XDAO SECURITY IN THE AGE OF AI: MYTHOS FOUND A BUG, WE SHIPPED THE FIX 🛡
You've probably heard of Mythos, Anthropic's new AI model. It finds vulnerabilities in systems that were considered impenetrable for decades and that human experts had missed. Mythos is not yet available to the public: Anthropic has restricted access to Claude Mythos Preview under Project Glasswing, granting it to a limited number of major technology, financial, and infrastructure organizations (including Microsoft, Google, Apple, Amazon, and CrowdStrike) for cybersecurity purposes.
For example, Mythos found logic errors in cryptographic library implementations that banking systems and secure communication protocols have relied on since the 1990s. Those libraries had held up as a reliability benchmark for 30 years, and Mythos worked through them in hours.
One of those findings concerned XDAO. Mythos discovered a vulnerability in one of our auxiliary modules on EVM blockchains that could theoretically allow minting of DAO LP tokens. The report reached us through Anthropic's coordinated vulnerability disclosure program, where Trail of Bits handles triage and passes findings on to the projects concerned. Our team reviewed the report and shipped the patch.
What the community should know
The finding was confined to a single auxiliary module, and the fix is already live. That is the whole value of a working disclosure channel: the report went from Mythos through Trail of Bits to our engineers, and the fix followed.
We thank the Anthropic and Trail of Bits teams for the report and for getting it to us quickly 🤝❤️ In the world of decentralized finance, AI technologies are becoming our greatest ally.