AI Raises DeFi Risk; Major Hacks Still Driven by Key Compromise
Security firms report AI enables attackers to analyze more contracts and scale scams, while most 2026 losses remain linked to compromised keys and infrastructure.
Security firms and blockchain investigators report that AI tools are allowing attackers to analyze more smart contracts, scale scams and increase impersonation. In April, several high-profile breaches together accounted for roughly $630 million in losses. After a quieter May and June, some industry observers noted a lower monthly rate of stolen funds and a falling median hack size for the year to date.
Blockchain security firm CertiK recorded more than $1.3 billion lost across 344 security incidents in the first half of 2026. Wallet and key compromises were the single largest source of loss, accounting for more than $444 million in 33 incidents. Hacken’s report for the second quarter found that about 88% of the value stolen in Q2 came from compromised keys, signers and operational infrastructure.
Investigators report a rise in attacks on older and unverified contracts. CertiK found 73 vulnerability incidents in the first half of 2026 that targeted contracts deployed at least a year earlier, up from 45 for all of 2025. Chainalysis data show AI-enabled scams are roughly 4.5 times more profitable than traditional scams, extracting about $3.2 million per operation compared with $719,000 for older techniques. Chainalysis also identified $36.7 million taken from protocols whose smart contract source code had never been publicly verified and reported a surge in impersonation campaigns.
Natalie Newson, senior blockchain investigator at CertiK, noted that “proving whether AI was used to find an exploit can be difficult,” and investigators look for circumstantial signs such as shifts in attacker behavior. Stephen Ajayi, an offensive security engineer at Hacken, cautioned that while AI is changing attack methods, compromised credentials and weak operational security remain primary enablers of large thefts: “I would not confuse ‘not dominant yet’ with ‘not coming.'”
Security teams are also using AI defensively. Firms report tools that flag suspicious logic, summarize complex code and prioritize areas for manual review. Chainalysis representatives reported that investigators are moving from reactive work to more preventative measures and that fraud-as-a-service offerings now include modular tools augmented by AI.
Reports show the sector continues to record significant losses driven largely by key and infrastructure compromises, and security firms document changes in attacker activity consistent with wider use of AI-assisted methods.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








