Fears that AI-powered tools are triggering an unstoppable wave of DeFi hacks may be premature, but security experts warn the threat is real and accelerating. After a string of high-profile exploits in April 2026 that drained $630 million from crypto protocols, many in the industry feared an AI-driven ‘hackpocalypse.’ Yet the anticipated cascade of attacks has not materialized — at least not yet.
In May, Manuel Aráoz, founder of blockchain security platform OpenZeppelin, declared ‘all of DeFi unsafe’ following the April losses. But Dragonfly managing partner Haseeb Qureshi recently countered that the ‘hackpocalypse’ narrative was a ‘false alarm,’ noting that the year-to-date rate of hacked funds per month is actually lower than previous years, and the median hack size is declining.
Also read: Peter Brandt sets exact date for Bitcoin bear market bottom: October 4, 2026
AI is changing attacks, even if it isn’t causing them
According to CertiK’s H1 2026 report, Web3 protocols lost more than $1.3 billion across 344 security incidents. However, proving whether AI was used to identify or execute a specific exploit remains difficult. ‘Proving whether AI was used to find an exploit can be difficult,’ said Natalie Newson, senior blockchain investigator at CertiK.
Instead of direct attribution, analysts look for circumstantial evidence. Newson notes a sharp increase in older smart contracts and unverified contracts being exploited. CertiK found that 73 code vulnerability incidents in H1 2026 involved contracts deployed for at least a year — compared to just 45 in all of 2025. This suggests AI is enabling attackers to analyze far larger volumes of code than previously practical.
Also read: Michael Saylor publishes 110 reasons why BIP-110 Bitcoin fork is a bad idea
The real danger is scale
Blockchain data platform Chainalysis sees AI’s biggest impact as a multiplier for existing criminal activity. ‘Our 2026 crypto crime report found that AI-enabled crypto scams are 4.5x more profitable than traditional scams, extracting $3.2 million per operation versus $719,000,’ said Sully Hanif, head of UK public sector at Chainalysis.
Impersonation scams increased more than 1,400% year over year in 2025, driven by AI-generated deepfakes and face-swapping software. ‘The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more effective,’ Hanif added. Chainalysis also identified $36.7 million stolen from protocols whose smart contract source code was never publicly verified, with attackers using large language models to reverse engineer raw bytecode.
Where are the billion-dollar hacks coming from?
Despite the AI hype, the biggest crypto losses of 2026 so far stem from traditional attack vectors. CertiK’s report found wallet compromise accounted for more than $444 million in losses across just 33 incidents. Hacken’s Q2 2026 report found that roughly 88% of all value stolen was due to compromised keys, signers, and operational infrastructure — not smart contract bugs. Two North Korean-linked attacks against Drift Protocol and KelpDAO drove much of this.
Stephen Ajayi, Hacken’s leading offensive security engineer, explained: ‘AI is a new amplifier, but the old security failures still determine how large the blast becomes.’ He cautioned against confusing ‘not dominant yet’ with ‘not coming,’ noting that the capability curve is catching up quickly.
Conclusion
The evidence suggests that while AI has not yet triggered a new class of attacks, it is industrializing existing ones — making them cheaper, faster, and more scalable. The security industry is also deploying AI defensively, and the balance of advantage will depend on which side integrates the technology more effectively. For now, the ‘hackpocalypse’ remains a future risk, not a present reality.
FAQs
Q1: Is AI already causing most DeFi hacks?
No. While AI is being used to identify vulnerabilities and amplify attacks, the majority of losses in 2026 still come from compromised keys, poor operational security, and infrastructure failures.
Q2: How is AI making crypto crime more profitable?
AI enables scammers to automate phishing, generate convincing deepfakes, and analyze code at scale. Chainalysis found AI-enabled scams are 4.5x more profitable than traditional ones.
Q3: Can AI also be used to defend DeFi protocols?
Yes. Security firms are deploying AI to detect vulnerabilities, monitor for suspicious activity, and prevent scams before victims lose funds. The outcome depends on which side operationalizes AI more effectively.

Be the first to comment