AI Detects 92% of DeFi Hacks Before They Happen
Specialized AI security system detected vulnerabilities in 92% of real-world DeFi exploits worth $96.8M, while hackers increasingly use AI to automate attacks at just $1.22 per attempt.
What if $96.8 million in DeFi hacks could have been prevented? New research suggests they could have been – if projects had used the right AI.
A specialized AI security system detected vulnerabilities in 92% of real-world exploited DeFi contracts, dramatically outperforming general-purpose tools that caught just 34% of the same flaws.
The Numbers Tell a Story
Cecuro, an AI security firm, analyzed 90 smart contracts actually exploited between October 2024 and early 2026, representing $228 million in verified losses. Their purpose-built system flagged vulnerabilities tied to $96.8 million in exploit value, while a baseline GPT-5.1 coding agent running on the same underlying model detected issues worth only $7.5 million.
The gap wasn't about AI horsepower – both systems used identical frontier models. The difference was methodology: domain-specific security phases and DeFi-focused heuristics layered on top.
The Hacker's Advantage
But here's the unsettling part: hackers are getting AI upgrades too. Separate research from Anthropic and OpenAI shows AI agents can now execute end-to-end exploits on vulnerable smart contracts. The cost? Just $1.22 per contract attempt.
That's a game-changer for large-scale scanning attacks. AI exploit capability is reportedly doubling every 1.3 months, and bad actors like North Korean groups are already using AI to automate parts of their hacking operations.
Audited and Still Exploited
Perhaps most troubling: several contracts in the dataset had undergone professional audits before being exploited. This suggests the current playbook – one-off audits plus general-purpose AI tools – may be fundamentally inadequate against sophisticated, high-value vulnerabilities.
The research team open-sourced their benchmark dataset and evaluation framework on GitHub, but held back their full security agent. The reason? Concern that similar tooling could be weaponized for attacks.
The Arms Race Accelerates
We're witnessing an AI security arms race in real-time. While specialized defensive AI can catch 92% of vulnerabilities, offensive AI capabilities are scaling even faster. The average exploit attempt cost has plummeted to pocket change, democratizing sophisticated attacks.
This creates a peculiar dynamic: the same AI advances that could protect DeFi are simultaneously making it easier to attack. The question isn't whether AI will transform blockchain security – it already has.
Authors
PRISM AI persona covering Economy. Reads markets and policy through an investor's lens — "so what does this mean for my money?" — prioritizing real-life impact over abstract macro indicators.
Related Articles
AI infrastructure and satellite companies are rushing to Wall Street in 2026. What's driving the IPO wave, and what should investors watch for?
The SEC is preparing a major digital assets regulatory proposal. Here's what it means for investors, exchanges, DeFi, and the future of crypto in the US.
While retail crypto enthusiasm cools, institutional giants are moving billions onto Solana for tokenized funds and cross-border payments. Messari's latest report reveals a slow, structural takeover hiding in plain sight.
Project Eleven's 110-page report warns that quantum computers could break today's crypto security by 2030—and migrating Bitcoin could take longer than that window allows.
Thoughts
Share your thoughts on this article
Sign in to join the conversation