The Impact of Anthropic's Mythos Model on Crypto Industry Security

The introduction of Mythos, Anthropic's new AI model, is revolutionizing the crypto industry's approach to security. For years, decentralized finance has focused on defending smart contracts through code audits and vulnerability assessments. However, Mythos is shifting attention to the underlying infrastructure that supports these contracts, including key management systems, signing services, and oracle networks. According to Paul Vijender, head of security at Gauntlet, 'The bigger risks sit in infrastructure... I'm less concerned about smart contract exploits and more focused on AI-assisted attacks against the human and infrastructure layers.' A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the importance of securing these often-overlooked components. Mythos is part of a new class of AI systems designed to simulate adversaries, exploring how protocols interact and identifying potential weaknesses. This approach has drawn attention from banks like JP Morgan, which are using tools like Mythos for stress testing. Early findings have identified vulnerabilities in the systems that protect keys and handle communication between systems. Vijender notes that AI models are particularly valuable for discovering multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits may miss. The interconnected nature of DeFi protocols creates pathways for risk to spread, making it essential to prioritize security. Without AI, tracing dependencies is challenging, but with AI, they can be mapped and exploited at scale. Some industry leaders, like Stani Kulechov of Aave Labs, view Mythos as an acceleration of existing trends rather than a turning point. Kulechov believes that AI reflects the dynamics already at play in DeFi's adversarial environment and that DeFi is built for machine-speed attacks. However, Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. To defend against offensive AI, companies like Gauntlet and Aave are adopting an AI-centric approach, incorporating continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has integrated AI into its workflows, using it for simulations and code review alongside human auditors. The long-term effect of AI on the crypto industry may be less disruption than divergence, with secure protocols having a greater ability to test and harden systems before launching. As Hayden Adams, founder and CEO of Uniswap Labs, notes, 'AI gives builders better ways to stress test and harden systems,' and the gap between secure and insecure protocols is likely to widen over time.