The Impact of Anthropic's Mythos Model on Crypto Industry Security
The introduction of Anthropic's Mythos AI model has triggered a significant shift in the crypto industry's approach to security. For years, the focus has been on securing smart contracts through audits and vulnerability assessments. However, Mythos, with its ability to identify and exploit weaknesses across systems, is prompting a reevaluation of the infrastructure that underpins these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the greater risks lie in the infrastructure, including key management systems, signing services, bridges, oracle networks, and cryptographic layers. Vijender emphasized that when considering AI-driven threats, he is more concerned about attacks on the human and infrastructure layers rather than smart contract exploits. This concern is highlighted by a recent security breach at web infrastructure provider Vercel, which may have exposed customer API keys, prompting crypto projects to review their security measures. The breach was attributed to a compromised Google Workspace connection via a third-party AI tool. Mythos represents a new class of AI systems designed to simulate adversaries, exploring how protocols interact and testing the combination of small weaknesses into real-world exploits. This approach has drawn attention beyond the crypto industry, with banks like JP Morgan exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems that secure crypto platforms, including technologies that protect keys and handle inter-system communication. Vijender noted that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often overlook. The shift in focus towards infrastructure security is crucial in a system built on composability, where DeFi protocols interconnect and share services. This interconnectedness drives growth but also creates pathways for risk to spread. Without AI, tracing these dependencies is challenging, but with AI, they can be mapped and exploited at scale, leading to a shift from isolated exploits to systemic failures. Some industry leaders view Mythos as an acceleration of existing trends rather than a turning point. Stani Kulechov, founder of Aave Labs, believes AI reflects the dynamics already at play in DeFi's adversarial environment, representing an evolution in the tools used to achieve exploits. Kulechov noted that DeFi is built for machine-speed attacks, with smart contracts executing automatically and defenses operating without human intervention. However, Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. To defend against AI-driven threats, both Gauntlet and Aave advocate for changing the security model, emphasizing continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has integrated AI into its workflows for simulations and code review, complementing human-led auditing. The long-term effect of AI on the crypto industry may be less about disruption and more about divergence, with secure protocols having a greater ability to test and harden systems, and insecure protocols being most at risk. Ultimately, security is no longer about eliminating vulnerabilities but about continuously adapting to a system where those vulnerabilities are constantly rediscovered and recombined.