What Anthropic’s Mythos Means For Crypto Security
CNBC
0:00 A recent report from Anthropic says its Mythos AI model found flaws
0:04 in some of the basic security software that helps protect digital systems.
0:08 So what does that mean for cryptocurrency?
0:10 The risk is less in the blockchains themselves and more around the software
0:14 stack that crypto companies depend on to give owners access to their holdings.
0:18 So where do we see the threats from AI in the crypto space?
0:21 It's really to centralized companies,
0:24 companies that run security programs to secure their customers assets.
0:28 It's not the cryptographic keys of the Bitcoin network or the cryptographic
0:31 keys of any other coin that are securing your assets.
0:34 It is actually the company itself.
0:40 Anthropic Mythos is getting attention because it is
0:42 reportedly very good at identifying vulnerabilities in software.
0:46 The company also says that Mythos is more autonomous
0:48 and more capable at software engineering and cybersecurity than prior models,
0:53 which makes it better at working around restrictions.
0:55 That means it can help spot flaws in code
0:58 that humans or existing security tools may have missed.
1:01 But in some cases, Mythos is capable
1:03 of turning those vulnerabilities into working exploits.
1:07 Anthropic says the model found thousands
1:08 of high end critical severity vulnerabilities.
1:11 Anthropic documentation around Mythos suggests one
1:14 of the key issues here may be speed.
1:16 The company says the AI can shorten the time between
1:18 a bug becoming known and attackers figuring out how to weaponize it.
1:22 In other words, once a vulnerability is disclosed,
1:25 defenders may have less time to react.
1:28 At this point, AI is becoming a new class of thinker.
1:31 It's doing things that humans have never done.
1:33 We recently heard the release of the new mythos algorithm from Anthropic,
1:38 and this algorithm is able to.
1:40 And this model is able to find exploits in software that humans
1:43 have looked at for decades and have not found any problems in.
1:47 So it is creating a new class of attacks.
1:50 At the same time, it's creating a new class of defense
1:52 so companies that are able to adapt a genetic and AI
1:55 forward thinking are able to fight against those threats by internally
1:58 checking their own systems against these threats before they emerge.
2:02 Protocols like Bitcoin are probably not impacted by something like
2:06 this, because the code itself for Bitcoin is relatively simple.
2:10 If the whole premise of Mythos is using
2:13 agents to pour over code to look for flaws.
2:16 Something like Bitcoin that's been around since 2009,
2:18 whose code is actually very simple.
2:21 And really security lies in the decentralized economic security
2:25 of it rather than necessarily the code based security.
2:29 When people talk about AI and its effect on Bitcoin,
2:32 it's important to understand that Bitcoin is fundamentally
2:34 secured by cryptography and a set of shared rules.
2:37 The cryptography itself isn't affected by AI,
2:39 and the shared rules are enforced by a network
2:42 of people running Bitcoin nodes all over the world.
2:44 So while AI can influence how those people think in some way,
2:48 it really is very difficult to modify the rules
2:50 of the network without really full consensus from the network.
2:53 That means Bitcoin itself may not be where the risk is.
2:56 Instead, retail facing platforms and apps may be more vulnerable.
3:00 So in particular, if you have a website
3:02 that is tied towards the retail customers,
3:07 you have to have an internet like web based
3:10 browser or like mobile apps that connect with consumers.
3:14 I think that kind of platforms are kind of like maybe easier for AI
3:20 agents to attack because they have the fixed target that they can go after.
3:27 And so I would highlight some of these retail oriented
3:30 platform that could be more vulnerable to this kind of attack.
3:37 Now, as blockchain has grown more over time,
3:40 certainly there are a lot of applications that are more complex now,
3:42 and there are more applications that are that have some bits
3:46 of the process that are closed source or that are not fully open source.
3:50 And therein lies a little bit more risk.
3:52 Anthropic reported that Mythos found ways to bypass authentication
3:55 that allowed unauthorized users to give themselves administrator privileges.
4:00 It also figured out how to bypass account login features,
4:03 like getting in without a password or two factor authentication code.
4:07 Anthropic also suggested that bad actors can use denial of service
4:10 attacks to remotely delete data or crash web based services.
4:13 That's where the risk factor really increases.
4:15 It is probably going to the companies
4:17 that have the most capital associated with them, right?
4:19 These things like exchanges or trading applications where customers are
4:25 depositing funds and have a lot of funds on those platforms,
4:28 they will more likely be the ones that are targeted.
4:31 If AI gets better at finding flaws in those building blocks,
4:33 that could create new risks for the apps
4:35 and services people use to store and use crypto.
4:38 Ai is making social engineering attacks very, very easy and very low cost,
4:43 which means that an AI can go around and call a bunch of people,
4:46 pretend to be someone they know, and try to coerce them to give up
4:50 their pass phrases seed phrases and other cryptographic keys.
4:54 And this is actually the biggest attack vector right now.
4:56 It has been for a long time, but AI is making that easier.
4:59 Anthropic advises that the next steps to combating
5:01 the vulnerabilities would be to shorten patch cycles.
5:04 When software updates and security fixes are tested,
5:06 approved and deployed to systems,
5:08 which would include tightening and patching enforcement
5:11 window and enabling auto update wherever possible.
5:14 Because they are more vulnerable, I would also imagine these companies
5:19 will also invest more into these counter-attack,
5:23 like how they can protect against these AI agents.
5:25 At the same time, if they can attack these companies.
5:28 Crypto companies like Coinbase and others can also leverage
5:31 these AI agents to defend against these AI agents as well.
5:35 So you have to see it in both ways.
5:37 The AI cat is out of the bag.
5:40 It's impossible to put back.
5:41 And every day we see somebody innovate on a model.
5:43 And then the very next day,
5:45 the same model is improved across somewhere across the world.
5:47 So the knowledge sharing is happening in real time.
5:50 We've got the internet.
5:50 We cannot put this cat back in the bag.
5:52 So unfortunately, we're going to have to live with it,
5:54 which means we all have to level up and we're going
5:57 to be buying those solutions from the very companies that created the problems.
6:01 But there's also lots of open source work being done here
6:03 and lots of free work by very smart people across the world.
6:06 So I think this is ultimately a net benefit for humanity,
6:09 but it's going to be a period of time where we
6:12 struggle to understand what exactly to do with all of this.