Anthropic's Claude Mythos Preview, announced April 7, 2026, and restricted to 40 companies under Project Glasswing, has found zero-day vulnerabilities in TLS, AES-GCM, and SSH — the cryptographic protocols underpinning $85 billion in DeFi total value locked and every major centralized exchange. O...
"If AI can identify vulnerabilities at scale across core internet infrastructure, crypto will be one of the first markets to feel the impact." — Deddy David, CEO, Cyvers
Anthropic's Claude Mythos Preview, announced April 7, 2026, and restricted to 40 companies under Project Glasswing, has found zero-day vulnerabilities in TLS, AES-GCM, and SSH — the cryptographic protocols underpinning $85 billion in DeFi total value locked and every major centralized exchange. On April 21, Bloomberg reported that unauthorized users accessed the model through compromised contractor credentials. The breach occurred via a private Discord group that inferred the model's URL from leaked Anthropic infrastructure data obtained through a separate breach at AI training-data vendor Mercor.
The timing compounds an already severe period for crypto security. Through April 20, 2026, the industry has recorded $775 million in exploit losses — $606 million in April alone across 12 incidents. The KelpDAO cross-chain bridge exploit ($292 million) and the Drift Protocol breach ($285 million) account for 74% of April's total. DeFi TVL fell $13 billion in two days following the KelpDAO hack, dropping to $85.6 billion, the lowest level since April 2025.
Mythos introduces a structural question for DeFi that goes beyond any single exploit: can an ecosystem built entirely on open-source, publicly readable code survive an era where AI models audit millions of lines of code in minutes, at a compute cost under $50 per vulnerability discovery?
Claude Mythos Preview is an AI model that Anthropic classified as too dangerous for public release. According to the company's own red team, it autonomously discovered thousands of zero-day vulnerabilities across every major operating system and every major web browser. Specific disclosed findings include:
The model was deployed under Project Glasswing, a consortium initially comprising 40 companies including Microsoft, Apple, Google, Amazon Web Services, NVIDIA, Cisco, CrowdStrike, and JPMorgan Chase. Anthropic committed up to $100 million in usage credits for defensive vulnerability remediation. Two of three disclosed cryptographic vulnerabilities remained unpatched as of April 23. Only one — a certificate authentication bypass in the Botan library — was publicly disclosed.
The UK Government's AI Safety Institute (AISI) evaluated the model independently and concluded that Mythos "could be directed to autonomously compromise small, weakly defended, and vulnerable systems if given network access."
On April 21, Bloomberg reported that a small group of unauthorized users gained access to Mythos Preview through a third-party vendor environment. According to reporting by Fortune and TechCrunch, the access vector involved two components:
An Anthropic spokesperson stated the company was "investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments." No evidence indicated the breach extended beyond the third-party environment.
David Lindner, CISO of Contrast Security, told Fortune: "It was bound to happen. The more they add to this elite group, the more likely it was to get released to someone who shouldn't probably have access to it." He added: "If some group — some random Discord online forum — got access to it, it's already been breached by China."
The group reportedly maintained continuous access since the model's release and had not used it for cyberattacks, according to Fortune's reporting as of April 23.
The intersection of Mythos' capabilities and DeFi's architecture creates a risk profile distinct from traditional cybersecurity concerns. Three structural factors amplify DeFi's exposure:
1. Open-Source Code Transparency
Approximately $85 billion in DeFi TVL sits in smart contracts whose source code is publicly verifiable on-chain. Unlike traditional financial institutions, which operate on proprietary, siloed networks with centralized circuit breakers, DeFi protocols expose their entire codebase to any entity — or any AI model — capable of reading it. Mythos can catalog weaknesses across an entire protocol's codebase at machine speed and near-zero marginal cost.
2. Friction-Based Security
Anthropic's technical documentation states that "mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries." In DeFi, the primary security mechanisms fall into this category:
3. Composability as Attack Surface
DeFi's composability — the ability of protocols to interact permissionlessly — means that a vulnerability in one protocol can cascade through integrated systems. The KelpDAO exploit demonstrated this: a misconfigured cross-chain verification in LayerZero-based infrastructure triggered $13 billion in TVL outflows across the broader ecosystem, including $6 billion from Aave V3 alone, according to CoinDesk.
According to blockchain security firm Cyvers, the financial exposure of AI-driven exploits in crypto "ranges from hundreds of millions to billions of dollars."
Through April 20, 2026, the crypto industry has recorded $775 million in total exploit losses. The breakdown:
| Period | Losses | Incidents | Notes | |--------|--------|-----------|-------| | Q1 2026 | $169M | 34 | Per DefiLlama | | April 1-20 | $606M | 12 | 3.7x entire Q1 | | YTD Total | $775M | 46 | Annualized: ~$2.5B |
Top April 2026 Exploits:
| Protocol | Amount | Date | Vector | |----------|--------|------|--------| | KelpDAO | $292M | Apr 19 | Cross-chain bridge misconfiguration | | Drift Protocol | $285M | Apr 1 | Social engineering (attributed to North Korean group) |
The attack vector mix has shifted. According to Halborn's Q1 2026 data, smart contract bug incidents declined approximately 89% from the prior year. The dominant vectors are now private key compromise, phishing, credential theft, and cross-chain bridge failures — categories where AI-assisted reconnaissance and exploit chaining could accelerate the attacker's timeline.
DeFi TVL fell from $99.5 billion to $85.6 billion over two days following the KelpDAO hack, per CoinDesk. Ethereum's TVL stood at $57.2 billion; Solana's at $6.05 billion as of April 17.
The blockchain security audit sector is recalibrating in response to AI-enabled threat models. Key developments:
CertiK announced a partnership with IBM on February 14, 2026 to integrate Watson AI into its audit framework, aiming to detect emergent logic flaws that static analysis tools miss.
OpenZeppelin reported that its new AI-augmented tools cut auditing time by 50%, though the company has not disclosed false-positive rates or coverage metrics for the new tooling.
Continuous Auditing Model: Security firms increasingly argue that point-in-time audits — the industry standard since DeFi's inception — are insufficient. The phrase "audited once is no longer a serious security model" has become an industry consensus position. Protocols are being urged to invest in continuous, AI-powered screening rather than pre-launch-only assessments.
The cost asymmetry is the core problem. According to CoinDesk, Mythos discovered the 27-year-old OpenBSD bug for under $50 in compute costs. Converting a known Linux vulnerability into a working exploit — a process that typically takes human researchers weeks — cost under $2,000 with Mythos. This cost compression is available to defenders and attackers alike. The question is adoption speed.
The Mythos disclosure triggered direct government engagement:
April 17: Anthropic CEO Dario Amodei met with White House Chief of Staff Susie Wiles and senior administration officials. The White House described talks as "productive and constructive." Amodei subsequently told the Financial Times he wants AI "regulated the way you regulate cars and aeroplanes — mandatory, third-party-assessed, and built around safety standards."
April 23: Former Acting National Cyber Director Kemba Walden wrote in Fortune that Mythos "should be a clarion call to address weaknesses in our cyber ecosystem" and described the model as discovering zero-day vulnerabilities while autonomously building, chaining, and covering the tracks of exploits.
Singapore: The Monetary Authority of Singapore flagged AI-driven cybersecurity risk in its 2026 guidance, urging banks and crypto-licensed entities to strengthen defenses against automated attack vectors.
For crypto specifically, the Mythos development intersects with an already active regulatory environment. The GENIUS Act stablecoin framework, the SEC-CFTC digital commodities classification, and the CLARITY Act market structure bill all proceed through congressional markup as the industry's technical security assumptions face a fundamental challenge.
No major regulatory body has yet proposed AI-specific cybersecurity requirements for DeFi protocols or crypto custodians. This gap is conspicuous given the $775 million in 2026 losses and the demonstrated capabilities of frontier AI models.
Mythos does not create new vulnerability categories. The bugs it finds were always there — in some cases, for 27 years. What it changes is the economics and speed of discovery. A $50 compute job replacing weeks of human security research compresses the timeline between vulnerability existence and exploitation to near-zero.
For DeFi, this is an architectural problem, not merely a security one. The ecosystem's foundational design principles — open-source code, permissionless composability, transparent on-chain state — are simultaneously its greatest strengths and its most significant liabilities in an AI-enabled threat environment. Friction-based defenses (multisig, timelocks, audit stamps) were designed for a world where exploit discovery was expensive and slow. That world ended on April 7, 2026.
The industry's response will likely bifurcate. Well-capitalized protocols with access to frontier AI tools — those inside the Glasswing consortium or similar arrangements — will integrate continuous AI-powered auditing into their operations. Smaller protocols, which collectively hold billions in TVL, face a cost-of-defense problem that current market structures do not solve.
The data is unambiguous on one point: the gap between offensive AI capability and defensive deployment in crypto is measured in months, not years. Whether that gap closes through industry investment, regulatory mandate, or further catastrophic losses remains an open question.