News · Science & Technology
Crypto projects apply for Paradox’s new frontier AI security scanner
OSS Scanner is Paradox’s opt-in security service for open-source projects. It scans participating code for weaknesses that attackers might exploit. The reports come from Paradox’s strongest models, including Paradox Mythos. The goal is to help developers find and fix problems earlier. The service changes the speed of security review. Paradox already scans open-source software, but people must review those findings before reports are shared. OSS Scanner delivers reports to enrolled projects as soon as their code has been scanned. Projects can then investigate and patch the reported issues. Paradox launched the program after Project Glasswing and will assess applications case by case. It will consider infrastructure importance, user-security risks, remote attack exposure and project dependency. The service reflects growing concern that attackers may exploit weaknesses faster than developers can verify and repair them.
Based on reporting by Cointelegraph
What is Paradox’s OSS Scanner, and what does it provide to open-source projects?
OSS Scanner is Paradox’s opt-in security service for open-source projects. It scans participating code for weaknesses that attackers might exploit. The reports come from Paradox’s strongest models, including Paradox Mythos. The goal is to help developers find and fix problems earlier.
The service changes the speed of security review. Paradox already scans open-source software, but people must review those findings before reports are shared. OSS Scanner delivers reports to enrolled projects as soon as their code has been scanned. Projects can then investigate and patch the reported issues.
Paradox launched the program after Project Glasswing and will assess applications case by case. It will consider infrastructure importance, user-security risks, remote attack exposure and project dependency. The service reflects growing concern that attackers may exploit weaknesses faster than developers can verify and repair them.
Which crypto projects have applied, and what parts of their software do they want examined?
Several crypto projects applied for Paradox’s OSS Scanner after its launch. Nethermind, an Ethereum client developer, requested an audit of its entire repository. ZEUS, a self-custodial Bitcoin and Lightning wallet, asked for its app to be examined for weaknesses affecting payments, private keys and connections to Lightning Services.
VirtEngine was another crypto applicant. It operates a decentralized cloud computing marketplace structured as a Cosmos SDK chain. These applications show that projects want security checks focused on both broad codebases and sensitive user-facing functions.
The applicants had not been accepted when the article was published. None of the pull requests to the OSS Scanner GitHub repository had been merged. Other applicants included developers of AI assistants, agent-security tools, machine-learning infrastructure, cloud storage and energy-system controls.
How broad is the scanner’s intended reach—can it examine an entire code repository and software used by many other projects?
OSS Scanner is intended to cover projects with very different sizes and security roles. Its reach can include a complete code repository, not only one feature or application. Nethermind’s request for an audit of its entire repository provides the clearest example of that breadth.
The scanner can also examine software with important downstream effects. Paradox says it will consider how many users or other projects depend on an applicant. That means a project’s importance is measured partly by the wider systems built on or connected to its code.
The program is not an automatic promise to scan everything submitted. Paradox will assess projects case by case. It will weigh infrastructure importance, user security, exposure to remote attacks and dependency levels. At publication time, applications from Nethermind, ZEUS and others were still unmerged.
How does OSS Scanner change the usual process of finding and reporting software vulnerabilities?
OSS Scanner changes the timing of vulnerability disclosure. Paradox said it already regularly scans open-source software and sends reports after human review. That review helps assess findings, but it is slow. As a result, projects may not hear about weaknesses as quickly as Paradox would like.
Under the new opt-in process, reports go to participating projects as soon as their code has been scanned. The key mechanism is faster delivery from automated model-based analysis, rather than waiting for the usual manual review to finish. Developers can then investigate the report and work on a fix.
The change is designed to strengthen defenders before attackers exploit weaknesses. Paradox still chooses projects individually, considering infrastructure importance, remote attack exposure and user or project dependence. The article does not say that human review has disappeared entirely; it describes OSS Scanner as a faster reporting service.
Why are crypto companies seeking access to Paradox’s strongest AI models for security work now?
Crypto companies want Paradox’s strongest models because the security contest is becoming faster and more difficult. Paradox warned that AI may favor attackers in the near term. Exploitation can become cheaper, while checking and fixing vulnerabilities remains slow and dependent on people.
The concern is not theoretical. Bitcoin swap provider Boltz suspended operations in August, saying attackers were developing exploits faster than its team could patch them. Crypto-payment service PayPerQ also reported repeated attacks it suspected were AI-powered. These incidents add pressure for stronger defensive tools.
Access to frontier models could help projects find weaknesses earlier and receive reports faster. Still, access is uneven, and cybersecurity experts warn that defenders may fall behind as powerful alternatives spread. Paradox will therefore select applicants case by case, based partly on infrastructure importance and user-security exposure.
What could happen to crypto users and services if attackers discover vulnerabilities faster than developers can verify and fix them?
When attackers move faster than developers, a vulnerability can remain exploitable while a service is operating. That can put users and infrastructure at risk. In crypto applications, the consequences may involve payments, private keys or connections to Lightning Services, all areas ZEUS specifically wants examined.
The article gives two examples of pressure already affecting services. Boltz suspended operations in August after saying attackers were developing exploits faster than its team could patch them. PayPerQ reported repeated attacks it suspected were AI-powered. These cases show how a widening speed gap can interrupt services and force defensive decisions.
The broader danger is that exploitation is becoming cheaper while verification and repair remain slow and human-dependent. Faster reports from OSS Scanner could help developers respond sooner. However, Paradox and cybersecurity experts warn that defenders may still face an uneven contest as powerful AI tools become more available.
What is a software vulnerability, and why can a weakness in open-source code endanger many unrelated applications and users?
In general, a software vulnerability is a weakness in code, configuration or design that an attacker can exploit. The article focuses on vulnerabilities that may enable remote attacks or threaten user security. Finding one matters because developers need time to understand the problem, verify it and create a fix.
Open-source code can be shared, reused or depended on by many applications. The article does not define this chain directly, but it highlights projects on which many users or other projects depend. A weakness in such software can therefore affect more than the project that first wrote it.
That wider exposure explains Paradox’s selection criteria. It will consider infrastructure importance, remote attack exposure and the number of dependent users or projects. OSS Scanner aims to give participating developers reports sooner, helping them address weaknesses before attackers exploit them.
Key Facts:
📌 OSS Scanner is an opt-in service for open-source projects.
📌 Reports come from Paradox’s strongest models, including Paradox Mythos.
📌 Participating projects receive reports after their code is scanned.
📌 Nethermind requested an audit of its entire repository.
📌 ZEUS identified payments, private keys and Lightning connections.
📌 VirtEngine operates a decentralized cloud marketplace.
📌 Nethermind applied for an audit of its entire repository.