The Impact of Anthropic's Mythos Model on Crypto Industry Security

The emergence of Anthropic's Mythos AI model has sparked a significant shift in the crypto industry's approach to security. For years, decentralized finance has focused on bolstering smart contract defenses through rigorous audits and vulnerability assessments. However, Mythos, with its ability to identify and exploit weaknesses across entire systems, is prompting a broader examination of the infrastructure that underpins these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the most substantial risks lie in the infrastructure supporting these contracts. 'When I consider AI-driven threats, my primary concern is not smart contract exploits, but rather AI-assisted attacks targeting the human and infrastructure layers,' he said. This encompasses key management systems, signing services, bridges, oracle networks, and the cryptographic layers that connect them. These components are often less visible and fall outside the traditional audit scope. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, underscores the importance of scrutinizing these overlooked areas. Mythos represents a new class of AI systems designed to simulate adversarial attacks. By exploring how protocols interact and testing the potential for small weaknesses to be combined into real-world exploits, it has garnered attention beyond the crypto sphere. Banks like JP Morgan are increasingly recognizing AI-driven cyber risk as systemic and exploring tools like Mythos for stress testing purposes. Early findings from models like Mythos have highlighted vulnerabilities in the behind-the-scenes systems that maintain crypto platform security, including key protection technology and inter-system communication. Vijender notes that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often overlook. The significance of this shift lies in the composability of DeFi protocols, which are designed to interconnect and share liquidity. While this interconnectedness drives growth, it also creates pathways for risk to spread. The use of AI can both map and exploit these dependencies at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. Some industry leaders view Mythos as an evolutionary step rather than a revolutionary turning point. Stani Kulechov, founder of Aave Labs, believes AI reflects the existing dynamics in DeFi's adversarial environment. 'Web3 is no stranger to well-funded and motivated adversaries,' he said. 'AI models represent an evolution in the tools used to achieve exploits.' Kulechov argues that DeFi is already built for machine-speed attacks, with smart contracts executing automatically and defenses operating without human intervention. However, Aave is seeing AI uncover new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. To defend against AI-driven threats, both Gauntlet and Aave advocate for a change in the security model itself. This includes adopting an AI-centric approach with continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. Ultimately, the long-term effect of AI on the crypto industry may be less about disruption and more about divergence. Builders who prioritize security will have a greater ability to test and harden systems, while those who do not will be most at risk. As Hayden Adams, founder and CEO of Uniswap Labs, noted, 'AI gives builders better ways to stress test and harden systems.' Over time, the gap between secure and insecure protocols is likely to widen.