
Binance, Fireblocks and others still lack access to Anthropic's restricted Mythos model, even as AI-assisted exploits rise. FIS and HackerOne have joined the gated program.
Crypto's biggest exchanges and custodians are still waiting for access to frontier AI models that could help them defend against attacks, while a small group of firms has secured early entry. The uneven access is creating a new security divide in an industry where a single exploit can put billions of dollars at risk.
Coinbase said in June it had secured access to Anthropic's restricted Mythos model. Zcash's Zooko Wilcox said Anthropic used the model to audit the Zcash protocol at the request of Shielded Labs. Other major players are still waiting.
"That's one advanced frontier model that hasn't been made available to crypto just yet," Binance's chief security officer Jimmy Su told Cointelegraph. "We have been trying to make inroads there. We also talked to other crypto exchanges and our own investors to try to make some progress. But we haven't gotten the most frontier AI model, like Mythos."
Binance's lack of access comes despite it being the largest crypto exchange by daily trading volume, holding $137.8 billion in assets, according to DefiLlama. Anthropic says Mythos 5 uses the same underlying model as its publicly available Fable 5, but without the safeguards that restrict sensitive cybersecurity work. OpenAI operates a similar tiered system: verified defenders can use GPT-5.5 with "Trusted Access for Cyber," while its more permissive GPT-5.5-Cyber model is reserved for a smaller group conducting authorized penetration testing.
Crypto security executives said there is likely a need to initially restrict access to frontier cyber models, but continuing to gate them becomes harder to justify once publicly available models approach the same capabilities. Su said Anthropic's controlled rollout is a responsible approach because newly released models may benefit attackers faster than defenders.
"If it enhances the attacker much faster than the defender, then it actually is harming the ecosystem," he said, adding that a limited testing period could reduce the potential "blast radius."
Su said this calculation changes when competing models become more powerful and widely available. "As other more powerful models are being released, the pressure will be on Anthropic to make it more widely available," he said. The question would be whether defenders can deploy the frontier model as effectively as attackers once it becomes available.
Solana Foundation chief information security officer Michael Coates, who joined in July, supported safeguards but argued that legitimate defenders need a faster route to them. "I fully understand guardrails for advanced models, but we need to streamline the verification programs, the acceptance programs, to give these models to legitimate defenders," he said. "We need to make sure that the best models we can get are in the hands of defenders because attackers will have something capable enough."
Blockchain Capital's Sean Cheetham also supported eventually opening up restrictions, saying broader availability could favor defenders as legitimate security researchers greatly outnumber the small groups conducting sophisticated attacks. "If good people can multiply their defense scale… you're much better off just opening it up and allowing them to defend themselves," he said.
Crypto custodian Fireblocks, which secures trillions in assets annually, said in April it had sought access to Mythos and at the time only used Anthropic's publicly available model for pentesting, according to The Information. Uniswap founder Hayden Adams in June slammed Fable 5's safeguards that restrict prompts relating to cybersecurity. The Ethereum Foundation in July said it has been running "coordinated AI agents" to find bugs across its systems, but didn't disclose which models were being used. Cointelegraph reached out to Ethereum Foundation, Fireblocks and Uniswap to confirm if they have since received access.
Some crypto-adjacent companies have gained access. FIS, which provides technology to banks and partnered with Circle in July last year to let banking clients offer payments in USDC, joined Project Glasswing last month. Project Glasswing is Anthropic's gated program for giving vetted cyber defenders and organizations responsible for critical software infrastructure early access to its restricted Mythos models. HackerOne, which provides bug-bounty and security testing services to major crypto exchanges, also said it joined Project Glasswing, though testing is confined to its own infrastructure. FIS carries an Alpha Score of 41/100, labeled Mixed, on its stock page.
On Monday, Bitcoin swap service Boltz said it has chosen to halt its non-custodial bridge after seeing a steady rise in AI-assisted exploits over the past few months. "The pattern is clear: attackers now iterate faster than a team our size can find and patch." Last week, Bitcoin hardware wallet company Coinkite said a number of its Coldcard devices were exploited due to a flaw in its wallet seed generation, which turned out to be less random than expected. It speculated that the attacker had used AI to review previous versions of the firmware to find and exploit the flaw, despite it using "one of the best available AI models" to review its code just weeks before. Cointelegraph reached out to OpenAI and Anthropic about how many crypto companies have been given access to restricted models.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.