Current concerns about AI-powered DeFi attack wave may be premature — yet threat looms ahead

Current concerns about AI-powered DeFi attack wave may be premature — yet threat looms ahead

While AI-assisted exploits haven't rendered DeFi universally vulnerable yet, mounting evidence of legacy smart contract breaches indicates growing risks.

During April, a series of prominent cryptocurrency security breaches suspected to involve advanced artificial intelligence capabilities for discovering smart contract vulnerabilities sparked concerns that decentralized finance protocols across the board faced unprecedented danger.

Following April's exploits that resulted in $630 million worth of cryptocurrency losses, Manuel Aráoz, who founded the blockchain security firm OpenZeppelin, made a stark declaration in May stating that "all of DeFi unsafe."

Yet as industry participants prepared themselves for a scenario where agentic AI would topple DeFi protocols in rapid succession, the frequency of these attacks appeared to decrease.

This shift prompted Haseeb Qureshi, managing partner at Dragonfly, to recently announce that concerns regarding a DeFi "hackpocalypse" represented a "false alarm." His analysis highlighted that when incorporating April's significant breaches, the year to date has witnessed "a lower rate of hacked $ per month" while the "median hack size by year is also declining."

This raises the question: Which perspective holds validity? Is the alarm about an artificial intelligence-fueled hacking wave completely exaggerated, or are we experiencing a temporary quiet period preceding a major storm?

"I think the 'hackpocalypse' narrative is overstated if it suggests AI has already replaced compromised keys, weak infrastructure and human error as the main causes of Web3 losses," Stephen Ajayi, Hacken's leading offensive security engineer, tells Magazine.

However, he emphasizes that this assessment doesn't render the concerns completely unfounded.

"I would not confuse 'not dominant yet' with 'not coming.' My view is that we are still in the early stages: the hype is ahead of the incident data, but the capability curve is catching up quickly," Ajayi clarifies.

AI is changing attacks, even if it isn't causing them

During the initial six months of 2026, Web3 protocols experienced losses exceeding $1.3 billion throughout 344 distinct security incidents, based on CertiK's H1 report findings.

Determining the precise number of these incidents that incorporated AI-discovered or AI-facilitated exploits remains challenging. According to Natalie Newson, senior blockchain investigator at CertiK, "proving whether AI was used to find an exploit can be difficult."

Instead of seeking direct confirmation, Newson indicates that she monitors circumstantial indicators such as shifts in how attackers operate. She observes a substantial uptick in exploits targeting legacy smart contracts and contracts lacking verification.

According to CertiK's report, 73 code vulnerability incidents during the first half of 2026 involved contracts that had been deployed for a minimum of one year prior to exploitation. "In 2025 as a whole this number was 45," Newson says. This data points toward AI enabling attackers to examine significantly larger code volumes than what was feasible previously.

Rather than creating completely novel attack categories, artificial intelligence seems to be reducing costs, accelerating timelines and enhancing scalability for established attack methods.

Monthly change in crypto exploit amounts
The monthly variation in cryptocurrency exploit values and incident counts throughout H1. Source: CertiK

"AI systems can help analyze codebases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas for deeper review," Newson says.

"An attacker, or a defender, can examine far more contracts in a given amount of time," she said, meaning that older codebases may now be at risk.

The real danger is scale

Chainalysis, a blockchain data analytics platform, similarly identifies AI's primary influence as an activity multiplier that industrializes conventional cryptocurrency crime methodologies.

According to Sully Hanif, head of UK public sector at Chainalysis, who spoke with Magazine, "Our 2026 crypto crime report found that AI-enabled crypto scams are 4.5x more profitable than traditional scams, extracting $3.2 million per operation versus $719,000."

"AI is enabling scammers to reach and manipulate far more victims simultaneously."

Smart contract exploits aren't the sole source of risk. Chainalysis discovered that impersonation-based scams surged by more than 1,400% on a year-over-year basis throughout 2025, with malicious actors leveraging AI-created deepfakes alongside face-swapping tools that are easily accessible through Telegram marketplaces.

"We've seen AI supercharge existing playbooks," he says. "The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more effective."

In a recent analysis, Chainalysis identified $36.7 million in thefts from protocols where the smart contract source code had never undergone public verification. Hanif cautions that adversaries are employing large language models to conduct reverse engineering on raw bytecode and uncover vulnerabilities on a large scale.

Unverified contracts data
Findings show: $36.7 million taken from unverified contract sources. Source: Chainalysis

"AI is likely to have its greatest impact where human effort has traditionally been the bottleneck," Newson says. "We're observing AI being used to impersonate support staff, video calls, influencers [...] The biggest risk is that attackers no longer need technical expertise or strong language skills."

So where are the billion-dollar hacks coming from?

When examining the available data, the largest cryptocurrency thefts throughout 2026 could potentially have been executed without incorporating AI technology.

CertiK's report identified wallet compromise as the most financially destructive attack method during the year's first half, responsible for over $444 million in losses spanning merely 33 separate incidents.

According to Hacken's Q2 2026 Web3 security report, approximately 88% of total value stolen throughout the second quarter resulted from compromised keys, signers and operational infrastructure vulnerabilities rather than smart contract coding flaws, with the two North Korean-attributed attacks targeting Drift Protocol and KelpDAO driving these statistics.

Stolen funds breakdown
From the total $763,971,791 in stolen assets, 88.3% was attributed to compromised keys, signers, and infrastructure vulnerabilities. Source: Hacken

According to Ajayi, artificial intelligence amplifies traditional attack methodologies through vulnerable employee identification, convincing phishing campaign generation, public code analysis and accelerated exploit development, rather than supplanting these methods entirely. Nevertheless, compromised governance structures, inadequate operational security practices and fragile infrastructure continue to be the determining factors in attack success.

"AI is a new amplifier, but the old security failures still determine how large the blast becomes," he said.

AI changes the battlefield, but not the fundamentals

Naturally, artificial intelligence can serve beneficial purposes as well, with the security sector implementing it for defensive applications. Hanif indicated that investigators are transitioning from reactive approaches to preventative strategies, noting that "the tools exist now to stop scams before victims lose money."

"Ultimately, AI is likely to enhance the capabilities of both attackers and defenders," Newson said, "with the balance of advantage depending on which side is able to integrate and operationalize the technology most effectively."