The Impact of Anthropic's Mythos Model on Crypto Industry Security
The introduction of Anthropic's Mythos AI model has sparked a significant shift in the crypto industry's approach to security. For years, the primary focus has been on securing smart contracts through code audits and vulnerability assessments. However, Mythos, with its ability to identify and exploit weaknesses across systems, has redirected attention towards the underlying infrastructure that supports these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the greater risks lie in the infrastructure, including key management systems, signing services, and cryptographic layers. He emphasized that when considering AI-driven threats, the focus should be on AI-assisted attacks against the human and infrastructure layers rather than smart contract exploits. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlighted the importance of robust security measures. The breach was attributed to a compromised Google Workspace connection via a third-party AI tool, Context.ai. Mythos represents a new class of AI systems designed to simulate adversaries, exploring how protocols interact and testing the potential for small weaknesses to be combined into real-world exploits. This approach has garnered attention beyond the crypto space, with banks like JP Morgan exploring the use of AI-driven stress testing tools. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender noted that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often overlook. The interconnected nature of DeFi protocols, which share liquidity and rely on common oracles, creates pathways for risk to spread. The use of AI can map and exploit these dependencies at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. While some industry leaders view Mythos as an acceleration of existing trends rather than a turning point, others see it as an opportunity to enhance security measures. Stani Kulechov, founder of Aave Labs, believes that AI reflects the dynamics already at play in DeFi's adversarial environment and that DeFi is built for machine-speed attacks. To defend against AI-driven threats, Gauntlet and Aave advocate for a change in the security model, incorporating continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. The long-term effect of AI on the crypto industry may be a divergence between secure and insecure protocols, with projects that prioritize security having a greater ability to test and harden systems before launching. As Hayden Adams, founder and CEO of Uniswap Labs, noted, AI gives builders better ways to stress test and harden systems, and the gap between secure and insecure protocols is likely to widen over time.