The Genie Picked the Lock
TL;DR
This thought leadership piece by Kenneth Kinsella explores what Claude Mythos signals for the future of financial systems.
AI is now capable of identifying and exploiting deep infrastructure vulnerabilities, across both traditional banking and DeFi at a speed and scale that outpaces current security models. Legacy systems carry structural risk. Open systems carry full visibility. Both are now operating in an environment shaped by machine-level intelligence.
The implication is simple: security must evolve to become continuous, autonomous, and AI-driven.
Follow Kenneth Kinsella on LinkedIn for more insights and updates.
How concerned should we be about Claude Mythos? After escaping its sandbox using its own jailbreak code, it penned a cheeky email to its researcher whilst he was having a sandwich that basically said, “Remember me?”
Anthropic had given Mythos a straightforward prompt: Escape this sealed test environment. It spent four hours of sniffing around several decades’ worth of networking code, found a software flaw old enough to rent a car, and turned it into a ‘kernel-level exploit’, the kind of deep operating‑system hack elite security teams spend months on. Ranging across the open internet, it asked, “Can you hear me now?”
For clarity, the ‘kernel’ here is the part of an operating system that’s in charge of memory, hardware, security, and everything else. Whoever controls the kernel sets the terms. Mythos deduced this from public documentation and raw code, and wrote the attack itself. This was the AI equivalent of a teenager saying, ‘I’ll be home by ten,’ then hot‑wiring the car, dodging every cop and speed camera on his joyride, and texting his mum a smiling selfie at 2am from a house party three cities over.
Anthropic’s response is telling. The public release is now on ice on account of its revealed recklessness. They seem, in a word, spooked.
Finance should take note, and probably stop treating AI as just another productivity tool. This is a new kind of actor in the financial system that can learn the rules in the morning, break them creatively by lunchtime, and then gloat about it in an email before you’ve finished your sandwich.
Traditional finance runs on legacy mainframes and outdated operating systems that haven’t been meaningfully stress-tested in years. Mythos can now find vulnerabilities older than the average junior developer, chain them together to escalate privileges, and move laterally across networks with deadly precision.
The old code stack of traditional banking is now exposed in a Mad Max-ian landscape of roving AI gangs. If it can’t defend as fast as AI can attack, the interface surface becomes unmanageable. Cloud and API dependencies make this worse, since banks lean heavily on these libraries that Mythos can exploit across all layers. A single unpatched zero-day — where the technology has a fault or backdoor that no one noticed — in a widely used component could compromise multiple banks simultaneously and trigger systemic risk comparable to a liquidity shock.
What exactly Mythos found on its joyride has not been publicly released. Anthropic and others have said that Mythos found “thousands” of previously unknown, high‑severity zero-day vulnerabilities across every major operating system and web browser it scouted, including some 27-year-old bugs. These platforms underpin traditional banking infrastructure, trading systems, cloud services, and endpoints. There’s no way its discoveries weren’t finance-adjacent.
Blockchain may not have creaking mainframes in basements, but it has a ticking time bomb of its own. Once a DeFi protocol ships its core smart contracts to the blockchain, those contracts are public and essentially written in stone. Unless you’ve built in explicit upgrade hooks, any bug in that code is permanent. The stickiest problems aren’t typos but ‘logic traps’ like re‑entrancy loops, price oracles that can be nudged off‑side, or tiny rounding quirks that leak value over millions of transactions. A model with Mythos–level capability can read every line of that code across every chain and start stringing those traps together into cross‑protocol attack paths, flash‑loan plays, and governance ambushes at machine speed.
Blockchain’s greatest strength — open source, transparent, composable, programmable money — is also its Achilles’ heel. Its entire attack surface is published on GitHub and Etherscan, neatly indexed for any AI that wants to trawl it and build a catalogue of attacks. Glowing audit badges still matter, but their protective power relies heavily on human validation and friction, slow decision cycles, social signalling, and the hope that attackers get bored and quit. An AI model that never sleeps, never gets tired of reading Solidity code, and doesn’t care about your governance calendar erodes that advantage.
We cannot retreat back into the corporate network and banking cave. We must fight silicon with silicon. Traditional banking wants to harden crumbling infrastructure by moving off legacy stacks, wrapping everything in zero‑trust architectures, and treating every vendor and API as a potential single point of systemic failure. Surely another patch will fix this!
Blockchain needs a different and on‑chain native response. AI‑assisted audits should be a prerequisite. We need to be running continuous, autonomous security agents that simulate attacks on live protocols before real adversaries do. Contracts must be designed with circuit breakers, kill‑switches, and upgrade paths that can be triggered when an agent flags something ugly. Emergency changes can be made in hours when governance is continuously stress-tested. Assume AI-speed attackers are everywhere, build AI-speed protection into the rails, and you just might survive.
AI is here, armed, and dangerous. It can already find and weaponise zero-days faster than humans can patch and is already being deployed in offensive and defensive security. It is reshaping fraud, identity, and compliance in real time.
Claude Mythos didn’t wake up and decide to break the financial system. It simply did what a hyper-capable optimiser does: It found paths, chained them, and succeeded. In both traditional banking and DeFi, the question is no longer if AI will reshape cybersecurity and financial risk, but whether we can stop the teenager from hotwiring the car and flooring it before we have even finished our sandwich.
