A wave of excessive profile crypto hacks in April that many suspected had been orchestrated utilizing subtle AI instruments to determine good contract exploits, led to fears that each DeFi protocol was instantly in danger.
In Might, Manuel Aráoz, founding father of the blockchain safety platform OpenZeppelin, declared “all of DeFi unsafe” following $630 million in crypto losses from exploits in April.
However even because the business braced for the state of affairs of DeFi protocols falling like dominoes to agentic AI, the stream of assaults appeared to ebb.
That led Dragonfly managing companion Haseeb Qureshi to declare not too long ago that fears of a DeFi “hackpocalypse” had been a “false alarm.” He identified that even together with April’s huge hacks, the 12 months thus far has seen “a decrease price of hacked $ per thirty days” and that the “median hack dimension by 12 months can be declining.”
So who’s proper? Are the fears of an AI pushed hacking epidemic completely overblown, or is that this simply the lull earlier than the storm?
“I feel the ‘hackpocalypse’ narrative is overstated if it suggests AI has already changed compromised keys, weak infrastructure and human error as the primary causes of Web3 losses,” Stephen Ajayi, Hacken’s main offensive safety engineer, tells Journal.
However he provides that doesn’t imply the fears are solely misplaced.
“I’d not confuse ‘not dominant but’ with ‘not coming.’ My view is that we’re nonetheless within the early phases: the hype is forward of the incident information, however the functionality curve is catching up shortly,” Ajayi clarifies.
AI is altering assaults, even when it isn’t inflicting them
Web3 protocols misplaced greater than $1.3 billion throughout 344 safety incidents within the first half of 2026, in response to CertiK’s H1 report.
It’s unattainable to say what number of of these incidents concerned AI-identified or assisted exploits. Natalie Newson, senior blockchain investigator at CertiK, explains that “proving whether or not AI was used to search out an exploit will be tough.”
Associated: AI-driven hacks may kill DeFi — until tasks act now
Slightly than in search of direct attribution, Newson says she watches for circumstantial proof like modifications in attacker habits. She notes there’s been a big enhance in older good contracts and unverified contracts being exploited.
CertiK’s report discovered that 73 code vulnerability incidents within the first half of 2026 had been deployed for no less than a 12 months earlier than being exploited. “In 2025 as an entire this quantity was 45,” Newson says. This implies AI helps attackers analyze far bigger volumes of code than was beforehand sensible.
As an alternative of inventing solely new assault lessons, AI seems to be making present ones cheaper, sooner and simpler to scale.

Month-to-month change in crypto exploit quantities and variety of incidents throughout H1. Supply: CertiK
“AI techniques will help analyze codebases, determine patterns related to recognized vulnerabilities, flag suspicious logic, summarize complicated code, and prioritize areas for deeper assessment,” Newson says.
“An attacker, or a defender, can look at way more contracts in a given period of time,” she mentioned, which means that older codebases might now be in danger.
The true hazard is scale
Blockchain information platform Chainalysis additionally sees AI’s largest influence as being a multiplier for exercise, thereby industrializing acquainted types of crypto crime.
Sully Hanif, head of UK public sector at Chainalysis, tells Journal, “Our 2026 crypto crime report discovered that AI-enabled crypto scams are 4.5x extra worthwhile than conventional scams, extracting $3.2 million per operation versus $719,000.”
“AI is enabling scammers to achieve and manipulate way more victims concurrently.”
The hazard doesn’t simply come from good contract exploits. Chainalysis discovered that impersonation scams elevated greater than 1,400% 12 months over 12 months in 2025, with criminals utilizing AI-generated deepfakes and face-swapping software program available on Telegram marketplaces.
“We’ve seen AI supercharge present playbooks,” he says. “The fraud-as-a-service ecosystem now gives modular, turnkey providers and AI makes every module more practical.”
Associated: AI fashions led to a ‘vulnerability apocalypse’ in crypto safety: Immunefi CEO
Chainalysis not too long ago recognized $36.7 million stolen from protocols whose good contract supply code had by no means been publicly verified. Hanif warns that attackers are utilizing massive language fashions to reverse engineer uncooked bytecode and determine vulnerabilities at scale.


The info: $36.7 million from unverified contracts. Supply: Chainalysis
“AI is more likely to have its best influence the place human effort has historically been the bottleneck,” Newson says. “We’re observing AI getting used to impersonate assist workers, video calls, influencers […] The most important danger is that attackers now not want technical experience or robust language expertise.”
So the place are the billion-dollar hacks coming from?
Trying on the information, the most important crypto losses of 2026 may have been carried out with out the usage of AI.
CertiK’s report discovered pockets compromise remained probably the most damaging assault vector throughout the first half of the 12 months, accounting for greater than $444 million in losses throughout simply 33 incidents.
Hacken’s Q2 2026 Web3 safety report discovered that roughly 88% of all worth stolen throughout the second quarter was as a consequence of compromised keys, signers and operational infrastructure quite than good contract bugs, largely pushed by the 2 North Korean-linked assaults in opposition to Drift Protocol and KelpDAO.


Of the $763,971,791 stolen, 88.3% was traced to compromised keys, signers, and infrastructure. Supply: Hacken
Ajayi s that quite than changing conventional assault strategies, AI is amplifying them by figuring out susceptible staff, producing convincing phishing campaigns, analyzing public code and accelerating exploit improvement. Nonetheless, compromised governance, poor operational safety and weak infrastructure nonetheless decide whether or not assaults succeed.
“AI is a brand new amplifier, however the previous safety failures nonetheless decide how massive the blast turns into,” he mentioned.
AI modifications the battlefield, however not the basics
After all, AI will also be used as a power for good, and the safety business is deploying it defensively as properly. Hanif mentioned investigators are shifting from reactive to preventative, and “the instruments exist now to cease scams earlier than victims lose cash.”
“Finally, AI is more likely to improve the capabilities of each attackers and defenders,” Newson mentioned, “with the steadiness of benefit relying on which facet is ready to combine and operationalize the know-how most successfully.”
Journal: Technique turned an emblem of the dot-com crash: May historical past repeat?
Cointelegraph publishes long-form journalism, evaluation and narrative reporting produced by Cointelegraph’s in-house editorial staff with subject-matter experience. All articles are edited and reviewed by Cointelegraph editors in keeping with our editorial requirements. Content material printed in right here doesn’t represent monetary, authorized or funding recommendation. Readers ought to conduct their very own analysis and seek the advice of certified professionals the place acceptable. Cointelegraph maintains full editorial independence.