The Impact of Anthropic's Mythos Model on Crypto Industry Security
The introduction of Mythos, Anthropic's AI model, has sparked a significant shift in the crypto industry's approach to security. For years, decentralized finance has focused on defending smart contracts through code audits and vulnerability assessments. However, Mythos, designed to identify and exploit weaknesses across systems, has expanded attention to the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'the bigger risks sit in infrastructure.' He emphasized that when considering AI-driven threats, he is more concerned about AI-assisted attacks on human and infrastructure layers than smart contract exploits. This includes key management systems, signing services, bridges, oracle networks, and cryptographic layers. These components, often outside traditional audit scope, are less visible than smart contracts. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the importance of reviewing code and rotating credentials. Mythos represents a new class of AI systems that simulate adversaries by exploring protocol interactions and testing small weaknesses to create real-world exploits. This approach has drawn attention beyond crypto, with banks like JP Morgan treating AI-driven cyber risk as systemic. Early findings from models like Mythos have identified vulnerabilities in behind-the-scenes systems, including technology protecting keys and handling communication between systems. Vijender noted that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits may miss. In a system built on composability, where DeFi protocols interconnect and share liquidity, AI can map and exploit dependencies at scale, resulting in a shift from isolated exploits to systemic failures. Industry leaders like Stani Kulechov, founder of Aave Labs, view Mythos as an evolution in the tools used to achieve exploits, rather than a turning point. However, they acknowledge that AI surfaces new categories of vulnerabilities, including issues previously deprioritized by human auditors. To defend against offensive AI, experts recommend adopting an AI-centric approach with continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has already integrated AI into its workflows for simulations and code review, complementing human-led auditing. Ultimately, the long-term effect of AI on the crypto industry may be less disruption than divergence, with projects prioritizing security having a greater ability to test and harden systems. As Hayden Adams, founder and CEO of Uniswap Labs, noted, 'AI gives builders better ways to stress test and harden systems,' and the gap between secure and insecure protocols is likely to widen over time.