IBM Launches $5 Billion Open-Source Security Push as Six Financial Giants Join Early

IBM Launches $5 Billion Open-Source Security Push as Six Financial Giants Join Early

N
News Editor 01
2026-07-24 02:10:15
IBM and Red Hat have launched Project Lightwell with a $5 billion commitment and 20,000 full-time engineers focused on finding and fixing open-source software vulnerabilities. Six major financial firms are already on board.

IBM has launched Project Lightwell with Red Hat, committing $5 billion and assigning 20,000 full-time engineers to identify and remediate vulnerabilities in open-source software using AI. At launch, Bank of America, JPMorgan Chase, Visa, Mastercard, Wells Fargo, and Morgan Stanley were named as early participants on the platform.

The timing is notable. Open-source supply chain attacks have intensified this year, both in frequency and impact. The source material points to a March incident involving the AI package LiteLLM, which sees nearly 100 million monthly downloads and was found carrying malicious code designed to steal crypto wallet private keys and SSH keys. In May, the TanStack npm supply chain attack also affected computers used by OpenAI employees. IBM is moving as those incidents push software dependency risk into sharper focus.

Red Hat expands beyond its own stack

Red Hat’s security tools and vulnerability scanning had previously centered on its own environments, including RHEL and OpenShift. Project Lightwell widens that scope to cover AI frameworks, open-source code repositories, and Apache Kafka, along with a broader set of distributed infrastructure. The target is not just the application layer. IBM is aiming at the dependency layer where malicious code can slip into systems that traditional perimeter defenses cannot protect.

The source also highlights Kafka’s heavy use across finance. JPMorgan Chase at one point posted more than 500 roles requiring Kafka experience, reflecting how deeply the technology is tied to real-time transaction processing, risk monitoring, and regulatory reporting. A compromised dependency in that stack can travel far beyond a developer workstation.

20,000 engineers are being reassigned, not newly hired

IBM says the scale of the project includes $5 billion in investment and 20,000 engineers drawn from its existing workforce. These are not contractors, part-time contributors, or outside advisers. According to the source, they are full-time IBM employees focused entirely on vulnerability detection and remediation in open-source software.

The move follows IBM’s May announcement that it was expanding its AI security product lineup and deepening work with Anthropic under the name Project Glasswing. Project Lightwell sits within that same direction, linking AI security, open-source code review, and enterprise infrastructure protection.

Early adopters reflect where the risk is concentrated

The first six partners represent major banks, card networks, and financial services firms in the US. They also share the same structural exposure: heavy reliance on open-source infrastructure, from Kafka and Kubernetes to AI inference frameworks. Each layer can become an entry point for a supply chain attack.

For financial institutions, the issue is larger than a broken application. If a dependency deep in the stack is poisoned, the consequences can spread into payment flows, monitoring systems, and reporting pipelines. Project Lightwell is built around that exact problem by moving scanning and remediation closer to the open-source ecosystem itself.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.