The Impact of Anthropic's Mythos Model on the Crypto Industry's Security Landscape
The emergence of Mythos, Anthropic's novel AI model, has sparked widespread concern and confusion across traditional tech and finance, prompting a significant shift in the crypto industry's approach to security. Historically, decentralized finance has focused on fortifying its defenses through smart contract audits, cataloging vulnerabilities, and understanding common exploits. However, Mythos, designed to identify and exploit weaknesses across systems, is driving attention towards the underlying infrastructure that supports these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'The greater risks reside in the infrastructure.' Vijender emphasized that when considering AI-driven threats, his primary concern lies not with smart contract exploits but with AI-assisted attacks targeting human and infrastructure layers. These components include key management systems, signing services, bridges, oracle networks, and the cryptographic layers connecting them. Unlike smart contracts, these elements are less visible and often fall outside the traditional audit scope. Recently, web infrastructure provider Vercel disclosed a security breach potentially exposing customer API keys, prompting crypto projects to review their code and rotate credentials. The breach was attributed to a compromised Google Workspace connection via the third-party AI tool Context.ai used by an employee. Mythos represents a new class of AI systems engineered to simulate adversaries, exploring how protocols interact and testing how minor weaknesses can be combined into real-world exploits. This approach has garnered attention beyond the crypto sphere, with banks like JP Morgan treating AI-driven cyber risk as systemic and exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems securing crypto platforms, including technologies protecting keys and handling inter-system communication. Vijender highlighted two key areas where AI models offer significant value: 'First, multi-step exploit chains that historically only get discovered after financial losses have occurred. Second, infrastructure-layer vulnerabilities that traditional audits often overlook.' This shift is particularly significant in a system built on composability, where DeFi protocols can interconnect and build upon each other's services. The interconnected nature of DeFi has driven growth but also creates pathways for risk to spread, as seen in recent bridge exploits. Composability is what makes DeFi capital-efficient and innovative, but it also means a minor vulnerability in one protocol can become a critical exploit vector with contagion potential across the ecosystem. Without AI, tracing these dependencies is challenging. With AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures cascading across protocols. The evolution of AI attacks has led some industry leaders to view Mythos as an acceleration rather than a turning point. Stani Kulechov, founder of Aave Labs, noted that AI reflects the dynamics already at play in DeFi's adversarial environment, representing an evolution in the tools used to achieve exploits. From this perspective, DeFi is already built for machine-speed attacks, with smart contracts executing automatically and defenses operating without human intervention. Kulechov emphasized that AI doesn't introduce a new dynamic but intensifies an environment that has always required constant vigilance. However, Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. The breadth of these findings matters in a system where even smaller vulnerabilities can undermine trust or be combined into larger exploits. If attackers can move faster, the question becomes whether defenses can keep pace. For both Gauntlet and Aave, the answer lies in changing the security model itself, incorporating continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has integrated AI into its workflows for simulations and code review alongside human auditors, adopting an AI-first approach where it adds clear value but complements human-led auditing. In this context, AI equips both attackers and defenders, potentially leading to a divergence in the long term. Builders may find that the real shift is not about eliminating vulnerabilities but about continuously adapting to a system where those vulnerabilities are constantly rediscovered and recombined. Hayden Adams, founder and CEO of Uniswap Labs, expressed genuine interest in what tools like Mythos can do for protocol security, believing AI gives builders better ways to stress test and harden systems. Over time, Adams expects the gap between secure and insecure protocols to widen, with projects prioritizing security having a greater ability to test and harden systems before launching.