The Emergence of Anthropic's Mythos Model: A New Era for Crypto Security

The introduction of Mythos, Anthropic's novel AI model, is prompting a substantial shift in the crypto industry's approach to security. Historically, decentralized finance has focused on fortifying smart contracts through rigorous auditing and vulnerability assessments. However, Mythos, designed to identify and exploit interconnected weaknesses across systems, is redirecting attention towards the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'The more significant risks reside in the infrastructure, particularly in areas such as key management systems, signing services, and bridges, which are often overlooked in traditional audits.' This month, a security breach at web infrastructure provider Vercel, which exposed customer API keys, highlighted the importance of robust infrastructure security. The breach was attributed to a compromised Google Workspace connection via a third-party AI tool. Mythos represents a new class of AI systems that simulate adversarial attacks by exploring potential interactions between protocols and identifying vulnerabilities. This approach has garnered attention beyond the crypto sphere, with banks like JP Morgan exploring AI-driven stress testing. Early findings from models like Mythos have revealed weaknesses in the underlying systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender emphasized the value of AI models in identifying 'multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often miss.' The interconnected nature of DeFi protocols, which facilitates growth but also creates pathways for risk, underscores the importance of AI-driven security assessments. Without AI, tracing dependencies and vulnerabilities is challenging; with AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures. Some industry leaders view Mythos as an acceleration of existing trends rather than a turning point. Stani Kulechov, founder of Aave Labs, noted that AI reflects the dynamics already present in DeFi's adversarial environment. 'Web3 is no stranger to well-funded and motivated adversaries,' Kulechov said. 'AI models represent an evolution in the tools used to achieve exploits.' To counter AI-driven threats, Gauntlet and Aave advocate for an AI-centric security model that incorporates continuous auditing, real-time simulation, and systems designed with the assumption of potential breaches. Aave has integrated AI into its workflows, using it for simulations and code review in conjunction with human auditors. Ultimately, the impact of AI on crypto security may lead to a divergence between secure and insecure protocols, with projects prioritizing security better equipped to test and harden their systems.