Friday, 9 October 2026 9 calls on file SearchSubscribe
Crypto and finance news. On the record.
Breaking
AI3 min read

Anthropic OSS Scanner Offers Free Opt-In Bug Hunts

Anthropic launched OSS Scanner, a free opt-in service that sends model-generated vulnerability reports to open-source projects without human triage.

Anthropic OSS Scanner Offers Free Opt-In Bug Hunts
Illustration: Called It

Anthropic OSS Scanner is the company's attempt to turn Project Glasswing's private bug hunting into a public, opt-in pipeline for open-source maintainers. On October 8, 2026, Anthropic said projects that join will receive periodic security scans from its strongest models at no cost.

What happened

In its research post, Anthropic said language models on the CyberGym benchmark had gone from finding under 20% of vulnerabilities early last year to more than 85% this year. Over six months the lab discovered more than 29,000 candidate vulnerabilities with its latest models but manually reviewed only about 6,000. Maintainers who received first reports often asked for bulk dumps of unverified findings; Anthropic said it has sent nearly 5,000 such reports on request.

OSS Scanner outputs will be fully model-generated, without human review or triage, so some reports may be incorrect. Scans will use Anthropic's strongest models, including Claude Mythos. Each report is meant to include a self-contained reproducer, an explanation with bisection where possible, and a candidate patch when available. Early pipeline tests with dozens of projects produced hundreds of bug reports, including chains to unauthenticated remote code execution. Expert testers checked 97 critical and high-severity scanner findings across 48 projects; 85 (88%) met Anthropic's coordinated-disclosure bar.

The Verge underscored the trade-off: faster, more frequent scans without human review, with Mythos among the models in the mix. It also noted the wider context — AI helpers have found major flaws such as the May "Copy Fail" Linux bug, while some projects are drowning in low-quality AI reports.

Why it matters

Open source is both the soft underbelly of critical infrastructure and the place where volunteer maintainers have the least triage time. Anthropic OSS Scanner tries to give defenders the same model firepower attackers can already rent, while admitting the false-positive cost upfront. Human-verified coordinated vulnerability disclosure continues in parallel for projects that cannot absorb raw model output.

Quotes in Anthropic's post from PostgreSQL, OpenSSL Corporation, wolfSSL and HotCRP maintainers described unusually high signal, including patches usable nearly as-is and CVE-ready findings. That is the bar the service must keep if it is not to become another spam channel. The launch also sits beside enterprise Claude Security products; OSS Scanner is the free public counterpart aimed at ecosystem defense rather than paid enterprise scanning. Related AI-security and research threads on Called It include OpenAI's 722 math papers drop and OpenAI's TextGrain watermark for the EU AI Act.

Maintainer quotes in Anthropic's post sketch what good Anthropic OSS Scanner output looks like. PostgreSQL's Noah Misch said an unusually high fraction of findings were real defects with near-usable fixes. OpenSSL Corporation's Anton Arapov contrasted early AI slop from 18 months ago with reports that matched or beat human quality when a real exploit was attached. wolfSSL's Todd Ouska said 72 of 74 reports were valid and five became CVEs. HotCRP's Eddie Kohler praised permission-model detail and prioritization.

Those testimonials set a public bar. The Verge's reminder that projects already drown in low-quality AI bug mail is the failure mode Anthropic is trying to avoid by shipping reproducers and patches with every report. Human CVD remains for under-resourced projects; OSS Scanner is the fast track for teams that asked for the unverified bulk. Enrollment volume, CVE conversion rates and maintainer opt-out rates over the next quarter will show whether the service stays a defense public good or becomes another inbox tax.

Anthropic said exploits can now be developed in minutes, which is why it wants defenders scanning at model speed even when some tickets are wrong. Anthropic OSS Scanner is therefore an explicit bet that false positives are cheaper than slow disclosures against automated attackers.

Of the 12 scanner findings that missed Anthropic's coordinated-disclosure bar in the expert check, the company said 11 were real but duplicated known issues or other scan findings, and only one was an outright false positive; some maintainers have said severity ratings can be inflated.

What's next

Enrollment runs through Anthropic's OSS Scanner program pages and GitHub workflow for eligible projects. Watch how quickly high-profile repositories opt in, what fraction of model-only reports survive maintainer scrutiny, and whether other labs answer with their own free scanners. Anthropic OSS Scanner will be judged less on candidate counts than on how many findings become real fixes before exploit code is a commodity.

This article is for information only and is not investment advice.

More from AI

All ai

The Morning Call.

The day's crypto and finance news, one call and one chart. Weekdays at 7am ET.