
A wave of high-profile crypto hacks in April led many to suspect that sophisticated AI tools were being used to identify smart contract exploits, sparking fears that every DeFi protocol was suddenly at risk. In May, Manuel Aráoz, founder of blockchain security platform OpenZeppelin, declared “all of DeFi unsafe” following $630 million in crypto losses from exploits that month. But even as the industry braced for a scenario of DeFi protocols falling like dominoes to agentic AI, the stream of attacks seemed to ebb.
That led Dragonfly managing partner Haseeb Qureshi to declare recently that fears of a DeFi “hackpocalypse” were a “false alarm.” He pointed out that even including April’s big hacks, the year to date has seen “a lower rate of hacked $ per month” and that the “median hack size by year is also declining.” So who’s right? Are the fears totally overblown, or is this just the lull before the storm?
Experts weigh in on AI’s role
Stephen Ajayi, Hacken’s leading offensive security engineer, tells Magazine that he thinks the “hackpocalypse” narrative is overstated if it suggests AI has already replaced compromised keys, weak infrastructure and human error as the main causes of Web3 losses. But he adds that doesn’t mean the fears are entirely misplaced. “I would not confuse ‘not dominant yet’ with ‘not coming.’ My view is that we are still in the early stages: the hype is ahead of the incident data, but the capability curve is catching up quickly,” Ajayi clarifies.
AI is changing attacks, even if it isn’t causing them
Web3 protocols lost more than $1.3 billion across 344 security incidents in the first half of 2026, according to CertiK’s H1 report. It’s impossible to say how many of those incidents involved AI-identified or assisted exploits. Natalie Newson, senior blockchain investigator at CertiK, explains that “proving whether AI was used to find an exploit can be difficult.” Rather than looking for direct attribution, Newson says she watches for circumstantial evidence like changes in attacker behavior. She notes there’s been a large increase in older smart contracts and unverified contracts being exploited.
CertiK’s report found that 73 code vulnerability incidents in the first half of 2026 had been deployed for at least a year before being exploited. “In 2025 as a whole this number was 45,” Newson says. This suggests AI is helping attackers analyze far larger volumes of code than was previously practical. Instead of inventing entirely new attack classes, AI appears to be making existing ones cheaper, faster and easier to scale. “AI systems can help analyze codebases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas for deeper review,” Newson says. “An attacker, or a defender, can examine far more contracts in a given amount of time,” meaning older codebases may now be at risk.
The real danger is scale
Blockchain data platform Chainalysis also sees AI’s biggest impact as being a multiplier for activity, thereby industrializing familiar forms of crypto crime. Sully Hanif, head of UK public sector at Chainalysis, says that their 2026 crypto crime report found that AI-enabled crypto scams are 4.5x more profitable than traditional scams, extracting $3.2 million per operation versus $719,000. “AI is enabling scammers to reach and manipulate far more victims simultaneously,” he notes. The danger does not just come from smart contract exploits. Chainalysis found that impersonation scams increased more than 1,400% year over year in 2025, with criminals using AI-generated deepfakes and face-swapping software readily available on Telegram marketplaces.
“We’ve seen AI supercharge existing playbooks,” Hanif says. “The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more effective.” Chainalysis recently identified $36.7 million stolen from protocols whose smart contract source code had never been publicly verified. Hanif warns that attackers are using large language models to reverse engineer raw bytecode and identify vulnerabilities at scale. “AI is likely to have its greatest impact where human effort has traditionally been the bottleneck,” Newson adds. “We’re observing AI being used to impersonate support staff, video calls, influencers… The biggest risk is that attackers no longer need technical expertise or strong language skills.”
Where are the billion-dollar hacks coming from?
Looking at the data, the biggest crypto losses of 2026 could have been carried out without the use of AI. CertiK’s report found wallet compromise remained the most damaging attack vector during the first half of the year, accounting for more than $444 million in losses across just 33 incidents. Hacken’s Q2 2026 Web3 security report found that roughly 88% of all value stolen during the second quarter was due to compromised keys, signers and operational infrastructure rather than smart contract bugs, largely driven by two North Korean-linked attacks against Drift Protocol and KelpDAO. Ajayi notes that rather than replacing traditional attack methods, AI is amplifying them by identifying vulnerable employees, generating convincing phishing campaigns, analyzing public code and accelerating exploit development. However, compromised governance, poor operational security and weak infrastructure still determine whether attacks succeed. “AI is a new amplifier, but the old security failures still determine how large the blast becomes,” he said.
AI changes the battlefield, but not the fundamentals
Of course, AI can also be used as a force for good, and the security industry is deploying it defensively as well. Hanif said investigators are moving from reactive to preventative, and “the tools exist now to stop scams before victims lose money.” “Ultimately, AI is likely to enhance the capabilities of both attackers and defenders,” Newson said, “with the balance of advantage depending on which side is able to integrate and operationalize the technology most effectively.”
As the debate continues, one thing is clear: the fears of an AI-driven DeFi hack epidemic are not unfounded, but they are currently overstated. The data shows that traditional security failures remain the primary cause of losses, while AI serves as a force multiplier that is gradually reshaping the threat landscape. The industry must prepare for a future where AI-powered attacks become more sophisticated, but it also has the opportunity to leverage the same technology for defense. The lull in attacks may be temporary, and the storm could still come.
Source:Cointelegraph News
