Anthropic's Mythos Model Revolutionizes Crypto Security
The introduction of Anthropic's Mythos AI model has sparked a significant transformation in the crypto industry's approach to security. For years, the focus has been on protecting smart contracts through code audits and vulnerability assessments. However, Mythos, with its ability to identify and exploit weaknesses across systems, is shifting attention to the underlying infrastructure that supports these contracts. According to Paul Vijender, head of security at Gauntlet, a risk management firm, the most substantial risks lie in the infrastructure, including key management systems, signing services, bridges, and oracle networks. These components, often overlooked in traditional audits, are now being recognized as critical vulnerabilities. A recent security breach at web infrastructure provider Vercel, which exposed customer API keys, highlights the importance of addressing these infrastructure weaknesses. The breach was attributed to a compromised Google Workspace connection via a third-party AI tool. Mythos belongs to a new class of AI systems designed to simulate adversarial attacks, exploring how protocols interact and testing the potential for small weaknesses to be combined into real-world exploits. This approach has garnered attention beyond the crypto industry, with banks like JP Morgan exploring the use of AI-driven stress testing. Early findings from models like Mythos have identified vulnerabilities in the behind-the-scenes systems that secure crypto platforms, including key protection technology and inter-system communication. Vijender emphasizes the value of AI models in identifying multi-step exploit chains and infrastructure-layer vulnerabilities that traditional audits often miss. The shift in focus towards infrastructure security is crucial in a system built on composability, where DeFi protocols interconnect and build upon each other's services. This interconnectedness drives growth but also creates pathways for risk to spread, as seen in recent bridge exploits. While some industry leaders view Mythos as an acceleration of existing trends, others see it as a turning point in the evolution of AI-driven attacks. Stani Kulechov, founder of Aave Labs, believes AI reflects the dynamics already at play in DeFi's adversarial environment, representing an evolution in the tools used to achieve exploits. To defend against these emerging threats, industry leaders advocate for a shift in the security model, incorporating continuous auditing, real-time simulation, and systems designed with the assumption that breaches will occur. Aave has already integrated AI into its workflows, using it for simulations and code review alongside human auditors. The long-term effect of AI on the crypto industry may be less about disruption and more about divergence, with secure protocols becoming increasingly resilient and insecure ones more vulnerable. As Hayden Adams, founder and CEO of Uniswap Labs, notes, AI provides builders with better tools to stress test and harden systems, potentially widening the gap between secure and insecure protocols over time.