IBM has launched Project Lightwell with Red Hat, committing $5 billion and assigning 20,000 full-time engineers to identify and remediate vulnerabilities in open-source software using AI. At launch, Bank of America, JPMorgan Chase, Visa, Mastercard, Wells Fargo, and Morgan Stanley were named as early participants on the platform.
The timing is notable. Open-source supply chain attacks have intensified this year, both in frequency and impact. The source material points to a March incident involving the AI package LiteLLM, which sees nearly 100 million monthly downloads and was found carrying malicious code designed to steal crypto wallet private keys and SSH keys. In May, the TanStack npm supply chain attack also affected computers used by OpenAI employees. IBM is moving as those incidents push software dependency risk into sharper focus.
Red Hat expands beyond its own stack
Red Hat’s security tools and vulnerability scanning had previously centered on its own environments, including RHEL and OpenShift. Project Lightwell widens that scope to cover AI frameworks, open-source code repositories, and Apache Kafka, along with a broader set of distributed infrastructure. The target is not just the application layer. IBM is aiming at the dependency layer where malicious code can slip into systems that traditional perimeter defenses cannot protect.
The source also highlights Kafka’s heavy use across finance. JPMorgan Chase at one point posted more than 500 roles requiring Kafka experience, reflecting how deeply the technology is tied to real-time transaction processing, risk monitoring, and regulatory reporting. A compromised dependency in that stack can travel far beyond a developer workstation.
20,000 engineers are being reassigned, not newly hired
IBM says the scale of the project includes $5 billion in investment and 20,000 engineers drawn from its existing workforce. These are not contractors, part-time contributors, or outside advisers. According to the source, they are full-time IBM employees focused entirely on vulnerability detection and remediation in open-source software.
The move follows IBM’s May announcement that it was expanding its AI security product lineup and deepening work with Anthropic under the name Project Glasswing. Project Lightwell sits within that same direction, linking AI security, open-source code review, and enterprise infrastructure protection.
Early adopters reflect where the risk is concentrated
The first six partners represent major banks, card networks, and financial services firms in the US. They also share the same structural exposure: heavy reliance on open-source infrastructure, from Kafka and Kubernetes to AI inference frameworks. Each layer can become an entry point for a supply chain attack.
For financial institutions, the issue is larger than a broken application. If a dependency deep in the stack is poisoned, the consequences can spread into payment flows, monitoring systems, and reporting pipelines. Project Lightwell is built around that exact problem by moving scanning and remediation closer to the open-source ecosystem itself.

