Longtime Ethereum developer Péter Szilágyi caused a bit of a stir last month when he shared a post about artificial intelligence.
“Been using LLMs the entire year, but yesterday was the first time I sent them out bug-hunting proper in my codebase,” he wrote. He was blown away. In fact, the experience appears to have been rather frightful. “We’re f***ed,” he concluded.
This kind of alarmism has its critics, who say that AI can help defenders as much as it can help cybercriminals. But Szilágyi isn’t the only worrywart. “The cyberhacking capability was stunning,” Microsoft founder Bill Gates recently said of Anthropic’s Mythos model. “We’re just in a period of extreme vulnerability to cyberattack.”
This double-edge sword — turbocharged offense and turbocharged defense — is especially relevant to crypto, where much of the code is publicly available and where developers often strive to ship “immutable” code, which can’t be patched after deployment.
Cybercriminals carried out 207 separate hacks in the first half of 2026, according to crypto security firm TRM Labs. It was the highest number the firm ever recorded in any six month period, and it attributed the increase to “smart contract exploits targeting DeFi protocols, decentralized exchanges, and token projects.”
The rapid pace of AI development and the troubling rise in crypto exploits raise two questions: First, are cybercriminals actually using AI to steal digital assets? Second, how vulnerable is the industry, really?
In our latest research report, we partnered with Firepan to answer these questions. What we found might surprise you.
AI-assisted social engineering
Firepan reviewed all 1,236 incidents in DefiLlama's hacks database between June 2011 and August 2026. Artificial intelligence played a role in just one: the April exploit of Zerion.
That month, hackers affiliated with North Korea drained $100,000 from Zerion's hot wallet after spending weeks working on employees over Telegram, LinkedIn, and Slack. DefiLlama's incident record says the Zerion attackers used AI-assisted social engineering to get the employees' credentials.
But that number is suspiciously low — one case of AI-fueled hacking in fifteen years probably says more about what attackers disclose than about what they use.
So Firepan went back to each incident in the DefiLlama database, and took a look at the code as it stood before the exploit. Could a current code-analysis agent find the vulnerability and build a working exploit?
Bad news and good news
Of the 1,236 incidents, 60% were rated both AI-discoverable and AI-exploitable. But the database includes exploits targeting centralized exchanges and other software with off-chain components.
Of 1,040 incidents that targeted DeFi protocols running entirely onchain, 68% were rated both AI-discoverable and AI-exploitable. Another 12.9% were partially reproducible: the flaw was visible in code, but the exploit needed something an agent could not supply on its own. The remaining 19.1% sat outside the reach of code analysis entirely.
The good news is, hacks that could be executed entirely by AI weren’t especially lucrative for the attackers. They made up 60% of the dataset, but only 23% of the $20 billion lost. Hacks that AI couldn’t pull off made up 27% of the dataset and 46% of the money lost.
That’s because the data is skewed by a handful of massive hacks, and most of those were key and signer failures — in other words, human error, rather than a bug in the code.
→ LATEST FROM DEFILLAMA RESEARCH
→ DEEP CUTS
Vault Economy, Revisited
Our Vault Economy report with Sentora found capital moving away from pooled lending markets and into vaults where a named curator sets the risk rules. Three months later, the migration has only increased.
Curated-vault TVL is up 64.8% year to date, to $9.30B. Lending TVL is down 10.0% over the same stretch, even as the tracked-curator universe grew from 55 to 90.
Revenue capture hasn't budged, and Sentora still converts fees to revenue at more than double Steakhouse's rate. That’s 11.79% versus 5.89% over the trailing year, despite generating less TVL and fewer raw fees. Gauntlet remains the weakest capturer, at 2.03%.
Concentration eased slightly. The top three curators now hold 70.4% of the market, down from 75.9% in July.
→ FIELD NOTES
→ WEEKLY NEWS ROUNDUP
Join the DefiLlama Telegram channel to see the full weekly roundup.
NEWS
LAYER 1 & 2
DEFI
READS
RAISES
SECURITY
AI
→ TOOLS FOR LLAMAS
Introducing the new Card Compare dashboard
Which crypto cards pay cashback? Which skip foreign exchange fees? Which are self-custodial? Until now, the only way to find out was checking three dozen provider websites one by one.
Card Compare puts 30 crypto cards side by side: cashback rates, annual and FX fees, ATM fees, airport lounge access, Apple and Google Pay support, spending limits, and which cryptocurrencies each one lets you spend, filterable by country.
One thing that turned up while building it: "up to 12%" cashback headlines often hide tiny base rates, spending caps, and token-holding requirements that quietly erase the reward before it shows up on a statement.









