Revolutionizing Crypto Security: How Anthropic's Mythos Model is Redefining the Industry
The introduction of Mythos, a groundbreaking AI model developed by Anthropic, has sent shockwaves through the traditional tech and finance sectors, and is now driving a seismic shift in the crypto industry's approach to security. For years, decentralized finance has focused primarily on safeguarding smart contracts through rigorous auditing and vulnerability assessments. However, Mythos, with its ability to identify and exploit weaknesses across entire systems, is compelling the industry to look beyond code and delve into the underlying infrastructure that supports it. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'the bigger risks reside in infrastructure.' Vijender emphasized that when considering AI-driven threats, his primary concern lies not with smart contract exploits, but rather with AI-assisted attacks targeting the human and infrastructure layers. This includes key management systems, signing services, bridges, oracle networks, and the cryptographic layers that connect them – components that are often less visible and frequently outside the scope of traditional audits. In fact, a recent security breach disclosed by web infrastructure provider Vercel, which many crypto companies utilize, may have exposed customer API keys, prompting crypto projects to reevaluate their credentials and review their code. The breach was attributed to a compromised Google Workspace connection via the third-party AI tool Context.ai, used by an employee. Mythos represents a new class of AI systems designed to simulate adversaries, exploring how protocols interact and testing how minor weaknesses can be combined into real-world exploits. This approach has garnered attention beyond the crypto sphere, with banks like JP Morgan increasingly treating AI-driven cyber risk as systemic and exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems that secure crypto platforms, including technologies that protect keys and facilitate communication between systems. Vijender noted that AI models are particularly valuable in two areas: 'First, multi-step exploit chains that historically only get discovered after money is lost. Second, infrastructure-layer vulnerabilities that traditional audits never touch.' This shift is significant in a system built on composability, where DeFi protocols can interconnect and build upon each other's services. DeFi protocols are designed to be interconnected, sharing liquidity, relying on common oracles, and interacting through layers of integrations that are challenging to map in full. This interconnectedness has driven growth but also creates pathways for risk to spread, as seen in recent bridge exploits like the Hyperbridge attack. 'Composability is what makes DeFi capital efficient and innovative,' Vijender said. 'But it also means a minor vulnerability in one protocol can become a critical exploit vector with contagion potential across the ecosystem.' Without AI, these dependencies are difficult to trace. With AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. Some industry leaders view Mythos as an acceleration rather than a turning point. Stani Kulechov, founder of Aave Labs, believes AI reflects the dynamics already at play in DeFi's adversarial environment. 'Web3 is no stranger to well-funded and motivated adversaries,' he said. 'AI models represent an evolution in the tools used to achieve exploits.' From this perspective, DeFi is already built for machine-speed attacks, with smart contracts executing automatically and defenses such as liquidation mechanisms and risk parameters operating without human intervention. 'DeFi operates at compute speed, so AI doesn't introduce a new dynamic,' Kulechov said. 'It intensifies an environment that has always required constant vigilance.' Even so, Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. 'The Mythos paper shows that AI can uncover old bugs that were previously deprioritized,' he said. This breadth still matters in a system where even smaller vulnerabilities can undermine trust or be combined into larger exploits. If attackers can move faster, the question becomes whether defenses can keep pace. For both Gauntlet and Aave, the answer lies in changing the security model itself. Audits before deployment and monitoring after were designed for human-paced threats. AI compresses that timeline. 'To defend against offensive AI, we will need to take an AI-centric approach where speed and continuous adaptation are essential,' Vijender of Gauntlet said. This includes continuous auditing, real-time simulation, and systems built with the assumption that breaches will happen. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. 'We take an AI-first approach where it adds clear value,' Kulechov of Aave Labs said. 'But it complements, rather than replaces, human-led auditing.' In this sense, AI equips both attackers and defenders. For builders, the long-term effect may be less disruption than divergence. 'We haven’t tested Mythos yet, but we’re genuinely interested in what it and tools like it can do for protocol security,' said Hayden Adams, founder and CEO of Uniswap Labs. 'AI gives builders better ways to stress test and harden systems.' Over time, Adams expects the gap between secure and insecure protocols to widen. 'Projects that prioritize security will have greater ability to test and harden systems before launching,' he said. 'Projects that don’t will be most at risk.' This may be the real shift. Security is no longer about eliminating vulnerabilities; it is about continuously adapting to a system in which those vulnerabilities are constantly rediscovered and recombined.