The Impact of Anthropic's Mythos Model on the Crypto Industry's Security Landscape
The introduction of Anthropic's Mythos AI model has sparked significant concern and uncertainty within the traditional tech and finance sectors, while also driving a substantial shift in the crypto industry's approach to security. For years, the decentralized finance sector has focused on defending smart contracts through code audits, vulnerability cataloging, and common exploit mitigation. However, Mythos, designed to identify and chain weaknesses across systems, is pushing the industry to look beyond code and into the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'the bigger risks sit in infrastructure,' and he is more concerned about AI-assisted attacks on human and infrastructure layers than smart contract exploits. This includes key management systems, signing services, bridges, oracle networks, and cryptographic layers, which are often outside traditional audit scope. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the importance of reviewing code and rotating credentials. The Mythos model, part of a new class of AI systems built to simulate adversaries, explores how protocols interact and tests how small weaknesses can be combined into real-world exploits, drawing attention beyond the crypto industry. Banks like JP Morgan are exploring tools like Mythos for stress testing, and early findings have identified weaknesses in behind-the-scenes systems that keep crypto platforms secure. Vijender notes that AI models are especially valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits never touch. The shift in focus matters in a system built on composability, where DeFi protocols can connect and build on each other's services, creating pathways for risk to spread. Without AI, dependencies are hard to trace, but with AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. Industry leaders see Mythos as an acceleration rather than a turning point, with some noting that AI reflects the dynamics already at play in DeFi's adversarial environment. Aave Labs founder Stani Kulechov believes that AI represents an evolution in the tools used to achieve exploits, and that DeFi is already built for machine-speed attacks. While some see AI as an intensification of existing dynamics, others believe it surfaces new categories of vulnerabilities. To defend against offensive AI, the security model itself must change, with a focus on continuous auditing, real-time simulation, and systems built with the assumption that breaches will happen. Builders may adopt an AI-centric approach, using AI for simulations and code review alongside human auditors. Ultimately, the long-term effect of AI may be less disruption than divergence, with the gap between secure and insecure protocols widening over time.