How Anthropic's Mythos Model is Revolutionizing the Crypto Industry's Approach to Security
The introduction of Anthropic's Mythos model has sparked a significant shift in the crypto industry's perception of security. For years, decentralized finance has focused on safeguarding smart contracts through auditing and vulnerability assessments. However, Mythos, an AI model designed to identify and exploit weaknesses across systems, is driving attention towards the often-overlooked infrastructure that underpins these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the most significant risks lie in the infrastructure that supports smart contracts. 'When I think about AI-driven threats, I'm less concerned about smart contract exploits and more focused on AI-assisted attacks against the human and infrastructure layers,' he said. These components, including key management systems, signing services, bridges, oracle networks, and cryptographic layers, are frequently outside the scope of traditional audits. A recent security breach at web infrastructure provider Vercel, which many crypto companies rely on, highlights the importance of addressing these vulnerabilities. The breach, which may have exposed customer API keys, was attributed to a compromised Google Workspace connection via a third-party AI tool. Mythos represents a new class of AI systems built to simulate adversaries, exploring how protocols interact and testing how small weaknesses can be combined into real-world exploits. This approach has drawn attention from banks like JP Morgan, which are increasingly treating AI-driven cyber risk as systemic and exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified weaknesses in the behind-the-scenes systems that keep crypto platforms secure, including the technology that protects keys and handles communication between systems. Vijender believes that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often miss. The shift towards AI-driven security matters in a system built on composability, where DeFi protocols can connect and build on each other's services. DeFi protocols are designed to interconnect, sharing liquidity and relying on common oracles, which creates pathways for risk to spread. The use of AI can help map and exploit these dependencies at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. While some industry leaders see Mythos as an acceleration rather than a turning point, others believe that AI reflects the dynamics already at play in DeFi's adversarial environment. Stani Kulechov, founder of Aave Labs, notes that AI models represent an evolution in the tools used to achieve exploits, rather than introducing a new dynamic. To defend against AI-driven threats, Gauntlet and Aave are changing their security models, incorporating continuous auditing, real-time simulation, and systems built with the assumption that breaches will happen. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. Ultimately, the emergence of AI-powered threats may lead to a divergence in the crypto industry, with projects that prioritize security having a greater ability to test and harden systems before launching. As Hayden Adams, founder and CEO of Uniswap Labs, notes, 'AI gives builders better ways to stress test and harden systems.' Over time, the gap between secure and insecure protocols is likely to widen, with projects that don't prioritize security being most at risk.