Fears of AI-Driven DeFi Hack Epidemic Overstated For Now — But Not For Long
‘All of Defi’ hasn’t suddenly become unsafe due to AI-driven hacks, but a surge in old smart contract exploits shows the danger is increasing.
YayaNews contributes financial news and market context through the YayaNews editorial workflow.

‘All of Defi’ hasn’t suddenly become unsafe due to AI-driven hacks, but a surge in old smart contract exploits shows the danger is increasing.
Fears of AI-Driven DeFi Hack Epidemic Overstated For Now — But Not For Long
DOGE
$0.07047
3.20%
TRX
$0.3266
0.87%
LINK
$8.50
1.84%
ZEC
$517.41
0.81%
ADA
$0.1711
2.47%
XRP
$1.11
2.58%
ETH
$1,901.02
1.78%
BTC
$65,030.29
1.15%
XMR
$349.98
0.55%
BNB
$566.94
1.05%
XLM
$0.1823
3.89%
SOL
$76.75
1.47%
HYPE
$59.62
1.59%
Written by
Christina Comben
staff writer
Reviewed by
Andrew Fenton
staff editor
Written by
Christina Comben
staff writer
Reviewed by
Andrew Fenton
staff editor
Fears of AI-driven DeFi hack epidemic overstated for now — but not for long
Magazine
Published
Jul 23, 2026
Are the fears of an AI driven hacking epidemic totally overblown, or is this just the lull before the storm?
A wave of high profile crypto hacks in April that many suspected had been orchestrated using sophisticated AI tools to identify smart contract exploits, led to fears that every DeFi protocol was suddenly at risk.
In May, Manuel Aráoz, founder of the blockchain security platform OpenZeppelin, declared “all of DeFi unsafe” following
$630 million in crypto losses from exploits
in April.
But even as the industry braced for the scenario of DeFi protocols falling like dominoes to agentic AI, the stream of attacks seemed to ebb.
That led Dragonfly managing partner
Haseeb Qureshi to declare recently that fears
of a DeFi “hackpocalypse” were a “false alarm.” He pointed out that even including April’s big hacks, the year to date has seen “a lower rate of hacked $ per month” and that the “median hack size by year is also declining.”
So who’s right? Are the fears of an AI driven hacking epidemic totally overblown, or is this just the lull before the storm?
“I think the ‘hackpocalypse’ narrative is overstated if it suggests AI has already replaced compromised keys, weak infrastructure and human error as the main causes of Web3 losses,” Stephen Ajayi, Hacken’s leading offensive security engineer, tells Magazine.
But he adds that doesn’t mean the fears are entirely misplaced.
“I would not confuse ‘not dominant yet’ with ‘not coming.’ My view is that we are still in the early stages: the hype is ahead of the incident data, but the capability curve is catching up quickly,” Ajayi clarifies.
AI is changing attacks, even if it isn’t causing them
Web3 protocols
lost more than $1.3 billion
across 344 security incidents in the first half of 2026, according to CertiK’s H1 report.
It’s impossible to say how many of those incidents involved AI-identified or assisted exploits. Natalie Newson, senior blockchain investigator at CertiK, explains that “proving whether AI was used to find an exploit can be difficult.”
Related:
AI-driven hacks could kill DeFi — unless projects act now
Rather than looking for direct attribution, Newson says she watches for circumstantial evidence like changes in attacker behavior. She notes there’s been a large increase in older smart contracts and unverified contracts being exploited.
CertiK’s report found that 73 code vulnerability incidents in the first half of 2026 had been deployed for at least a year before being exploited. “In 2025 as a whole this number was 45,” Newson says. This suggests AI is helping attackers analyze far larger volumes of code than was previously practical.
Instead of inventing entirely new attack classes, AI appears to be making existing ones cheaper, faster and easier to scale.
Monthly change in crypto exploit amounts and number of incidents across H1. Source: CertiK
“AI systems can help analyze codebases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas for deeper review,” Newson says.
“An attacker, or a defender, can examine far more contracts in a given amount of time,” she said, meaning that older codebases may now be at risk.
The real danger is scale
Blockchain data platform Chainalysis also sees AI’s biggest impact as being a multiplier for activity, thereby industrializing familiar forms of crypto crime.
Sully Hanif, head of UK public sector at Chainalysis, tells Magazine, “Our 2026 crypto crime report found that AI-enabled crypto scams are 4.5x more profitable than traditional scams, extracting $3.2 million per operation versus $719,000.”
“AI is enabling scammers to reach and manipulate far more victims simultaneously.”
The danger does not just come from smart contract exploits. Chainalysis found that impersonation scams increased more than 1,400% year over year in 2025, with criminals using AI-generated deepfakes and face-swapping software readily available on Telegram marketplaces.
“We’ve seen AI supercharge existing playbooks,” he says. “The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more effective.”
Related:
AI models led to a ‘vulnerability apocalypse’ in crypto security: Immunefi CEO
Chainalysis recently
identified
$36.7 million stolen from protocols whose smart contract source code had never been publicly verified. Hanif warns that attackers are using large language models to reverse engineer raw bytecode and identify vulnerabilities at scale.
The data: $36.7 million from unverified contracts. Source: Chainalysis
“AI is likely to have its greatest impact where human effort has traditionally been the bottleneck,” Newson says. “We’re observing AI being used to impersonate support staff, video calls, influencers [...] The biggest risk is that attackers no longer need technical expertise or strong language skills.”
So where are the billion-dollar hacks coming from?
Looking at the data, the biggest crypto losses of 2026 could have been carried out without the use of AI.
CertiK’s report found wallet compromise remained the most damaging attack vector during the first half of the year, accounting for more than $444 million in losses across just 33 incidents.
Hacken’s Q2 2026 Web3 security report
found
that roughly 88% of all value stolen during the second quarter was due to compromised keys, signers and operational infrastructure rather than smart contract bugs, largely driven by the two North Korean-linked attacks against
Drift Protocol
and
KelpDAO
.
Of the $763,971,791 stolen, 88.3% was traced to compromised keys, signers, and infrastructure. Source: Hacken
Ajayi s that rather than replacing traditional attack methods, AI is amplifying them by identifying vulnerable employees, generating convincing phishing campaigns, analyzing public code and accelerating exploit development. However, compromised governance, poor operational security and weak infrastructure still determine whether attacks succeed.
“AI is a new amplifier, but the old security failures still determine how large the blast becomes,” he said.
AI changes the battlefield, but not the fundamentals
Of course, AI can also be used as a force for good, and the security industry is deploying it defensively as well. Hanif said investigators are moving from reactive to preventative, and “the tools exist now to stop scams before victims lose money.”
“Ultimately, AI is likely to enhance the capabilities of both attackers and defenders,” Newson said, “with the balance of advantage depending on which side is able to integrate and operationalize the technology most effectively.”
Magazine:
Strategy became a symbol of the dot-com crash: Could history repeat?
Subscribe to daily byte-sized crypto news from Cointelegraph
Subscribe
Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.
AI
Hacks
Social Engineering
DeFi
Scams
Scams & Cybercrime
More on the subject
Home invasions became most common crypto wrench attack in H1 2026: CertiK
5 hours ago
Ezra Reguerra
Hackers steal $31.6M in 2 crypto bridge attacks within 7 hours
12 hours ago
Felix Ng
Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys
Jul 22, 2026
Zoltan Vardai
News Brief
Home invasions became most common crypto wrench attack in H1 2026: CertiK
5 hours ago
Ezra Reguerra
Hackers steal $31.6M in 2 crypto bridge attacks within 7 hours
12 hours ago
Felix Ng
Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys
Jul 22, 2026
Zoltan Vardai
News Brief
Original YayaNews editorial coverage, published for informational purposes.
This article is sourced from CoinTelegraph. It is for informational purposes only and does not constitute investment advice.
Topics & Symbols
Continue Reading
Related Reading
Crypto for Advisors: It’s time for tokenization to get to work
Crypto for Advisors: It’s time for tokenization to get to work

Bitcoin consolidates below $66,000 as a 13% July recovery runs out of steam
BTC is rangebound between $64,000 and $66,800 after a 13% recovery from July's lows, with macro markets offering little direction and WLFI the session's surprise standout at +12%.

Bulls face a test unlike anything in bitcoin's 17-year history: Crypto Daily
The day ahead in crypto: July 23, 2026

BitMEX notifies users that it is shutting down operations after an 11-year run
The platform, co-founded by Arthur Hayes, has notified users they have until Sept. 23 to withdraw their assets or face penalty charges.
