A wave of high-profile cryptocurrency hacks in April, which many believed were orchestrated by using sophisticated artificial intelligence tools to identify shrewd contract exploits, raised fears that every DeFi protocol was suddenly compromised.
In May, Manuel Aráoz, founder of blockchain security platform OpenZeppelin, declared that “all of DeFi is dangerous” following April’s $630 million in crypto losses due to exploits.
But even as the industry braced for a scenario in which DeFi protocols would fall like dominoes towards agent-based AI, the stream of attacks seemed to snail-paced down.
This prompted Dragonfly managing partner Haseeb Qureshi to declare that recent fears of a DeFi “hackpocalypse” were a “false alarm.” He emphasized that even accounting for April’s major hacks, we have seen a “lower rate of monthly dollar breaches year-to-date” and that “the average size of hacks year-over-year is also decreasing.”
So who is right? Are fears of an epidemic of AI-powered hackers completely exaggerated, or is this just the peaceful before the storm?
“I think the hackpocalypse narrative is overblown if it suggests that AI has already replaced compromised keys, poor infrastructure and human error as the main causes of Web3 losses,” Stephen Ajayi, Hacken’s lead offensive security engineer, tells Magazine.
But, he adds, that doesn’t mean the concerns are completely wrong.
“I wouldn’t confuse ‘I’m not dominating yet’ with ‘I won’t come.’ In my opinion, we are still in the early stages: the hype has outpaced the incident data, but the opportunity curve is quickly catching up,” explains Ajayi.
AI changes attacks even if it doesn’t cause them
CertiK’s half-year report shows that Web3 protocols lost more than $1.3 billion in the first half of 2026 as a result of 344 security incidents.
It’s impossible to say how many of these incidents involved AI-identified or AI-enhanced exploits. Natalie Newson, senior blockchain researcher at CertiK, explains that “it can be difficult to prove whether artificial intelligence was used to find an exploit.”
Related: AI-powered hacks could kill DeFi – unless projects start acting now
Instead of looking for direct attribution, Newson says he looks for circumstantial evidence, such as changes in the attacker’s behavior. It notes that the employ of legacy shrewd contracts and unverified contracts has increased significantly.
The CertiK report shows that in the first half of 2026, 73 code vulnerability incidents were deployed for at least a year before being exploited. “For all of 2025, the number was 45,” Newson says. This suggests that AI is helping attackers analyze much larger amounts of code than was previously practical.
Instead of inventing entirely recent classes of attacks, AI makes existing ones cheaper, faster and easier to scale.
Monthly change in the number of cryptographic exploits and the number of incidents in the first half of the year. Source: CertiK
“AI systems can help analyze code bases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas requiring deeper analysis,” Newson says.
“An attacker or defender can check many more contracts in a given time,” she said, which means older codebases could now be at risk.
The real threat is scale
Blockchain data platform Chainalytic also sees AI’s greatest impact as an activity multiplier, thus industrializing familiar forms of crypto crime.
Sully Hanif, head of UK public sector at Chainalytic, tells Magazine: “Our 2026 Crypto Crime Report found that AI-enabled cryptocurrency scams are 4.5 times more profitable than traditional scams, raking in $3.2 million per operation compared to $719,000.”
“Artificial intelligence enables fraudsters to target and manipulate many more victims at once.”
The threat does not arise solely from the employ of shrewd contracts. Chainalytic found that impersonation scams increased by more than 1,400% year-on-year in 2025, with criminals taking advantage of AI-generated counterfeit news and face-swapping software that were readily available on Telegram marketplaces.
“We have seen artificial intelligence supercharging existing textbooks,” he says. “The fraud-as-a-service ecosystem now offers modular, turnkey services, with artificial intelligence making each module more effective.”
Related: Artificial intelligence models led to ‘vulnerability apocalypse’ in cryptocurrency security: Immunefi CEO
Recently, chain analysis identified $36.7 million was stolen from protocols whose shrewd contract source code has never been publicly verified. Hanif warns that attackers are using enormous language models to reverse engineer raw bytecode and identify vulnerabilities at scale.

Figures: $36.7 million in unverified contracts. Source: Chain Analysis
“Artificial intelligence is likely to have its greatest impact where human effort has traditionally been a bottleneck,” says Newson. “We are seeing AI being used to impersonate support staff, video calls and influencers […] The biggest risk is that attackers will no longer need technical expertise or strong language skills.”
So where do billion-dollar hacks come from?
Looking at the data, the largest cryptocurrency losses in 2026 could have been incurred without the employ of artificial intelligence.
The CertiK report found that wallet hacking remained the most damaging attack vector in the first half of the year, causing over $444 million in losses in just 33 incidents.
Hacken Web3 Security Report Q2 2026 found that approximately 88% of all value stolen in the second quarter resulted from compromised keys, signers and operational infrastructure rather than shrewd contract bugs, which were largely contributed to by two North Korea-linked attacks on Drift Protocol and KelpDAO.

Of the $763,971,791 stolen, 88.3% involved compromised keys, signers and infrastructure. source: Hacken
Instead of replacing classic attack methods, Ajayi says AI enhances them by identifying vulnerable employees, generating compelling phishing campaigns, analyzing public code and accelerating the development of exploits. However, compromised management, indigent operational security and tender infrastructure still depend on whether attacks are successful.
“Artificial intelligence is the new booster, but old safety failures still determine how big the outbreak will be,” he said.
Artificial intelligence is changing the battlefield, but not the fundamentals
Of course, AI can also be used as a force for good, and the security industry is also using it defensively. Hanif said investigators are moving from reactive to preventive efforts and “tools now exist to stop fraud before victims lose money.”
“Ultimately, AI will likely enhance the capabilities of both attackers and defenders,” Newson said, “with the balance of benefits depending on which side can most effectively integrate and deploy the technology.”
Warehouse: The strategy became a symbol of the Internet crash: could history repeat itself?
Cointelegraph publishes long-form journalism, analysis and narrative reporting from Cointelegraph’s in-house editorial team with subject matter expertise. All articles are edited and reviewed by Cointelegraph editors in accordance with our editorial standards. The content published on this website does not constitute financial, legal or investment advice. Readers should conduct their own research and, if necessary, consult qualified professionals. Cointelegraph maintains full editorial independence.
