📰 Key Takeaways

Anthropic’s Claude Mythos (dev codename Fable 5) has sparked intense wariness in the crypto community. In April, hackers stole $629.7 million in cryptocurrency—the highest monthly total since February 2025—and analysts directly link this to the widespread adoption of AI tools.

Moonrock Capital founder Simon Dedic has issued a public warning: after Fable 5’s release, the cost and technical barrier to finding exploitable vulnerabilities in smart contracts will approach zero. He points out that unaudited DeFi protocols will become sitting ducks, known attack vectors will be repeatedly replicated across various fork projects, and even tiny projects won’t escape being targeted due to extremely low attack costs. He advises users to proactively revoke wallet authorizations, withdraw assets from protocols, and transfer holdings to new hardware wallets.

Curve Finance co-founder Michael Egorov takes a more conservative view. He notes that most vulnerabilities Mythos finds in other software come from large systems with millions of lines of code, whereas DeFi smart contracts typically contain only a few thousand lines—both humans and existing AI can fully grasp their logic. Therefore, the breakthrough isn’t as significant as the hype suggests. He predicts greater risks actually lie in operational security, such as multi-signature key theft and front-end dependency supply chain attacks, rather than on-chain contracts being directly exploited.

In terms of capability verification, Anthropic in May, through Project Glasswing, had Mythos scan over 1,000 open-source projects and uncover approximately 6,200 high-severity or critical vulnerabilities. Currently, Anthropic has opened limited access to a small batch of security and infrastructure firms to use Claude Mythos 5 with some safeguards removed.


💬 JudyAI Lab Perspective

The leap in AI vulnerability scanning capabilities is flipping the entire cost calculus of DeFi security defense—that’s the core of this news worth paying attention to.

Anthropic’s Project Glasswing had Claude Mythos scan over 1,000 open-source projects and uncover roughly 6,200 high-severity vulnerabilities, showing that AI as a dual-use tool for both attack and defense is rapidly scaling up. Moonrock Capital founder Simon Dedic’s warning highlights a reality: when the technical barrier to finding contract vulnerabilities approaches zero, even tiny unaudited protocols won’t escape being targeted. However, Curve Finance co-founder Michael Egorov offers another perspective—the code volume in smart contracts is limited, and the breakthrough AI brings may not be as significant as the hype suggests; the bigger actual risk comes from operational-level concerns like multi-signature key theft and front-end dependency supply chain attacks. This reminds us that when facing AI-driven security threats, we shouldn’t just focus on on-chain contracts—the depth of defense across the entire operational environment is equally important.

Take Action Now: Go into every DeFi protocol where you hold assets, revoke all unused wallet authorizations, and evaluate whether you need to move your main positions to hardware wallets—that’s the lowest-cost self-protection option available right now.


📅 Source Info