The Impact of Anthropic's Mythos Model on the Crypto Industry's Security Landscape
The emergence of Anthropic's Mythos AI model has sparked significant concern and confusion within the traditional tech and finance sectors, but it is also driving a substantial shift in the crypto industry's approach to security. For years, decentralized finance has focused on fortifying its defenses through smart contract audits, vulnerability assessments, and familiarity with common exploits. However, Mythos, an AI model designed to identify and exploit weaknesses across systems, is expanding the industry's attention beyond code to the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, 'the bigger risks sit in infrastructure,' and when considering AI-driven threats, his primary concern lies in AI-assisted attacks against human and infrastructure layers, including key management systems, signing services, bridges, oracle networks, and cryptographic layers. These components are often less visible and fall outside traditional audit scopes. A recent security breach disclosed by web infrastructure provider Vercel, which many crypto companies utilize, may have exposed customer API keys, prompting crypto projects to rotate credentials and review their code. The breach was attributed to a compromised Google Workspace connection via the third-party AI tool Context.ai. Mythos represents a new class of AI systems built to simulate adversaries, exploring how protocols interact and testing how small weaknesses can be combined into real-world exploits. This approach has garnered attention beyond the crypto sphere, with banks like JP Morgan treating AI-driven cyber risk as systemic and exploring tools like Mythos for stress testing. Early findings from models like Mythos have identified weaknesses in the behind-the-scenes systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender notes that AI models are particularly valuable in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often overlook. The shift in focus matters significantly in a system built on composability, where DeFi protocols interconnect, share liquidity, and rely on common oracles, creating pathways for risk to spread. DeFi protocols are designed to be interconnected, which drives growth but also creates potential exploit vectors. Without AI, these dependencies are challenging to trace, but with AI, they can be mapped and exploited at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. Some industry leaders view Mythos as an acceleration of existing trends rather than a turning point. Stani Kulechov, founder of Aave Labs, believes AI reflects the dynamics already at play in DeFi's adversarial environment, representing an evolution in the tools used to achieve exploits. From this perspective, DeFi is already built for machine-speed attacks, with smart contracts executing automatically and defenses operating without human intervention. Even so, Aave is seeing AI surface new categories of vulnerabilities, including issues that human auditors may have previously deprioritized. The answer to keeping pace with AI-driven threats lies in changing the security model itself, according to both Gauntlet and Aave. This includes continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has integrated AI into its workflows for simulations and code review alongside human auditors, taking an AI-first approach where it adds clear value but complements human-led auditing. Ultimately, AI equips both attackers and defenders, and for builders, the long-term effect may be less disruption than divergence, with the gap between secure and insecure protocols widening over time. Projects that prioritize security will have a greater ability to test and harden systems before launching, while those that neglect security will be most at risk.