The Impact of Anthropic's Mythos Model on Crypto Industry Security
The introduction of Anthropic's Mythos AI model has sparked a significant shift in the crypto industry's approach to security. For years, the focus has been on defending smart contracts through code audits and vulnerability assessments. However, Mythos, designed to identify and exploit weaknesses across systems, is pushing the industry to look beyond code and into the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the greater risks lie in the infrastructure, including key management systems, signing services, and cryptographic layers. These components are often less visible and outside traditional audit scope. A recent security breach at web infrastructure provider Vercel, which many crypto companies use, exposed customer API keys, prompting crypto projects to review their code and rotate credentials. The breach was attributed to a compromised Google Workspace connection via a third-party AI tool. Mythos belongs to a new class of AI systems that simulate adversaries, exploring how protocols interact and testing how small weaknesses can be combined into real-world exploits. This approach has drawn attention beyond the crypto industry, with banks like JP Morgan exploring AI-driven cyber risk. Early findings from models like Mythos have identified weaknesses in the behind-the-scenes systems that keep crypto platforms secure. Vijender believes AI models are especially valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits may miss. The shift in focus matters in a system built on composability, where DeFi protocols interconnect and share liquidity. While this interconnectedness drives growth, it also creates pathways for risk to spread. Without AI, those dependencies are hard to trace, but with AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. Some industry leaders see Mythos as an acceleration rather than a turning point. Stani Kulechov, founder of Aave Labs, believes AI reflects the dynamics already at play in DeFi's adversarial environment. From this perspective, DeFi is already built for machine-speed attacks, and AI only intensifies an environment that requires constant vigilance. Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. To defend against AI-driven threats, Gauntlet and Aave advocate for changing the security model itself, incorporating continuous auditing, real-time simulation, and systems built with the assumption that breaches will happen. Aave has integrated AI into its workflows, using it for simulations and code review alongside human auditors. The long-term effect of AI on the crypto industry may be less disruption than divergence, with the gap between secure and insecure protocols widening over time.