The Impact of Anthropic's Mythos Model on Crypto Industry Security

The introduction of Mythos, a novel AI model by Anthropic, has sparked a paradigm shift in the crypto industry's approach to security. For years, the primary focus of decentralized finance has been on fortifying smart contracts through auditing, vulnerability cataloging, and understanding common exploits. However, Mythos, designed to identify and exploit system weaknesses, is redirecting attention towards the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'The bigger risks sit in infrastructure... When I think about AI-driven threats, I’m less concerned about smart contract exploits and more focused on AI-assisted attacks against the human and infrastructure layers.' This includes components like key management systems, signing services, bridges, oracle networks, and cryptographic layers, which are less visible and often outside traditional audit scope. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, underscores the importance of reevaluating security protocols. Mythos, part of a new class of AI systems simulating adversaries, explores how protocols interact and tests the combination of small weaknesses into real-world exploits. This approach has garnered attention beyond the crypto sphere, with banks like JP Morgan exploring tools like Mythos for stress testing. Early findings have highlighted vulnerabilities in the systems securing crypto platforms, including key protection technology and inter-system communication. Vijender notes, 'I think there are two areas where AI models are especially valuable: First, multi-step exploit chains that historically only get discovered after money is lost. Second, infrastructure-layer vulnerabilities that traditional audits never touch.' The interconnected nature of DeFi protocols, which share liquidity and rely on common oracles, creates pathways for risk to spread. The introduction of AI exacerbates this by enabling the mapping and exploitation of dependencies at scale, leading to systemic failures that cascade across protocols. While some industry leaders view Mythos as an acceleration of existing trends, others see it as a turning point. Stani Kulechov, founder of Aave Labs, believes AI reflects the dynamics already at play in DeFi's adversarial environment, representing an evolution in the tools used for exploits. However, Aave is seeing AI surface new categories of vulnerabilities, including previously deprioritized issues. To counter AI-driven threats, both Gauntlet and Aave advocate for changing the security model, emphasizing continuous auditing, real-time simulation, and systems designed with the assumption of breaches. Aave has integrated AI into its workflows for simulations and code review, complementing human-led auditing. The long-term effect of AI on the crypto industry may be less about disruption and more about divergence, with secure protocols having a greater ability to test and harden systems, thus widening the gap between secure and insecure projects.