The Impact of Anthropic's Mythos Model on Crypto Industry Security
The introduction of Mythos, a cutting-edge AI model developed by Anthropic, has sparked significant concern and uncertainty within the traditional tech and finance sectors, while also driving a substantial shift in the way the crypto industry approaches security. For years, the primary focus of decentralized finance has been on bolstering defenses for smart contracts, with code audits, vulnerability cataloging, and common exploit mitigation being key areas of attention. However, Mythos, designed to pinpoint and chain together system vulnerabilities, is now pushing the industry to look beyond code and delve into the underlying infrastructure that supports it. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the most significant risks reside in the infrastructure, and when considering AI-driven threats, the focus should be on AI-assisted attacks targeting human and infrastructure layers, rather than just smart contract exploits. This encompasses key management systems, signing services, bridges, oracle networks, and the cryptographic layers that connect them – components that are often less visible and outside the scope of traditional audits. In fact, this month, web infrastructure provider Vercel disclosed a security breach that may have exposed customer API keys, prompting crypto projects to review their code and rotate credentials. The breach was attributed to a compromised Google Workspace connection via the third-party AI tool Context.ai, used by an employee. Mythos represents a new class of AI systems designed to simulate adversaries, exploring how protocols interact and testing how small weaknesses can be combined into real-world exploits, rather than just scanning for known bugs. This approach has drawn attention beyond the crypto space, with banks like JP Morgan treating AI-driven cyber risk as systemic and exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender highlights two key areas where AI models are particularly valuable: multi-step exploit chains that are often only discovered after funds have been lost, and infrastructure-layer vulnerabilities that traditional audits may miss. This shift matters in a system built on composability, where DeFi protocols can connect and build upon each other's services, sharing liquidity and relying on common oracles. The interconnectedness of DeFi has driven growth but also creates pathways for risk to spread, as seen in recent bridge exploits. Without AI, tracing these dependencies is challenging; with AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. While some industry leaders view Mythos as an acceleration of existing trends rather than a turning point, others see it as a catalyst for change. Aave Labs founder Stani Kulechov notes that AI reflects the dynamics already at play in DeFi's adversarial environment, with AI models representing an evolution in the tools used to achieve exploits. From this perspective, DeFi is already built for machine-speed attacks, with smart contracts executing automatically and defenses operating without human intervention. However, Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. To defend against offensive AI, the security model itself must change, with audits, monitoring, and systems designed to assume breaches will happen. Both Gauntlet and Aave are adopting AI-centric approaches, incorporating continuous auditing, real-time simulation, and AI-driven code review alongside human auditors. Ultimately, the long-term effect of AI on the crypto industry may be less about disruption and more about divergence, with secure protocols having a greater ability to test and harden systems, while insecure ones will be most at risk.