The Emergence of Anthropic's Mythos Model: A New Era for Crypto Security
The introduction of Mythos, Anthropic's groundbreaking AI model, is revolutionizing the crypto industry's approach to security. For years, decentralized finance has focused primarily on safeguarding smart contracts through rigorous auditing and vulnerability assessments. However, Mythos, with its ability to identify and exploit weaknesses across entire systems, is prompting a seismic shift in focus towards the underlying infrastructure that supports these contracts. According to Paul Vijender, Head of Security at Gauntlet, a risk management firm, the most significant risks reside in the infrastructure, including key management systems, signing services, bridges, oracle networks, and cryptographic layers. These components, often overlooked in traditional audits, are now under scrutiny. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, underscores the importance of this new focus. The breach, attributed to a compromised Google Workspace connection via a third-party AI tool, has prompted crypto projects to reevaluate their security measures. Mythos represents a new class of AI systems designed to simulate adversarial attacks. By exploring how protocols interact and testing the potential for small weaknesses to be combined into real-world exploits, Mythos has garnered attention beyond the crypto sphere, with banks like JP Morgan exploring its potential for stress testing. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender highlights two areas where AI models are particularly valuable: identifying multi-step exploit chains and uncovering infrastructure-layer vulnerabilities that traditional audits often miss. The interconnected nature of DeFi protocols, which share liquidity and rely on common oracles, creates pathways for risk to spread. AI can map and exploit these dependencies at scale, resulting in a shift from isolated exploits to systemic failures that cascade across protocols. Some industry leaders view Mythos as an acceleration of existing trends rather than a turning point. Stani Kulechov, founder of Aave Labs, believes that AI reflects the dynamics already at play in DeFi's adversarial environment, representing an evolution in the tools used to achieve exploits. However, others argue that AI introduces a new dynamic, requiring constant vigilance and a shift in the security model itself. To defend against AI-driven threats, Gauntlet and Aave advocate for an AI-centric approach, incorporating continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. This AI-first approach complements, rather than replaces, human-led auditing, equipping both attackers and defenders with new tools. The long-term effect of AI on the crypto industry may be less about disruption and more about divergence, with secure and insecure protocols becoming increasingly distinct. Projects that prioritize security will have a greater ability to test and harden systems, while those that do not will be most at risk. Ultimately, security is no longer about eliminating vulnerabilities but about continuously adapting to a system where those vulnerabilities are constantly rediscovered and recombined.