The Impact of Anthropic's Mythos Model on Crypto Industry Security

The introduction of Anthropic's Mythos AI model has sparked a significant shift in the crypto industry's approach to security. For years, the primary focus has been on safeguarding smart contracts through auditing, vulnerability cataloging, and understanding common exploits. However, Mythos, designed to identify and link weaknesses across systems, is expanding attention to the underlying infrastructure. Paul Vijender, head of security at Gauntlet, emphasizes that the greater risks lie in infrastructure, including key management systems, signing services, bridges, and oracle networks. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, underscores the importance of reviewing code and rotating credentials. Mythos represents a new class of AI systems that simulate adversaries, exploring how protocols interact and testing the combination of small weaknesses into real-world exploits. This approach has drawn attention beyond the crypto industry, with banks like JP Morgan exploring AI-driven cyber risk. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems securing crypto platforms, including key protection technology and inter-system communication. According to Vijender, AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often overlook. The interconnected nature of DeFi protocols, which share liquidity and rely on common oracles, creates pathways for risk to spread. Without AI, these dependencies are difficult to trace, but with AI, they can be mapped and exploited at scale. Industry leaders like Stani Kulechov of Aave Labs view Mythos as an evolution rather than a turning point, as DeFi is already built for machine-speed attacks. However, AI surfaces new categories of vulnerabilities, including issues previously deprioritized by human auditors. To defend against offensive AI, a shift towards an AI-centric approach with continuous auditing, real-time simulation, and systems designed with the assumption of breaches is necessary. Aave has integrated AI into its workflows for simulations and code review, complementing human-led auditing. Ultimately, the long-term effect of AI on the crypto industry may be less disruption and more divergence, with secure protocols widening the gap with insecure ones.