber defenders and organizations tied to critical software infrastructure early access to restricted Mythos models. Payments-infrastructure firm FIS said it joined last month, and bug-bounty platform HackerOne said it joined too, though HackerOne's Glasswing testing is limited to its own infrastructure rather than its exchange clients' bug-bounty programs.
Other major players describe a longer wait. Custodian Fireblocks said in April it had sought Mythos access and, at the time, was still relying on Anthropic's publicly available model for pentesting. Uniswap founder Hayden Adams criticized Fable 5's cybersecurity-related prompt restrictions in June. The Ethereum Foundation said in July it is running "coordinated AI agents" to hunt for bugs across its systems but did not disclose which models it uses.
Who has access, who doesn't
| Organization | Stated status |
|---|---|
| Coinbase | Confirmed access to Mythos (as of June) |
| Zcash / Shielded Labs | Mythos used by Anthropic to audit the Zcash protocol |
| FIS | Joined Project Glasswing (last month) |
| HackerOne | Joined Project Glasswing; testing limited to own infrastructure |
| Binance | No access; says it has pursued it through multiple channels |
| Fireblocks | Sought access in April; was using public model as of then |
| Uniswap | Founder criticized restrictions on Fable 5; access unconfirmed |
| Ethereum Foundation | Running AI bug-hunting agents; models undisclosed |
Why It Matters
Crypto is an unusually high-stakes proving ground for this debate: exploits can drain hundreds of millions of dollars in minutes, and the industry is already seeing signs that attackers are moving faster with AI assistance than some defense teams can keep pace with.
Security leaders interviewed broadly accept that an initial restriction period makes sense. Binance's Su argued that if a newly released model helps attackers more than defenders in its early period, wide release could do net harm to the ecosystem — and that a limited rollout reduces the potential "blast radius." He added that pressure on Anthropic to widen access will grow as competing models catch up in capability.
Solana Foundation CISO Michael Coates, who joined the foundation in July, said he supports guardrails in principle but wants faster, more streamlined verification and acceptance programs so legitimate defenders aren't left waiting. Blockchain Capital's Sean Cheetham went further, arguing that because legitimate security researchers vastly outnumber sophisticated attackers, opening access more broadly would ultimately favor defense over offense.
Background context
What is Project Glasswing?
Per the source reporting, Project Glasswing is Anthropic's gated access program that gives vetted cyber defenders and organizations responsible for critical software infrastructure early access to its restricted Mythos-tier models, ahead of any broader public release.
The Numbers
Hard figures in the reporting are limited, but they underline the scale of what's exposed while frontier-model access stays uneven:
Methodology / sourcing notes
All figures above come directly from the supplied Cointelegraph article. The Binance asset figure is attributed there to DefiLlama. No additional data points, estimates, or projections have been added.
Market Reaction
The source material does not report price or trading-volume reactions tied to this story — it focuses on operational security posture rather than market pricing. Two operational incidents are documented instead:
Separately, hardware wallet maker Coinkite said last week that a number of its Coldcard devices were exploited due to a flaw in wallet seed generation that turned out to be less random than intended. Coinkite speculated the attacker may have used AI to review earlier firmware versions to locate the flaw — notable because Coinkite said it had used "one of the best available AI models" to review its own code just weeks earlier without catching the issue.
What's Next / Things to Watch
- Verification-program speed: Solana's Coates is pushing for faster vetting and acceptance processes so legitimate defenders reach restricted models sooner.
- Competitive pressure on Anthropic: Binance's Su expects the calculus to shift as open-source and rival models approach Mythos-level capability, increasing pressure to widen access.
- Outstanding responses: Cointelegraph said it had reached out to Ethereum Foundation, Fireblocks, and Uniswap on whether they've since gained access, and separately to OpenAI and Anthropic on total crypto-sector access numbers — none of those responses are reflected in the reporting so far.
- Further AI-linked incidents: Boltz's bridge halt and Coinkite's Coldcard exploit suggest more disclosures of this kind may follow as firms adapt to AI-assisted attack patterns.
FAQs
What is Anthropic's Mythos model, and why is it restricted?
Per the source, Mythos 5 runs on the same underlying model as Anthropic's public Fable 5 release, but without the safeguards that limit sensitive cybersecurity-related use — which is why access is gated rather than open to everyone.
Which crypto companies currently have access to Mythos?
Coinbase confirmed access in June. FIS and HackerOne say they joined Anthropic's Project Glasswing program. Anthropic separately used Mythos to audit the Zcash protocol at Shielded Labs' request.
Why doesn't Binance have access yet?
Binance's CSO Jimmy Su said the exchange has pursued access through direct outreach and through crypto exchange and investor contacts, but has not obtained it, despite Binance being the largest exchange by daily trading volume.
Is OpenAI doing something similar?
Yes — the source describes a tiered system where verified defenders get GPT-5.5 through "Trusted Access for Cyber," while a more permissive GPT-5.5-Cyber variant is limited to a smaller group doing authorized penetration testing.
Are AI-assisted attacks on crypto actually increasing?
The source cites two concrete cases this month: Boltz halting its non-custodial bridge over a rise in AI-assisted exploits, and Coinkite attributing a Coldcard hardware wallet exploit to a firmware flaw it believes an attacker may have found using AI-assisted code review.
Sourcing note: This article is a rewritten, contextualized version of a single Cointelegraph report. No external URLs were provided in the source material for individual claims, so no additional endnote links are included beyond the general sourcing below.
- Original reporting: Cointelegraph, "Crypto firms still seeking frontier AI access; only select few have it."
- Related Cointelegraph piece referenced in the source: "Can AI drain DeFi? Separating Claude Mythos hype from reality."
- Related Cointelegraph piece referenced in the source: "Fears of AI-driven DeFi hack epidemic overstated for now — but not for long."
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.