Crypto companies are competing for early access to frontier AI systems, with the fight centered less on model development and more on who can use the strongest tools first to protect tokens, protocols and infrastructure.
According to CoinTelegraph on Aug. 4, only a small group of crypto firms have obtained access to Anthropic’s restricted Claude Mythos model. Larger names across the industry are still waiting in line.
Coinbase got Mythos first, while Binance says it still does not have it
Coinbase, the largest crypto exchange in the United States, said in June that it had secured access to Anthropic’s Mythos model. Zcash founder Zooko Wilcox also wrote on X that Anthropic used the model to audit the Zcash protocol for Shielded Labs.
Binance, despite being the world’s largest exchange, has not received the same level of access. Binance Chief Security Officer Jimmy Su said, “We’ve discussed this with other exchanges and even our own investors, but we still haven’t gotten the most cutting-edge AI models like Mythos.”
The report noted that Binance holds $137.8 billion in assets, yet Mythos still has not been opened to the company.
Fireblocks, a major crypto custody provider, said in April that its penetration testing work at the time relied on public models rather than a higher-permission system. The article described Fireblocks as protecting trillions of dollars in assets each year.
Anthropic and OpenAI are both using tiered access systems
Anthropic and OpenAI have both set up layered access structures for their most advanced security-capable models.
- At Anthropic, the publicly available model is Fable 5. Mythos 5, which runs on the same base model, has its security restrictions removed for sensitive cyber tasks and is available only to screened defenders. FIS and HackerOne are already part of the Project Glasswing program.
- At OpenAI, verified defenders can use GPT-5.5 through a trusted cybersecurity channel. The more permissive GPT-5.5-Cyber remains limited to a small set of teams conducting authorized penetration testing.
CoinTelegraph said Mythos 5 and the public Fable 5 share the same underlying model. The main difference is that Mythos removes the guardrails that limit sensitive cybersecurity work.
AI-assisted attacks are already hitting crypto targets
AI-assisted attacks are no longer a distant risk. Data from Epoch AI cited in the report showed a noticeable increase in severe CVE vulnerabilities after Claude Mythos launched.
Two examples highlighted on Monday show how that shift is playing out in practice:
- Bitcoin swap service Boltz said it had seen a continued rise in AI-assisted attacks over the past few months and suspended its non-custodial bridging service.
- Hardware wallet maker Coinkite said Coldcard devices were exploited because of insufficient randomness in seed generation. Coinkite suspects the attacker used AI to review earlier firmware versions.
The Ethereum Foundation said in July that it had deployed “coordinated AI agents” to find bugs in its systems, though it did not disclose which models were used.
The argument is shifting to defender access
Solana Foundation Chief Information Security Officer Michael Coates, who took the role in July, said he supports initial screening but wants the verification path simplified. “I completely understand the protections around high-end models, but we need to simplify the verification process and the admission process, and put the models in the hands of real defenders,” he said.
Sean Cheetham of Blockchain Capital argued that breadth matters more than precision. In his view, the number of legitimate security researchers far exceeds the size of many state-backed or national attack teams. “If the good guys can scale defense … just open the door and let them protect themselves,” he said.
Uniswap founder Hayden Adams had also criticized Fable 5 restrictions on cybersecurity-related prompts in June, saying those limits leave crypto protocols at a disadvantage.
An uneven security boundary is forming
Unequal access is creating a new security divide inside crypto. Model developers have clear reasons to restrict the strongest systems, since a more capable release could strengthen attackers before defenders can respond.
Still, Jimmy Su said the real issue is whether defenders will be able to deploy frontier models as effectively as attackers as rival systems become stronger and more widely available.
The gap, in other words, is not created by AI alone. It comes down to who gets the model and who can actually use it to defend live systems.

