Mysten Labs CTO Joins Anthropic as AI Threats Test Blockchain Defenses
Sam Blackshear is leaving his job as Mysten Labs CTO to work on AI security at Anthropic, and blockchain infrastructure is part of the problem he wants to tackle. The Mysten Labs co-founder is stepping down as CTO because, in his view, the hardest security problems are shifting toward AI. The tradeoff is blunt: AI helps developers find software flaws faster, but it also helps attackers probe crypto protocols and scale phishing campaigns. This is already happening. And with blockchain networks holding billions of dollars in assets, one small coding mistake can become an expensive, very public mess. Fast.

At Anthropic, Blackshear will return to hands-on research, working on ways to protect software from more capable AI attacks. He started Mysten Labs, the company behind the Sui blockchain, in September 2021 with four other former Meta executives. Co-founder and CEO Evan Cheng will now lead Mysten’s technical work. Blackshear described the choice in personal terms: “When I reflect on my career, I have been happiest doing hands-on technical work while exploring new problem domains. This is an opportunity to do both, and I’m motivated to work on security at a time when the balance of power between attackers and defenders is shifting.” I’ll be honest: the line about the balance of power matters more than the executive reshuffle. AI systems can already find vulnerabilities and automate phishing. As they improve, attacks will probably become cheaper to launch. Why does that matter? Because cheaper attacks mean more attempts, including against protocols that previously looked too obscure to target.
For crypto markets, this is more than an executive changing jobs. It is a sign that AI-assisted attacks need attention now. Most commentary treats a CTO departure as a leadership story. That’s only half right. Blackshear has spent years designing blockchain systems, and his decision to focus on defensive AI research is difficult to dismiss as routine career movement. Crypto prices can collapse after a security failure; when a major protocol is exploited, its token may lose 20% to 30% within hours as traders rush to sell. Things get ugly quickly. My take: stronger defenses will not prevent every selloff, but they can reduce the chance that one overlooked flaw empties a protocol. They can also keep a technical failure from becoming a lasting crisis of confidence.
Investors may begin separating protocols that do serious security work from those leaning on comforting claims and outdated audits. Inflation and higher interest rates have already made investors less forgiving about risk. If AI makes blockchain attacks quicker or cheaper, money could leave weak protocols for safer crypto assets—or leave crypto entirely. Counter to the usual advice, simply adding another audit may not be enough. A DeFi protocol has a stronger pitch to institutional investors if it can demonstrate how it finds AI-assisted attacks and tests its code, then show exactly how it handles incidents. Evidence counts. The label “AI-hardened” is empty unless a team publishes test results, describes its controls or proves those controls during an attack. Is that standard too demanding? Not when billions of dollars in assets can sit behind a small coding mistake. In a downturn, well-protected protocols might behave more like mature technology companies; speculative projects will probably suffer more.
Blackshear is giving up his operating role, but he is keeping his connections to Mysten, Sui and the Move Foundation. He expects to remain a close adviser to Mysten and the Sui ecosystem while continuing his work with the Move Foundation. At first glance, that can sound like the usual soft landing after an executive departure. I don’t think it is that simple. The relationship may let the groups share useful security research, and it is practical for a less glamorous reason: AI-powered attackers do not care about company lines. What developers learn from one exploited protocol may help them protect another. Boundaries won’t save them.
What this means
Blockchain security teams are dealing with attackers who can use AI to inspect code, produce believable scams and try the same attack again and again at much greater speed. Blackshear’s move suggests today’s security practices may not keep up as these tools improve. Investors should ask one direct question: which protocols are actually changing their defenses? Sui and other projects built with the Move language will have to show their work, not fall back on vague claims about innovation. That could mean different testing methods or shorter incident response times. It could also mean publishing research into AI-assisted threats. Yes, that is a tougher standard than many projects face today. It should be. Without evidence, confidence in tokens such as SUI could crack after the next exploit—or even after a credible warning about one.
Investors should pay attention to what major protocols build, whom they work with and whether their defenses survive contact with the real world. An AI security announcement may lift sentiment briefly, but a partnership does not prove the technology works. We should be skeptical here. A confirmed AI-assisted breach would probably hit smaller projects first, particularly those with thin liquidity or small security teams. By contrast, a system that catches a genuine vulnerability before an attacker reaches it would be convincing. Blackshear’s continued involvement gives investors another concrete place to look: the Move Foundation’s security plans. Research from Anthropic could eventually reach blockchain developers through that connection, although there is no guarantee it will. So what will settle the argument? The next few security incidents—not another round of polished announcements.
