NewsCryptoAI Has Not Unleashed a DeFi Hack Epidemic Yet — But It Is Making Every Weakness More Dangerous

AI Has Not Unleashed a DeFi Hack Epidemic Yet — But It Is Making Every Weakness More Dangerous

Author: Cointelegraph·

Key Takeaways

  • Web3 protocols lost over $1.3 billion across 344 security incidents in the first half of 2026, though experts consider fears of an AI-driven hacking epidemic to be overstated.
  • AI primarily functions as a force multiplier that makes existing crypto crimes cheaper and more scalable rather than creating entirely new categories of attacks.
  • Wallet compromises remained the most damaging attack vector in the first half of 2026, accounting for over $444 million in losses across 33 incidents.
  • AI-enabled crypto scams are 4.5 times more profitable than traditional scams, extracting an average of $3.2 million per operation.
  • Compromised keys, poor operational security, and weak infrastructure continue to be the primary determining factors in the success of cyberattacks.
AI Has Not Unleashed a DeFi Hack Epidemic Yet — But It Is Making Every Weakness More Dangerous

A series of high-profile cryptocurrency hacks in April — many suspected of being orchestrated with sophisticated AI tools to identify smart contract exploits — triggered fears that the entire DeFi ecosystem was suddenly vulnerable. In May, Manuel Aráoz, founder of blockchain security platform OpenZeppelin, declared "all of DeFi unsafe" after $630 million in crypto losses from exploits that month alone.

Yet even as the industry braced for DeFi protocols falling like dominoes to agentic AI, the wave of attacks appeared to subside. That prompted Dragonfly managing partner Haseeb Qureshi to recently call fears of a DeFi "hackpocalypse" a "false alarm." He noted that even including April's major incidents, the year to date has seen "a lower rate of hacked $ per month" and that the "median hack size by year is also declining."

The question remains: are fears of an AI-driven hacking epidemic entirely overblown, or is this merely the calm before the storm?

"I think the 'hackpocalypse' narrative is overstated if it suggests AI has already replaced compromised keys, weak infrastructure and human error as the main causes of Web3 losses," Stephen Ajayi, Hacken's leading offensive security engineer, told Magazine. However, he cautioned that the concerns should not be dismissed entirely.

"I would not confuse 'not dominant yet' with 'not coming.' My view is that we are still in the early stages: the hype is ahead of the incident data, but the capability curve is catching up quickly," Ajayi clarified.

AI Is Changing Attacks, Even If It Isn't Causing Them

Web3 protocols lost more than $1.3 billion across 344 security incidents in the first half of 2026, according to CertiK's H1 report.

Determining precisely how many of those incidents involved AI-identified or AI-assisted exploits remains difficult. Natalie Newson, senior blockchain investigator at CertiK, explains that "proving whether AI was used to find an exploit can be difficult."

Rather than seeking direct attribution, Newson says she monitors circumstantial evidence such as shifts in attacker behavior. She has observed a significant increase in the exploitation of older smart contracts and unverified contracts.

CertiK's report found that 73 code vulnerability incidents in the first half of 2026 involved contracts that had been deployed for at least a year before being exploited. "In 2025 as a whole this number was 45," Newson notes. This pattern suggests AI is enabling attackers to analyze far larger volumes of code than was previously practical.

That matters in DeFi because smart contracts are often publicly visible and, once deployed, can continue securing assets long after their original audits or developer attention have faded. Public code makes transparency possible for users and defenders, but it also gives attackers a large, permanent surface to scan.

Rather than inventing entirely new attack categories, AI appears to be making existing ones cheaper, faster, and easier to scale.

"AI systems can help analyze codebases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas for deeper review," Newson says. "An attacker, or a defender, can examine far more contracts in a given amount of time," she added, meaning that older codebases previously considered safe may now be exposed.

The Real Danger Is Scale

Blockchain data platform Chainalysis similarly identifies AI's most significant impact as a force multiplier that industrializes familiar forms of crypto crime.

Sully Hanif, head of UK public sector at Chainalysis, told Magazine: "Our 2026 crypto crime report found that AI-enabled crypto scams are 4.5x more profitable than traditional scams, extracting $3.2 million per operation versus $719,000."

"AI is enabling scammers to reach and manipulate far more victims simultaneously," Hanif said.

The threat extends beyond smart contract exploits. Chainalysis found that impersonation scams increased more than 1,400% year over year in 2025, with criminals leveraging AI-generated deepfakes and face-swapping software readily available on Telegram marketplaces.

"We've seen AI supercharge existing playbooks," Hanif said. "The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more effective."

Chainalysis recently identified $36.7 million stolen from protocols whose smart contract source code had never been publicly verified. Hanif warns that attackers are using large language models to reverse engineer raw bytecode and identify vulnerabilities at scale.

Source-code verification is one of the basic ways blockchain users and security teams compare human-readable contract code with what is deployed on-chain. When contracts remain unverified, defenders have less accessible information to review, while attackers can still analyze the underlying bytecode.

"AI is likely to have its greatest impact where human effort has traditionally been the bottleneck," Newson says. "We're observing AI being used to impersonate support staff, video calls, influencers [...] The biggest risk is that attackers no longer need technical expertise or strong language skills."

Where Are the Billion-Dollar Hacks Coming From?

Examining the data, the largest crypto losses of 2026 could have been carried out without any AI involvement.

CertiK's report found that wallet compromise remained the most damaging attack vector during the first half of the year, accounting for more than $444 million in losses across just 33 incidents.

Hacken's Q2 2026 Web3 security report found that roughly 88% of all value stolen during the second quarter was attributable to compromised keys, signers, and operational infrastructure rather than smart contract bugs — largely driven by two North Korean-linked attacks against Drift Protocol and KelpDAO.

Ajayi notes that rather than replacing traditional attack methods, AI is amplifying them by identifying vulnerable employees, generating convincing phishing campaigns, analyzing public code, and accelerating exploit development. Nevertheless, compromised governance, poor operational security, and weak infrastructure remain the determining factors in whether attacks succeed.

"AI is a new amplifier, but the old security failures still determine how large the blast becomes," he said.

AI Changes the Battlefield, But Not the Fundamentals

AI can also serve as a defensive tool, and the security industry is deploying it on that front as well. Hanif said investigators are shifting from reactive to preventative approaches, and "the tools exist now to stop scams before victims lose money."

For protocols, the practical takeaway from the current data is less about treating AI as a wholly new category of risk and more about reducing the weaknesses it can magnify: exposed operational keys, unverified or neglected contracts, inadequate monitoring, and social-engineering channels around teams and users.

"Ultimately, AI is likely to enhance the capabilities of both attackers and defenders," Newson said, "with the balance of advantage depending on which side is able to integrate and operationalize the technology most effectively."