AI Shrinks Lifespan of Crypto Audits, Researchers Warn
Researchers say AI tools let attackers find smart-contract flaws faster, prompting calls for recurring reaudits after an AI found a four-year Zcash bug and $1.32B was stolen in H1 2026.
Blockchain security firms and researchers are urging crypto projects to schedule recurring reaudits of smart contracts after several recent incidents. Security firm CertiK reported $1.32 billion in blockchain thefts in the first half of 2026. Researchers also used an AI agent to find a four-year-old vulnerability in Zcash’s Orchard shielded pool; the flaw has been patched.
The Zcash issue was identified by a security engineer using a custom auditing agent built on Anthropic’s Claude Opus 4.8. Researchers said the bug could have enabled undetectable counterfeiting within the Orchard shielded pool, one of the network’s privacy features.
Firms report attackers are increasingly returning to older codebases and using automated tools to search for long-hidden weaknesses. Anthropic’s internal tests showed AI agents flagged roughly $4.6 million in exploitable smart-contract issues during controlled evaluations.
Recent exploits targeted inactive or paused projects. On June 14 attackers drained $2.1 million from Aztec Connect, which had ceased operations in March 2023. On June 19 a smart contract on the decentralized exchange mySwap was exploited for about $300,000 despite the platform’s interface having been closed to new liquidity months earlier. In May a white-hat researcher known as 0xflorent recovered 1,003 Ether, about $1.72 million, from a 2016 ICO contract that had been stuck due to a refund bug.
CertiK warned that “the window of maximum vulnerability does not close after launch” and urged projects that run legacy infrastructure to make reaudits a recurring operational requirement.
Ari Redbord, head of policy at TRM Labs, argued the data favor continuous review rather than one-time audits, noting that attack techniques are evolving faster than audits performed at deployment can account for.
Security teams are adapting by combining automated scanning, manual code review, bug bounty programs and continuous monitoring. Some projects are testing AI-powered agents for defensive auditing to match capabilities attackers use. Redbord added that law enforcement and anti-money-laundering efforts are needed to disrupt the actors and the financial networks that benefit from hacks, observing, “Protocols can lock their doors, but someone still has to go after the actor breaking in.”
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.







