AI as a tool of attackers and defenders in DeFi
DeFi protocols publicly disclose much of their code, and transactions with users’ assets are executed through smart contracts. As a result, each new generation of software analysis tools is also quickly emerging as a security issue in the sector. On April 7, 2026, Anthropic unveiled Claude Mythos Preview, a model designed to find vulnerabilities in software on its own, as part of the Project Glasswing initiative, which reignited the debate about whether such tools can equally accelerate attacks on DeFi protocols as well as defending them.
Source: cointelegraph
Claude Mythos and Project Glasswing
Claude Mythos Preview is, according to Anthropic, a general model capable of independently finding zero-day vulnerabilities in software and creating functional exploits for them. As part of the Project Glasswing initiative, selected partners, including AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, who use it to review and protect their own infrastructure, have been given access to the model. The model is not publicly available, and Anthropic has not announced that it will change this for now. According to Anthropic’s report, Project Glasswing had found more than 10,000 vulnerabilities of high or critical severity as of May 22, 2026, including a 17-year-old vulnerability in FreeBSD’s NFS server and a 27-year-old vulnerability in OpenBSD that had survived all security audits by then. On June 12, 2026, a U.S. government order went into effect regarding concerns about the possible circumvention of security restrictions when looking for software vulnerabilities. Due to the inability to verify the nationality of users, Anthropic then temporarily suspended access to the Claude Fable 5 and Claude Mythos 5 models for all users, not just the foreign nationals to whom the order originally referred, while other Anthropic models remained available. The restrictions were lifted on June 30, 2026.
Source: cointelegraph
Why DeFi is sensitive to tools like this
DeFi protocols make a large part of their code public, which allows security teams to review, but the same goes for potential attackers. In addition, transactions with user assets are executed through smart contracts, so a bug in the code can allow funds to be moved quickly without additional approval. Finding a vulnerability is not the same as a successful attack, though. According to an analysis by Stephen Ajayi, a leading offensive security engineer at Hacken, a successful attack usually requires an understanding of the protocol’s mechanics, available capital, and coordination of multiple transactions, rather than just an identified vulnerability in the code.
Source: cointelegraph
Data for the first half of 2026
According to a report by CertiK, in the first half of 2026, losses of more than $1.31 billion were recorded in 344 security incidents on Web3 protocols. Manuel Aráoz, founder of the OpenZeppelin security platform, warned in May 2026 after losses of $630 million in April that the entire DeFi sector should be viewed as at risk. Natalie Newson, a senior investigator at CertiK, states that in the first half of 2026, as many as 73 cases of exploiting vulnerabilities in the code involved smart contracts that had been in operation for more than a year before the attack, compared to 45 such cases throughout 2025. According to her assessment, this could be a sign that AI tools allow attackers to analyze a significantly larger number of smart contracts than was previously common, although the data on older contracts alone does not directly prove the use of AI tools in individual attacks. Based on the same data for 2026, Haseeb Qureshi, managing partner of the investment firm Dragonfly, estimates that there has been a lower monthly amount of hacked assets and a decrease in the median size of individual hacks compared to previous years, which, according to him, shows that fears of the so-called “AI hacker apocalypse” are exaggerated for now.
Source: cointelegraph
Where do the big losses come from?
According to Hacken’s second-quarter 2026 report, about 88 percent of the total stolen value during that period was related to compromised private keys, signers, and operational infrastructure, rather than smart contract flaws. Much of that value relates to two attacks that researchers link to groups from North Korea, targeting the Drift Protocol and Kelp DAO platforms. According to Chainalysis’ Crypto Crime Report 2026, fraud with on-chain links to AI tool providers in 2025 averaged $3.2 million per operation in 2025, compared to $719,000 for traditional scams, according to Sully Hanif, the company’s UK public sector manager. He adds that phishing scams have increased by more than 1,400 percent year-on-year in 2025, with the increasingly available use of AI tools to create deepfake content.
Source: cointelegraph
AI and on the side of defense
Security companies also use AI tools to review code, monitor on-chain activity, and work on bug bounty programs. According to Natalie Newson from CertiK, the same tools can also be used for defensive security analysis, while their actual effect depends on who applies the technology faster and more efficiently in practice. Stephen Ajayi adds that for now, AI mainly accelerates existing attack methods, such as code analysis and creating phishing campaigns, while weaknesses such as poor access management and operational security still largely determine the extent of the damage when an attack occurs. According to him, this does not mean that the risk of more advanced AI attacks is not present, but that the data so far does not show that AI has replaced the current causes of losses in the sector.
