When the Federal Reserve’s dovish pivot reignited crypto’s risk-on frenzy in early 2024, most exchanges scrambled to scale their matching engines. Kraken did something quieter. It signed a security pact with Anthropic, handing its vulnerability hunting to an AI model named Claude Mythos. The press release framed it as a leap forward: “Payward joins Project Glasswing to find security flaws.” On the surface, this is a textbook case of AI4Security—a bullish narrative for both the exchange and the sector. But peel back the layers, and you find a different architecture: one where Kraken trades short-term detection capability for long-term sovereignty risk. This is not a story about faster bug fixes. It is a story about the fragility of outsourced trust in an industry that claims to be built on trustlessness.
Project Glasswing is Anthropic’s curated program for granting vetted organizations access to its cybersecurity AI, Claude Mythos. The model is designed to analyze code, reverse-engineer malware, and surface zero-day-like vulnerabilities. For Kraken, which holds billions in user assets and faces constant pressure from both hackers and regulators, offloading some of the security burden to a state-of-the-art LLM seems rational. But the devil lives in the fine print of the data processing agreement. When Kraken feeds a suspicious smart contract or a log of anomalous withdrawal patterns into Claude Mythos, that data travels across Anthropic’s infrastructure. The model’s outputs are probabilistic, not deterministic. A single false negative—a vulnerability missed by the AI—could lead to a catastrophic breach. And a false positive? It wastes security engineers’ time, eroding the very efficiency the partnership promises.
Let me be clear about what this is not: a revolutionary improvement in security. During my 2019 audit of Uniswap V1 liquidity pools, I manually traced 50 high-frequency wallets to understand the real economic value behind the TVL. I discovered that 80% of liquidity was fleeting “fat token” manipulation—a finding that came from meticulous human analysis, not a tool. The lesson stuck: no AI, no matter how advanced, can replace the context-aware judgment of a seasoned security team. Claude Mythos may catch 90% of known vulnerability patterns, but the remaining 10%—the novel, the contextual, the logic-level flaws—are precisely what cause the most damage. And those require human intuition, which cannot be outsourced.
But the deeper risk lies in the supply chain. Kraken is now dependent on Anthropic’s model availability, its data hygiene, and its resistance to adversarial attacks. If a prompt injection technique compromises Claude Mythos, the attacker could feed Kraken’s security team false negatives or, worse, malicious code disguised as a patch. This is not a theoretical threat. In 2023, researchers successfully poisoned LLMs by embedding triggers in training data. Kraken’s security floor is now tied to Anthropic’s AI security posture. This is the Glasswing Paradox: a tool designed to increase transparency and security creates a new opaque dependency.
From a macro perspective, this move signals a broader trend: exchanges are pivoting from building proprietary security moats to buying AI-powered ones. Coinbase has its own AI initiatives, but Binance relies on its SAFU fund and internal teams. Kraken’s choice to partner with Anthropic is a bet that the best AI security will come from a specialized vendor, not an in-house team. This is a classic make-or-buy decision. In a bull market, when speed-to-market matters, buying seems efficient. But in a bear market, the cost of switching vendors becomes a hidden liability. And Kraken is a mature institution—founded in 2011, it has weathered multiple cycles. Why now?
The answer may lie in the regulatory pressure cooker. The U.S. SEC and CFTC have been scrutinizing exchanges for years. Kraken settled with the SEC over its staking program in 2023, paying a $30 million fine. To regain trust, the exchange needs to demonstrate a security posture that exceeds regulatory expectations. Partnering with Anthropic, a company with a strong reputation in AI safety research, provides a powerful narrative: “We use the most advanced AI to protect your assets.” It is a narrative that resonates with institutional clients who are wary of crypto’s Wild West image. But narratives are not security. As I wrote in my 2021 DeFi Summer Disillusionment manifesto, technology amplifies the underlying incentives. If the incentive is to check a box for compliance, the AI becomes a decoration, not a shield.
Let me walk through the structural mechanics. The core of any security audit is the ability to reason about the system’s invariants: what can never happen. For a custody exchange, the invariant is that user funds are never spent without authorization. Claude Mythos can scan code for common vulnerabilities—reentrancy, integer overflow, improper access control—but it cannot reason about the unique economic logic of a new DeFi protocol or the motivations of a rogue employee. The most sophisticated attacks are not code-level exploits; they are logic-level manipulations. The 2023 Euler Finance flash loan attack was not a simple reentrancy; it was a complex sequence of operations that exploited a donation mechanism. Could an AI have caught that? Possibly, but only if it was trained on a similar pattern. The attack surface is infinite; the training data is finite.
There is also the question of data sovereignty. Kraken’s security logs, transaction patterns, and internal codebases are among its most sensitive assets. Feeding them into a third-party model means trusting Anthropic not to use them for training, not to leak them, and not to be compelled to hand them over to a government. Anthropic’s privacy policy states that data from enterprise customers is not used for model improvement, but that is a contractual promise, not a cryptographic guarantee. In a world where regulators can subpoena AI companies, Kraken’s security posture is only as strong as Anthropic’s legal team. Trust is the new collateral.
Now, let me push back against the bullish narrative. Some analysts will argue that this partnership gives Kraken a competitive advantage. I disagree. In the short term, yes, it provides a PR boost. But in the long term, the security of any exchange depends on the quality of its engineers, not the sophistication of its tools. If every major exchange adopts the same AI security service—and Anthropic is clearly aiming for that—the differentiation disappears. The security becomes a commodity, and the real moat lies in the ability to integrate that AI with human intuition and a robust incident response plan. Kraken has a strong team, but the partnership does not fundamentally change the economics of security. Liquidity is a mirage; only settlement is real. The settlement of a security breach is not measured in tickets closed but in dollars lost and trust eroded.
Let me ground this in a personal experience. During the 2022 bear market, I spent three months researching the regulatory frameworks of the Bangko Sentral ng Pilipinas regarding digital assets. I drafted a comparative analysis of three CBDC pilot programs, focusing on how state-backed stability could counter the volatility I had witnessed. That experience taught me that institutional trust is built slowly, through consistent action, not through press releases. Kraken’s partnership with Anthropic is a press release. The real work—training the AI on Kraken’s specific threat models, validating its outputs, and maintaining a fallback manual process—will take years. And if the market is already exuberant, the price of failure is asymmetric.

From a contrarian standpoint, the biggest blind spot is the human factor. Claude Mythos may be excellent at finding vulnerabilities in code, but it cannot read the mind of a malicious insider. The most damaging breaches in crypto history—the 2014 Mt. Gox hack, the 2019 Binance KYC leak, the 2022 FTX collapse—were not caused by technical vulnerabilities. They were caused by governance failures, operational lapses, and deliberate fraud. An AI that scans code cannot prevent a CEO from misappropriating funds. It cannot prevent a rogue employee from exfiltrating a database. In that sense, the partnership is a misallocation of resources. Kraken would be better served by investing in zero-knowledge architectures for client asset verification, or by implementing real-time multi-signature controls that distribute authority across multiple parties. But those improvements are harder to market.
Let me also address the regulatory angle. The U.S. is currently debating AI regulation, with bills like the AI Research and Innovation Act and the SAFE Innovation Act. If Congress mandates that AI models used in critical infrastructure must be audited by a government-approved body, Kraken could be forced to comply with a whole new set of requirements. Anthropic’s model is not open-source; its internal workings are opaque. Regulators may demand explainability—why did the AI flag this transaction as suspicious? If Claude Mythos cannot provide a clear chain of reasoning, Kraken may face fines or operational restrictions. Settlement is final. Regret is not.
Now, let me consider the opportunity for the broader ecosystem. The partnership could accelerate the adoption of AI in exchange security, pushing other exchanges to follow suit. This would create a positive network effect: better security across the board reduces systemic risk. But it also creates a monoculture. If all exchanges rely on the same AI model, a single vulnerability in that model could be exploited en masse. This is the same argument used against centralized smart contract audits. Diversity is a feature, not a bug. Kraken’s move is a step toward homogenization, not resilience.
What does this mean for the cycle? In a bull market, security spending is often the first thing to be cut when budgets tighten. But Kraken’s partnership is a long-term bet that AI security will become a necessary cost of doing business. If the bull market continues, the partnership will be seen as prescient. If a bear market hits, Kraken may be locked into a multi-year contract with an expensive vendor. The macro cycle is unpredictable, but the structural trend is clear: the cost of security is rising, and outsourcing is the path of least resistance.

There is one more subtle risk. Anthropic’s Project Glasswing is a “curated” program. By accepting Kraken, Anthropic implicitly endorses the exchange’s security posture. If Kraken suffers a breach after the partnership, Anthropic’s reputation is also damaged. This creates a mutual dependency that could lead to moral hazard: Kraken may become complacent, relying on the AI to catch everything, while Anthropic may be reluctant to report a flaw in its own model that could trigger a Kraken incident. The alignment of incentives is not perfect.
Let me return to the fundamental question: is this partnership good for crypto? Yes, if it raises the baseline security level of a major exchange. No, if it creates a false sense of security and distracts from the real work of building decentralized trust. Kraken is a centralized entity, and its security is only as good as its last audit. The AI can catch bugs, but it cannot fix culture. The industry’s history is littered with exchanges that invested in technology while ignoring governance. Kraken is better than most, but that is a low bar.
In conclusion, Kraken’s partnership with Anthropic is a well-intentioned but ultimately limited move. It provides a temporary narrative boost and a modest improvement in vulnerability detection, but it introduces new dependencies and risks that are not fully transparent. The market will price this in as a bullish signal, but the real test will come when a sophisticated attacker targets Kraken’s AI pipeline. Until then, the partnership is a bet on the promise of AI, not the execution of security. As I wrote in my 2024 ETF Institutional Bridge report, regulatory clarity drives capital flows, not technological breakthroughs. The same is true here: the clarity of Kraken’s security architecture will determine its long-term trust, not the name of its AI vendor.
Liquidity is a mirage; only settlement is real. The settlement of Kraken’s security bet will be measured in the absence of a breach, not the presence of a press release. And that settlement is years away.