The Impact of Anthropic's Mythos Model on the Crypto Industry's Security Landscape

The introduction of Anthropic's Mythos AI model has sparked a significant shift in the crypto industry's approach to security. For years, the focus has been on smart contract security, with code audits and vulnerability assessments being the primary defenses. However, Mythos, which is designed to identify and chain together weaknesses across systems, is pushing the industry to look beyond code and into the underlying infrastructure that supports it. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'the bigger risks sit in infrastructure,' and the industry needs to focus on AI-assisted attacks against the human and infrastructure layers. This includes key management systems, signing services, bridges, oracle networks, and the cryptographic layers that connect them. The recent security breach at web infrastructure provider Vercel, which may have exposed customer API keys, highlights the importance of securing these components. Mythos belongs to a new class of AI systems built to simulate adversaries, and its approach has drawn attention beyond the crypto industry. Banks like JP Morgan are exploring tools like Mythos for stress testing, and crypto companies like Coinbase and Binance are also interested in testing the model. The early findings from models like Mythos have identified weaknesses in the behind-the-scenes systems that keep crypto platforms secure, including the technology that protects keys and handles communication between systems. Vijender notes that AI models are especially valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits may miss. The shift towards AI-driven security is particularly important in a system built on composability, where DeFi protocols can connect and build on each other's services. While some industry leaders see Mythos as an acceleration rather than a turning point, others believe that AI reflects the dynamics already at play in DeFi's adversarial environment. Stani Kulechov, founder of Aave Labs, notes that 'web3 is no stranger to well-funded and motivated adversaries,' and AI models represent an evolution in the tools used to achieve exploits. However, even if AI doesn't introduce a new dynamic, it intensifies an environment that has always required constant vigilance. To defend against offensive AI, the industry needs to take an AI-centric approach, with continuous auditing, real-time simulation, and systems built with the assumption that breaches will happen. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. Ultimately, the long-term effect of AI on the crypto industry may be less disruption than divergence, with secure protocols having a greater ability to test and harden systems before launching, while insecure protocols will be most at risk.