Crypto Hackpocalypse or False Alarm? AI's Evolving Role in DeFi Security
Experts debate whether AI is already driving a wave of crypto exploits or merely amplifying existing vulnerabilities, as data shows a complex picture of Web3 losses.
Auf einen Blick
- A debate rages over whether AI is causing a 'hackpocalypse' in DeFi.
- While April saw major crypto losses, some experts call it a false alarm, citing declining median hack sizes.
- Others warn AI is rapidly enhancing existing attack methods, making older contracts vulnerable and industrializing crypto crime, even if it hasn't replaced traditional security failures.
KI-generierte Zusammenfassung
Warum es wichtig ist
A debate is ongoing within the crypto industry regarding the extent to which AI is driving recent high-profile hacks and whether fears of a 'DeFi hackpocalypse' are justified. While some data suggests a declining rate of hacked funds, experts warn that AI is rapidly enhancing existing attack methods.
A wave of high profile crypto hacks in April that many suspected had been orchestrated using sophisticated AI tools to identify smart contract exploits, led to fears that every DeFi protocol was suddenly at risk.
In May, Manuel Aráoz, founder of the blockchain security platform OpenZeppelin, declared “all of DeFi unsafe” following $630 million in crypto losses from exploits in April.
But even as the industry braced for the scenario of DeFi protocols falling like dominoes to agentic AI, the stream of attacks seemed to ebb.
That led Dragonfly managing partner Haseeb Qureshi to declare recently that fears of a DeFi “hackpocalypse” were a “false alarm.” He pointed out that even including April’s big hacks, the year to date has seen “a lower rate of hacked $ per month” and that the “median hack size by year is also declining.”
So who’s right? Are the fears of an AI driven hacking epidemic totally overblown, or is this just the lull before the storm?
“I think the ‘hackpocalypse’ narrative is overstated if it suggests AI has already replaced compromised keys, weak infrastructure and human error as the main causes of Web3 losses,” Stephen Ajayi, Hacken’s leading offensive security engineer, tells Magazine.
But he adds that doesn’t mean the fears are entirely misplaced.
“I would not confuse ‘not dominant yet’ with ‘not coming.’ My view is that we are still in the early stages: the hype is ahead of the incident data, but the capability curve is catching up quickly,” Ajayi clarifies.
AI is changing attacks, even if it isn’t causing them
Web3 protocols lost more than $1.3 billion across 344 security incidents in the first half of 2026, according to CertiK’s H1 report.
It’s impossible to say how many of those incidents involved AI-identified or assisted exploits. Natalie Newson, senior blockchain investigator at CertiK, explains that “proving whether AI was used to find an exploit can be difficult.”
Rather than looking for direct attribution, Newson says she watches for circumstantial evidence like changes in attacker behavior. She notes there’s been a large increase in older smart contracts and unverified contracts being exploited.
CertiK’s report found that 73 code vulnerability incidents in the first half of 2026 had been deployed for at least a year before being exploited. “In 2025 as a whole this number was 45,” Newson says. This suggests AI is helping attackers analyze far larger volumes of code than was previously practical.
Instead of inventing entirely new attack classes, AI appears to be making existing ones cheaper, faster and easier to scale.
“AI systems can help analyze codebases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas for deeper review,” Newson says.
“An attacker, or a defender, can examine far more contracts in a given amount of time,” she said, meaning that older codebases may now be at risk.
The real danger is scale
Blockchain data platform Chainalysis also sees AI’s biggest impact as being a multiplier for activity, thereby industrializing familiar forms of crypto crime.
Sully Hanif, head of UK public sector at Chainalysis, tells Magazine, “Our 2026 crypto crime report found that AI-enabled crypto scams are 4.5x more profitable than traditional scams, extracting $3.2 million per operation versus $719,000.”
“AI is enabling scammers to reach and manipulate far more victims simultaneously.”
The danger does not just come from smart contract exploits. Chainalysis found that impersonation scams increased more than 1,400% year over year in 2025, with criminals using AI-generated deepfakes and face-swapping software readily available on Telegram marketplaces.
“We’ve seen AI supercharge existing playbooks,” he says. “The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more effective.”
Chainalysis recently identified $36.7 million stolen from protocols whose smart contract source code had never been publicly verified. Hanif warns that attackers are using large language models to reverse engineer raw bytecode and identify vulnerabilities at scale.
“AI is likely to have its greatest impact where human effort has traditionally been the bottleneck,” Newson says. “We’re observing AI being used to impersonate support staff, video calls, influencers [...] The biggest risk is that attackers no longer need technical expertise or strong language skills.”
So where are the billion-dollar hacks coming from?
Looking at the data, the biggest crypto losses of 2026 could have been carried out without the use of AI.
CertiK’s report found wallet compromise remained the most damaging attack vector during the first half of the year, accounting for more than $444 million in losses across just 33 incidents.
Hacken’s Q2 2026 Web3 security report found that roughly 88% of all value stolen during the second quarter was due to compromised keys, signers and operational infrastructure rather than smart contract bugs, largely driven by the two North Korean-linked attacks against Drift Protocol and KelpDAO.
Of the $763,971,791 stolen, 88.3% was traced to compromised keys, signers, and infrastructure.
Ajayi s that rather than replacing traditional attack methods, AI is amplifying them by identifying vulnerable employees, generating convincing phishing campaigns, analyzing public code and accelerating exploit development. However, compromised governance, poor operational security and weak infrastructure still determine whether attacks succeed.
“AI is a new amplifier, but the old security failures still determine how large the blast becomes,” he said.
AI changes the battlefield, but not the fundamentals
Of course, AI can also be used as a force for good, and the security industry is deploying it defensively as well. Hanif said investigators are moving from reactive to preventative, and “the tools exist now to stop scams before victims lose money.”
“Ultimately, AI is likely to enhance the capabilities of both attackers and defenders,” Newson said, “with the balance of advantage depending on which side is able to integrate and operationalize the technology most effectively.”
Offene Fragen
- How many security incidents explicitly involved AI-identified or assisted exploits?
- What specific AI tools are attackers using for deepfakes and code analysis?
- How effectively can defensive AI tools counteract evolving AI-powered attacks?







