The Impact of Anthropic's Mythos Model on the Crypto Industry's Security Landscape
The introduction of Mythos, Anthropic's novel AI model, has sparked significant concern and confusion within traditional tech and finance, while also driving a substantial shift in the crypto industry's approach to security. For years, decentralized finance has focused on defending smart contracts through code audits, vulnerability cataloging, and understanding common exploits. However, Mythos, designed to identify and chain together weaknesses across systems, is redirecting attention towards the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'The bigger risks sit in infrastructure... When I think about AI-driven threats, I’m less concerned about smart contract exploits and more focused on AI-assisted attacks against the human and infrastructure layers.' This includes key management systems, signing services, bridges, oracle networks, and cryptographic layers, which are often less visible and outside traditional audit scope. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the vulnerability of these components. Mythos represents a new class of AI systems that simulate adversaries by exploring how protocols interact and testing small weaknesses that can be combined into real-world exploits. This approach has drawn attention beyond crypto, with banks like JP Morgan exploring tools like Mythos for stress testing. Early findings have identified weaknesses in the behind-the-scenes systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender emphasizes that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits overlook. The interconnected nature of DeFi protocols, which share liquidity and rely on common oracles, creates pathways for risk to spread. Composability is a double-edged sword, driving growth but also facilitating the spread of risk. Without AI, tracing these dependencies is challenging; with AI, they can be mapped and exploited at scale, leading to a shift from isolated exploits to systemic failures. Industry leaders view Mythos as an acceleration of existing dynamics rather than a turning point. Stani Kulechov, founder of Aave Labs, notes that AI reflects the adversarial environment already present in DeFi, with AI models representing an evolution in the tools used to achieve exploits. Even so, Aave is seeing AI surface new categories of vulnerabilities, including issues previously deprioritized by human auditors. The breadth of AI-driven threats matters in a system where even smaller vulnerabilities can undermine trust. To defend against offensive AI, Gauntlet and Aave advocate for an AI-centric approach with continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has integrated AI into its workflows for simulations and code review, complementing human-led auditing. Ultimately, the long-term effect of AI on the crypto industry may be less about disruption and more about divergence, with projects that prioritize security better equipped to test and harden systems, and those that do not becoming increasingly vulnerable.