A wave of high-profile crypto hacks in April, which many suspected were orchestrated using sophisticated AI tools to identify smart contract exploits, raised fears that every DeFi protocol was suddenly under threat.
In May, Manuel Aráoz, founder of blockchain security platform OpenZeppelin, declared “all DeFi dangerous” after $630 million in crypto losses due to exploits in April.
But even as the industry prepared for the scenario in which DeFi protocols fell like dominoes in the face of agentic AI, the flow of attacks seemed to diminish.
This led Dragonfly Managing Partner Haseeb Qureshi to recently state that fears of a DeFi “hackpocalypse” were a “false alarm.” He pointed out that even including April’s big hacks, the year to date has seen “a lower rate of dollars hacked per month” and that “the median size of hacks per year is also declining.”
So who is right? Are fears of an AI-driven hacking epidemic completely overblown, or is this simply a lull before the storm?
“I think the ‘hackpocalypse’ narrative is overblown if it suggests that AI has already replaced compromised keys, weak infrastructure and human error as the primary causes of Web3 losses,” Stephen Ajayi, Hacken’s principal offensive security engineer, told the Magazine.
But he adds that this does not mean these fears are completely unjustified.
“I wouldn’t confuse ‘not yet dominant’ with ‘not coming’. My view is that we are still in the early stages: the hype is ahead of the incident data, but the capacity curve is quickly catching up,” says Ajayi.
AI modifies attacks, even if it is not the cause
Web3 protocols lost more than $1.3 billion due to 344 security incidents in the first half of 2026, according to CertiK’s H1 report.
It is impossible to say how many of these incidents involved identified or AI-assisted exploits. Natalie Newson, senior blockchain researcher at CertiK, explains that “it can be difficult to prove whether AI was used to find an exploit.”
Related: AI-powered hacks could kill DeFi – unless projects act now
Rather than looking for direct attribution, Newson says she watches for circumstantial evidence, like changes in attackers’ behavior. She notes that there has been a large increase in old smart contracts and unverified contracts being exploited.
CertiK’s report reveals that 73 code vulnerability incidents in the first half of 2026 had been deployed for at least a year before being exploited. “Over the whole of 2025, that number was 45,” says Newson. This suggests that AI is helping attackers analyze much larger volumes of code than before.
Instead of inventing entirely new attack classes, AI appears to make existing classes cheaper, faster, and easier to evolve.

Monthly change in crypto exploit amounts and number of incidents during the first half of the year. Source: Certik
“AI systems can help analyze code bases, identify patterns associated with known vulnerabilities, flag suspicious logic, summarize complex code, and prioritize areas for further review,” says Newson.
“An attacker, or defender, can look at many more contracts in a given amount of time,” she said, meaning older codebases may now be at risk.
The real danger is scale
Blockchain data platform Chainalysis also sees AI’s most significant impact as an activity multiplier, thereby industrializing familiar forms of crypto-crime.
Sully Hanif, head of UK public sector at Chainalysis, told the magazine: “Our 2026 Crypto Crime Report found that AI-powered crypto scams are 4.5 times more profitable than traditional scams, extracting $3.2 million per transaction compared to $719,000.
“AI allows fraudsters to reach and manipulate many more victims simultaneously. »
The danger doesn’t just come from smart contract exploits. Chainalysis found that impersonation scams increased by more than 1,400% year-over-year in 2025, with criminals using AI-generated deepfakes and face-swapping software readily available on Telegram marketplaces.
“We’ve seen AI supercharge existing playbooks,” he says. “The fraud-as-a-service ecosystem now offers modular, turnkey services and AI makes each module more efficient. »
Related: AI models have led to a ‘vulnerability apocalypse’ in crypto security: Immunefi CEO
Chainalysis recently identified $36.7 million stolen from protocols whose smart contract source code has never been publicly verified. Hanif warns that attackers use large language models to reverse engineer raw bytecode and identify vulnerabilities at scale.

The data: $36.7 million from unaudited contracts. Source: Chainalysis
“AI will likely have its greatest impact where human effort has traditionally been the bottleneck,” says Newson. “We are seeing AI being used to impersonate support staff, video calls, influencers (…) The biggest risk is that attackers no longer need technical expertise or strong language skills.”
So where do these billions of dollars in hacks come from?
Looking at the data, the biggest crypto losses of 2026 could have been achieved without the use of AI.
CertiK’s report reveals that wallet compromise remained the most damaging attack vector during the first half of the year, accounting for more than $444 million in losses across just 33 incidents.
Hacken Q2 2026 Web3 Security Report find that approximately 88% of all value stolen during the second quarter was due to compromised keys, signers, and operational infrastructure rather than smart contract bugs, largely due to the two North Korea-linked attacks on Drift Protocol and KelpDAO.

Of the $763,971,791 stolen, 88.3% was traced to compromised keys, signers, and infrastructure. Source: Hacken
Ajayi believes that rather than replacing traditional attack methods, AI amplifies them by identifying vulnerable employees, generating convincing phishing campaigns, analyzing public code, and accelerating the development of exploits. However, compromised governance, poor operational security, and weak infrastructure still determine the success of attacks.
“AI is a new amplifier, but old security flaws still determine the scale of the explosion,” he said.
AI changes the battlefield, but not the fundamentals
Of course, AI can also be used as a force for good, and the security industry deploys it defensively as well. Hanif said investigators are moving from reaction to prevention, and “the tools now exist to stop scams before victims lose money.”
“Ultimately, AI is likely to enhance the capabilities of both attackers and defenders,” Newson said, “with the balance of benefit depending on which party is able to integrate and operationalize the technology most effectively.”
Review: The strategy has become a symbol of the Internet crash: could history repeat itself?
Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject matter expertise. All articles are edited and reviewed by Cointelegraph editors in accordance with our editorial standards. The content published here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains complete editorial independence.