The Impact of Anthropic's Mythos Model on Crypto Industry Security
The emergence of Anthropic's Mythos AI model has triggered a significant shift in the crypto industry's approach to security. For years, the focus has been on smart contract security, with code audits and vulnerability assessments being the primary lines of defense. However, Mythos, with its ability to identify and exploit weaknesses across systems, has expanded the scope of security concerns to include the underlying infrastructure. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the greater risks lie in the infrastructure, including key management systems, signing services, and oracle networks. These components, often overlooked in traditional audits, are now being recognized as critical vulnerabilities. The recent security breach at Vercel, a web infrastructure provider, which may have exposed customer API keys, highlights the importance of securing these infrastructure layers. The breach, attributed to a compromised Google Workspace connection via a third-party AI tool, has prompted crypto projects to re-evaluate their security measures. Mythos, as a simulation-based AI system, is designed to test protocol interactions and identify potential exploit chains. This approach has attracted attention from banks like JP Morgan, which are exploring the use of AI-driven stress testing. Early findings from models like Mythos have revealed weaknesses in the behind-the-scenes systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender emphasizes the value of AI models in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often miss. The interconnected nature of DeFi protocols, which share liquidity and rely on common oracles, creates pathways for risk to spread. The use of AI can help map and exploit these dependencies at scale, resulting in a shift from isolated exploits to systemic failures. While some industry leaders view Mythos as an acceleration of existing trends, others see it as a turning point in the evolution of AI-driven attacks. Stani Kulechov, founder of Aave Labs, believes that AI reflects the dynamics already at play in DeFi's adversarial environment, where well-funded and motivated adversaries are common. The integration of AI into security workflows, as seen in Aave's use of AI for simulations and code review, is becoming increasingly important. To defend against AI-driven threats, a new security model is emerging, one that emphasizes continuous auditing, real-time simulation, and the assumption that breaches will occur. The long-term effect of AI on the crypto industry may be a divergence between secure and insecure protocols, with those prioritizing security having a greater ability to test and harden systems.