Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
AI-Assisted Hackers Steal $36.7M from Unverified DeFi Smart Contracts in First Half of 2026
00

AI-Assisted Hackers Steal $36.7M from Unverified DeFi Smart Contracts in First Half of 2026

Jun 9, 2026

A Chainalysis report reveals that AI-assisted hackers stole $36.7 million from DeFi protocols in the first half of 2026 by exploiting unverified smart contracts. The attackers used advanced decompilation tools to find vulnerabilities in closed-source code. The largest incident was a $26.2 million exploit of Truebit. Chainalysis urges protocols to adopt source code verification as a minimum security standard.

Unverified smart contract exploits

  • ▪Attackers stole approximately $36.7 million from DeFi protocols by exploiting unverified smart contracts between January and May 2026
  • ▪The $36.7 million in losses represents a fraction of the more than $1 billion stolen from all DeFi protocols during the same six-month period
  • ▪The exploited contracts had not been verified on a blockchain explorer, meaning their source code was not publicly available for review

AI-powered decompilation tools

  • ▪Attackers can use large language models to analyze reverse-engineered code and identify common vulnerabilities
  • ▪Advances in AI and smart contract decompilation tools are making it easier for attackers to reverse-engineer closed-source code

Major DeFi protocol attacks

  • ▪Other major incidents included a $5.9 million theft from Trusted Volumes, a $3.2 million loss from Aperture Finance, and a $1.4 million loss from Ekubo
  • ▪The largest direct attack on a protocol's code in January 2026 targeted Truebit on January 8, causing losses of about $26.6 million

Security vulnerabilities in closed-source contracts

  • ▪The Truebit exploit was caused by an integer overflow vulnerability in a contract that had been unverified since 2021
  • ▪Unverified contracts receive less scrutiny from security researchers and are often excluded from bug bounty programs, reducing the chance of discovery
  • ▪Evidence suggests the Truebit attacker systematically hunted for vulnerable contracts before executing the exploit

Smart contract verification recommendations

  • ▪Blockchain analytics firm Chainalysis published a report on the trend, challenging the idea that hiding source code improves security
  • ▪Further recommendations from Chainalysis include auditing deployed code and implementing real-time monitoring for suspicious on-chain activity
  • ▪Chainalysis recommends that protocols treat source code verification as a minimum security standard and expand bug bounty coverage

2 sources

Cointelegraph
Chainalysis: AI-Assisted Attackers Target Hidden DeFi Code
View source article
Cryptotimes
AI-Assisted Hackers Drain $36.7M From Hidden Smart Contracts in 2026
View source article

Featured stories

View more in Smart contract auditing

OpenAI alerts over 100 organizations about rogue AI agent activity

Oct 1, 2026 · 2 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

Share your thoughts

Who is more responsible for preventing DeFi hacks?

Story comments

Loading comments…

Share your thoughts

Who is more responsible for preventing DeFi hacks?

Related Projects

Truebit

Topics

Smart contract auditingDeFi securityDeFiAI securitySmart contracts

Featured stories

View more in Smart contract auditing

OpenAI alerts over 100 organizations about rogue AI agent activity

Oct 1, 2026 · 2 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources