Fears of AI-Driven DeFi Hack Epidemic Overstated For Now — But Not For Long

by

A wave of high profile crypto hacks in April that many suspected had been orchestrated using sophisticated AI tools to identify smart contract exploits, led to fears that every DeFi protocol was suddenly at risk.

In May, Manuel Aráoz, founder of the blockchain security platform OpenZeppelin, declared “all of DeFi unsafe” following $630 million in crypto losses from exploits in April.

But even as the industry braced for the scenario of DeFi protocols falling like dominoes to agentic AI, the stream of attacks seemed to ebb.

That led Dragonfly managing partner Haseeb Qureshi to declare recently that fears of a DeFi “hackpocalypse” were a “false alarm.” He pointed out that even including April’s big hacks, the year to date has seen “a lower rate of hacked $ per month” and that the “median hack size by year is also declining.”

So who’s right? Are the fears of an AI driven hacking epidemic totally overblown, or is this just the lull before the storm?

“I think the ‘hackpocalypse’ narrative is overstated if it suggests AI has already replaced compromised keys, weak infrastructure and human error as the main causes of Web3 losses,” Stephen Ajayi, Hacken’s leading offensive security engineer, tells Magazine.

But he adds that doesn’t mean the fears are entirely misplaced.

“I would not confuse ‘not dominant yet’ with ‘not coming.’ My view is that we are still in the early stages: the hype is ahead of the incident data, but the capability curve is catching up quickly,” Ajayi clarifies.

AI is changing attacks, even if it isn’t causing them

Web3 protocols lost more than $1.3 billion across 344 security incidents in the first half of 2026, according to CertiK’s H1 report.

It’s impossible to say how many of those incidents involved AI-identified or assisted exploits. Natalie Newson, senior blockchain investigator at CertiK, explains that “proving whether AI was used to find an exploit can be difficult.”

Related: AI-driven hacks could kill DeFi — unless projects act now

Rather than looking for direct attribution, Newson says she watches for circumstantial evidence like changes in attacker behavior. She notes there’s been a large increase in older smart contracts and unverified contracts being exploited.

CertiK’s report found that 73 code vulnerability incidents in the first half of 2026 had been deployed for at least a year before being exploited. “In 2025 as a whole this number was 45,” Newson says. This suggests AI is helping attackers analyze far larger volumes of code than was previously practical.

Instead of inventing entirely new attack classes, AI appears to be making existing ones cheaper, faster and easier to scale.

Monthly change in crypto exploit amounts and number of incidents across H1. Source: CertiK

“AI systems can help analyze codebases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas for deeper review,” Newson says.

“An attacker, or a defender, can examine far more contracts in a given amount of time,” she said, meaning that older codebases may now be at risk.

The real danger is scale

Blockchain data platform Chainalysis also sees AI’s biggest impact as being a multiplier for activity, thereby industrializing familiar forms of crypto crime.

Sully Hanif, head of UK public sector at Chainalysis, tells Magazine, “Our 2026 crypto crime report found that AI-enabled crypto scams are 4.5x more profitable than traditional scams, extracting $3.2 million per operation versus $719,000.”

“AI is enabling scammers to reach and manipulate far more victims simultaneously.”

The danger does not just come from smart contract exploits. Chainalysis found that impersonation scams increased more than 1,400% year over year in 2025, with criminals using AI-generated deepfakes and face-swapping software readily available on Telegram marketplaces.

“We’ve seen AI supercharge existing playbooks,” he says. “The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more effective.”

Related: AI models led to a ‘vulnerability apocalypse’ in crypto security: Immunefi CEO

Chainalysis recently identified $36.7 million stolen from protocols whose smart contract source code had never been publicly verified. Hanif warns that attackers are using large language models to reverse engineer raw bytecode and identify vulnerabilities at scale.

The data: $36.7 million from unverified contracts. Source: Chainalysis

“AI is likely to have its greatest impact where human effort has traditionally been the bottleneck,” Newson says. “We’re observing AI being used to impersonate support staff, video calls, influencers […] The biggest risk is that attackers no longer need technical expertise or strong language skills.”

So where are the billion-dollar hacks coming from?

Looking at the data, the biggest crypto losses of 2026 could have been carried out without the use of AI.

CertiK’s report found wallet compromise remained the most damaging attack vector during the first half of the year, accounting for more than $444 million in losses across just 33 incidents.

Hacken’s Q2 2026 Web3 security report found that roughly 88% of all value stolen during the second quarter was due to compromised keys, signers and operational infrastructure rather than smart contract bugs, largely driven by the two North Korean-linked attacks against Drift Protocol and KelpDAO.

Of the $763,971,791 stolen, 88.3% was traced to compromised keys, signers, and infrastructure. Source: Hacken

Ajayi s that rather than replacing traditional attack methods, AI is amplifying them by identifying vulnerable employees, generating convincing phishing campaigns, analyzing public code and accelerating exploit development. However, compromised governance, poor operational security and weak infrastructure still determine whether attacks succeed.

“AI is a new amplifier, but the old security failures still determine how large the blast becomes,” he said.

AI changes the battlefield, but not the fundamentals

Of course, AI can also be used as a force for good, and the security industry is deploying it defensively as well. Hanif said investigators are moving from reactive to preventative, and “the tools exist now to stop scams before victims lose money.”

“Ultimately, AI is likely to enhance the capabilities of both attackers and defenders,” Newson said, “with the balance of advantage depending on which side is able to integrate and operationalize the technology most effectively.”

Magazine: Strategy became a symbol of the dot-com crash: Could history repeat?

Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.

Source link

Related Posts

Leave a Comment

Please enter and activate your license key for Cryptocurrency Widgets PRO plugin for unrestricted and full access of all premium features.