The Impact of Anthropic's Mythos Model on Crypto Security
The introduction of Anthropic's Mythos AI model has sparked a significant shift in the way the crypto industry approaches security. For years, the primary focus of decentralized finance has been on securing smart contracts through auditing and identifying vulnerabilities. However, Mythos, with its ability to identify and chain together weaknesses across systems, is pushing the industry to look beyond code and into the underlying infrastructure. This includes key management systems, signing services, bridges, oracle networks, and cryptographic layers, which are often less visible and outside traditional audit scope. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the importance of this expanded focus. The breach was traced to a compromised Google Workspace connection via a third-party AI tool, demonstrating the potential for AI-driven threats to target human and infrastructure layers. Mythos belongs to a new class of AI systems designed to simulate adversaries, exploring how protocols interact and testing how small weaknesses can be combined into real-world exploits. This approach has drawn attention beyond the crypto industry, with banks like JP Morgan exploring the use of AI-driven stress testing. Early findings from models like Mythos have identified weaknesses in the behind-the-scenes systems that keep crypto platforms secure, including technology that protects keys and handles communication between systems. According to Paul Vijender, head of security at Gauntlet, AI models are especially valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits may miss. The shift towards AI-driven security matters in a system built on composability, where DeFi protocols can connect and build on each other's services. While some industry leaders see Mythos as an acceleration rather than a turning point, others believe it represents an evolution in the tools used to achieve exploits. Aave Labs founder Stani Kulechov notes that AI reflects the dynamics already at play in DeFi's adversarial environment, intensifying an environment that has always required constant vigilance. To defend against offensive AI, companies like Gauntlet and Aave are adopting an AI-centric approach, incorporating continuous auditing, real-time simulation, and systems built with the assumption that breaches will happen. The long-term effect of AI on crypto security may be less disruption than divergence, with secure protocols having a greater ability to test and harden systems before launching, while insecure protocols will be most at risk.