The Impact of Anthropic's Mythos Model on the Crypto Industry's Security Landscape
The emergence of Anthropic's Mythos AI model has sparked a significant transformation in the crypto industry's approach to security. For years, the focus has been on safeguarding smart contracts through audits and vulnerability assessments. However, Mythos, designed to identify and exploit weaknesses across systems, is shifting attention towards the underlying infrastructure supporting these contracts. According to Paul Vijender, head of security at Gauntlet, 'the bigger risks reside in infrastructure,' including key management systems, signing services, and cryptographic layers. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the importance of addressing these often-overlooked components. Mythos belongs to a new class of AI systems that simulate adversarial attacks, exploring how small weaknesses can be combined into real-world exploits. This approach has garnered attention from banks like JP Morgan, which are exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified vulnerabilities in the systems protecting keys and handling communication between systems. Vijender emphasizes that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often overlook. The interconnected nature of DeFi protocols creates pathways for risk to spread, as seen in recent bridge exploits. While some industry leaders view Mythos as an acceleration of existing trends, others see it as a turning point. Aave Labs' founder, Stani Kulechov, notes that AI reflects the dynamics already at play in DeFi's adversarial environment, representing an evolution in the tools used to achieve exploits. To defend against AI-driven threats, Gauntlet and Aave advocate for an AI-centric approach, incorporating continuous auditing, real-time simulation, and systems designed with the assumption of potential breaches. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. The long-term effect of AI on the crypto industry may be a divergence between secure and insecure protocols, with projects prioritizing security better equipped to test and harden systems.