The Impact of Anthropic's Mythos Model on Crypto Industry Security
The introduction of Mythos, a cutting-edge AI model developed by Anthropic, has sparked widespread concern and confusion within the traditional tech and finance sectors. However, it is also driving a significant shift in the way the crypto industry approaches security. For years, the primary focus of decentralized finance has been on fortifying smart contracts through code audits and vulnerability assessments. Nevertheless, Mythos, which is designed to identify and exploit weaknesses across systems, is redirecting attention towards the underlying infrastructure that supports these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the most substantial risks lie in the infrastructure, including key management systems, signing services, bridges, oracle networks, and cryptographic layers. These components are often less visible and fall outside the traditional scope of audits. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the importance of reviewing and rotating credentials. The breach was attributed to a compromised Google Workspace connection via a third-party AI tool. Mythos is part of a new class of AI systems built to simulate adversarial attacks. Instead of scanning for known bugs, it explores how protocols interact and tests how small weaknesses can be combined into real-world exploits. This approach has garnered attention beyond the crypto industry, with banks like JP Morgan exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems that keep crypto platforms secure, including the technology that protects keys and handles communication between systems. Vijender believes that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often overlook. The shift in focus towards infrastructure security is crucial in a system built on composability, where DeFi protocols can connect and build on each other's services. This interconnectedness has driven growth but also creates pathways for risk to spread. Without AI, tracing these dependencies is challenging, but with AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. Some industry leaders view Mythos as an acceleration rather than a turning point. Stani Kulechov, founder of Aave Labs, believes that AI reflects the dynamics already at play in DeFi's adversarial environment. According to Kulechov, AI models represent an evolution in the tools used to achieve exploits, and DeFi is already built for machine-speed attacks. However, Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. The answer to defending against offensive AI lies in changing the security model itself, with a focus on continuous auditing, real-time simulation, and systems built with the assumption that breaches will happen. Aave has integrated AI into its workflows, using it for simulations and code review alongside human auditors. The long-term effect of AI on the crypto industry may be less disruption than divergence, with secure protocols having a greater ability to test and harden systems before launching, while insecure protocols will be most at risk.