What Anthropic’s Mythos Means For Crypto Security

What Anthropic’s Mythos Means For Crypto Security

CNBC

0:00 A recent report from Anthropic says its Mythos AI model found flaws

0:04 in some of the basic security software that helps protect digital systems.

0:08 So what does that mean for cryptocurrency?

0:10 The risk is less in the blockchains themselves and more around the software

0:14 stack that crypto companies depend on to give owners access to their holdings.

0:18 So where do we see the threats from AI in the crypto space?

0:21 It's really to centralized companies,

0:24 companies that run security programs to secure their customers assets.

0:28 It's not the cryptographic keys of the Bitcoin network or the cryptographic

0:31 keys of any other coin that are securing your assets.

0:34 It is actually the company itself.

0:40 Anthropic Mythos is getting attention because it is

0:42 reportedly very good at identifying vulnerabilities in software.

0:46 The company also says that Mythos is more autonomous

0:48 and more capable at software engineering and cybersecurity than prior models,

0:53 which makes it better at working around restrictions.

0:55 That means it can help spot flaws in code

0:58 that humans or existing security tools may have missed.

1:01 But in some cases, Mythos is capable

1:03 of turning those vulnerabilities into working exploits.

1:07 Anthropic says the model found thousands

1:08 of high end critical severity vulnerabilities.

1:11 Anthropic documentation around Mythos suggests one

1:14 of the key issues here may be speed.

1:16 The company says the AI can shorten the time between

1:18 a bug becoming known and attackers figuring out how to weaponize it.

1:22 In other words, once a vulnerability is disclosed,

1:25 defenders may have less time to react.

1:28 At this point, AI is becoming a new class of thinker.

1:31 It's doing things that humans have never done.

1:33 We recently heard the release of the new mythos algorithm from Anthropic,

1:38 and this algorithm is able to.

1:40 And this model is able to find exploits in software that humans

1:43 have looked at for decades and have not found any problems in.

1:47 So it is creating a new class of attacks.

1:50 At the same time, it's creating a new class of defense

1:52 so companies that are able to adapt a genetic and AI

1:55 forward thinking are able to fight against those threats by internally

1:58 checking their own systems against these threats before they emerge.

2:02 Protocols like Bitcoin are probably not impacted by something like

2:06 this, because the code itself for Bitcoin is relatively simple.

2:10 If the whole premise of Mythos is using

2:13 agents to pour over code to look for flaws.

2:16 Something like Bitcoin that's been around since 2009,

2:18 whose code is actually very simple.

2:21 And really security lies in the decentralized economic security

2:25 of it rather than necessarily the code based security.

2:29 When people talk about AI and its effect on Bitcoin,

2:32 it's important to understand that Bitcoin is fundamentally

2:34 secured by cryptography and a set of shared rules.

2:37 The cryptography itself isn't affected by AI,

2:39 and the shared rules are enforced by a network

2:42 of people running Bitcoin nodes all over the world.

2:44 So while AI can influence how those people think in some way,

2:48 it really is very difficult to modify the rules

2:50 of the network without really full consensus from the network.

2:53 That means Bitcoin itself may not be where the risk is.

2:56 Instead, retail facing platforms and apps may be more vulnerable.

3:00 So in particular, if you have a website

3:02 that is tied towards the retail customers,

3:07 you have to have an internet like web based

3:10 browser or like mobile apps that connect with consumers.

3:14 I think that kind of platforms are kind of like maybe easier for AI

3:20 agents to attack because they have the fixed target that they can go after.

3:27 And so I would highlight some of these retail oriented

3:30 platform that could be more vulnerable to this kind of attack.

3:37 Now, as blockchain has grown more over time,

3:40 certainly there are a lot of applications that are more complex now,

3:42 and there are more applications that are that have some bits

3:46 of the process that are closed source or that are not fully open source.

3:50 And therein lies a little bit more risk.

3:52 Anthropic reported that Mythos found ways to bypass authentication

3:55 that allowed unauthorized users to give themselves administrator privileges.

4:00 It also figured out how to bypass account login features,

4:03 like getting in without a password or two factor authentication code.

4:07 Anthropic also suggested that bad actors can use denial of service

4:10 attacks to remotely delete data or crash web based services.

4:13 That's where the risk factor really increases.

4:15 It is probably going to the companies

4:17 that have the most capital associated with them, right?

4:19 These things like exchanges or trading applications where customers are

4:25 depositing funds and have a lot of funds on those platforms,

4:28 they will more likely be the ones that are targeted.

4:31 If AI gets better at finding flaws in those building blocks,

4:33 that could create new risks for the apps

4:35 and services people use to store and use crypto.

4:38 Ai is making social engineering attacks very, very easy and very low cost,

4:43 which means that an AI can go around and call a bunch of people,

4:46 pretend to be someone they know, and try to coerce them to give up

4:50 their pass phrases seed phrases and other cryptographic keys.

4:54 And this is actually the biggest attack vector right now.

4:56 It has been for a long time, but AI is making that easier.

4:59 Anthropic advises that the next steps to combating

5:01 the vulnerabilities would be to shorten patch cycles.

5:04 When software updates and security fixes are tested,

5:06 approved and deployed to systems,

5:08 which would include tightening and patching enforcement

5:11 window and enabling auto update wherever possible.

5:14 Because they are more vulnerable, I would also imagine these companies

5:19 will also invest more into these counter-attack,

5:23 like how they can protect against these AI agents.

5:25 At the same time, if they can attack these companies.

5:28 Crypto companies like Coinbase and others can also leverage

5:31 these AI agents to defend against these AI agents as well.

5:35 So you have to see it in both ways.

5:37 The AI cat is out of the bag.

5:40 It's impossible to put back.

5:41 And every day we see somebody innovate on a model.

5:43 And then the very next day,

5:45 the same model is improved across somewhere across the world.

5:47 So the knowledge sharing is happening in real time.

5:50 We've got the internet.

5:50 We cannot put this cat back in the bag.

5:52 So unfortunately, we're going to have to live with it,

5:54 which means we all have to level up and we're going

5:57 to be buying those solutions from the very companies that created the problems.

6:01 But there's also lots of open source work being done here

6:03 and lots of free work by very smart people across the world.

6:06 So I think this is ultimately a net benefit for humanity,

6:09 but it's going to be a period of time where we

6:12 struggle to understand what exactly to do with all of this.

Study with Looplines Download Captions Watch on YouTube