The Impact of Anthropic's Mythos Model on the Crypto Industry's Security Landscape
The introduction of Anthropic's Mythos AI model has sparked a significant shift in the crypto industry's approach to security. For years, the primary focus has been on securing smart contracts through auditing and vulnerability cataloging. However, Mythos, with its capability to identify and exploit weaknesses across entire systems, is prompting a broader examination of the infrastructure supporting these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the greater risks lie in the infrastructure, including key management systems, signing services, bridges, and oracle networks. These components, often overlooked in traditional audits, are now under scrutiny. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, underscores the importance of this expanded focus. The breach, attributed to a compromised Google Workspace connection via a third-party AI tool, has led crypto projects to reevaluate their security measures. Mythos represents a new class of AI systems designed to simulate adversarial attacks, exploring how small weaknesses can be combined into significant exploits. This approach has drawn attention from beyond the crypto space, with banks like JP Morgan exploring AI-driven cyber risk management. Early findings from models like Mythos have highlighted vulnerabilities in the systems securing crypto platforms, including key protection technology and inter-system communication. Vijender notes that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits may miss. The interconnected nature of DeFi protocols, which share liquidity and rely on common oracles, creates pathways for risk to spread. While composability drives growth and innovation, it also increases the potential for systemic failures. Without AI, tracing these dependencies is challenging. With AI, they can be mapped and exploited on a large scale, shifting the focus from isolated exploits to systemic failures that cascade across protocols. Industry leaders like Stani Kulechov of Aave Labs view Mythos as an evolution rather than a revolution, reflecting the existing dynamics in DeFi's adversarial environment. However, they acknowledge that AI intensifies the need for constant vigilance and introduces new categories of vulnerabilities. To keep pace with AI-driven threats, defenses must adapt. Both Gauntlet and Aave advocate for an AI-centric security model, emphasizing continuous auditing, real-time simulation, and systems designed with the assumption of potential breaches. Aave has already integrated AI into its workflows for simulations and code review, complementing human auditors. This AI-first approach equips both attackers and defenders, potentially leading to a divergence where secure protocols thrive, and insecure ones are left vulnerable. Ultimately, the impact of Mythos and similar AI models may not be disruption but a widening gap between secure and insecure protocols, with security becoming a continuous adaptation to an ever-evolving landscape of vulnerabilities.