Mythos AI Flags Infrastructure Weaknesses in DeFi After $1 Billion DOT-Linked Incident

Mythos AI Flags Infrastructure Weaknesses in DeFi After $1 Billion DOT-Linked Incident

N
News Editor 01
2026-07-23 06:10:15
Mythos AI shifts attention from smart contract bugs to infrastructure risks in DeFi, highlighting key management, signing services, bridges, and oracles after a reported $1 billion unauthorized Polkadot token minting incident.
DeFiAI securityPolkadotcross-chain bridgeinfrastructure risk

Mythos AI is pushing DeFi security discussions beyond smart contract bugs and toward infrastructure. Paul Vijender, head of security at Gauntlet, said the biggest danger in AI-driven attacks now sits in back-end systems such as key management, signing services, cross-chain bridges, and oracle networks rather than in code alone.

A recent breach tied to widely used Vercel infrastructure illustrates that point. The incident threatened API keys used by numerous crypto firms, and investigators traced it to a vulnerability introduced by a third-party AI tool, Context.ai. For DeFi teams, the attack surface now stretches across the full technical stack, not just on-chain contracts.

Security models are shifting from bug scans to system interaction analysis

Traditional security tooling usually looks for known flaws in isolation. Mythos takes a different route, simulating complex attack paths by analyzing how systems interact with one another. That approach is meant to show how a small weakness can travel through interconnected protocols and cause outsized damage. The issue is no longer a single bug by itself; it is how that bug behaves inside a tightly linked environment.

The model is drawing interest from both crypto-native firms and traditional finance. The report says JP Morgan has started treating AI-generated cyber risks as a unified threat category and is stress-testing systems with models like Mythos. Coinbase and Binance have also reportedly entered discussions with Anthropic to pilot Mythos in their own security setups.

Composable DeFi structures can turn minor flaws into large losses

DeFi protocols are built to connect. They share liquidity, rely on oracle-fed data, and layer services on top of one another. That structure boosts flexibility, but it also creates conditions where damage can cascade quickly. The article points to a Hyperbridge exploit in which a flaw in message verification enabled the unauthorized minting of $1 billion worth of Polkadot tokens on Ethereum.

That case is presented as a clear example of infrastructure risk. The weak point was not framed as a standard contract bug; it sat in the verification and bridge layer. Once compromised, the failure extended beyond one application and exposed the broader network effect that defines DeFi composability.

AI is accelerating both offense and defense

Stani Kulechov, founder of Aave Labs, said Web3 has dealt with cyberattacks for years, but AI is increasing the speed of existing threats and changing how attacks develop. Aave has already started using AI tools in code review and audit workflows. Kulechov said those tools can surface issues that human auditors may have previously dismissed as irrelevant.

Uniswap Labs founder Hayden Adams said AI-based security creates a sharper divide between secure and insecure protocols. Earlier defense models leaned on pre-launch checks followed by human monitoring after deployment. That is changing. Always-on, adaptive security systems powered by AI are becoming harder to avoid as attackers move faster and target more than code.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.