SourceStalecollected in 82m

AI-Powered Hacks Target DeFi Protocols for Millions

Read original on The Next Web (TNW)
#cybersecurity#defi#social-engineering#threat-intelligence

Learn how AI is being weaponized in DeFi hacks to bypass traditional security and what you must do to defend your code.

30-Second TL;DR

What Changed

Attackers used AI-driven social engineering to impersonate trading firms and drain $285 million from Drift Protocol.

Why It Matters

The rise of AI-powered exploits forces DeFi developers to adopt more rigorous multi-signature security and AI-based anomaly detection systems. This trend will likely increase the cost of security audits and insurance for decentralized finance applications.

What To Do Next

Implement AI-based behavioral monitoring on your platform's API endpoints to detect anomalous transaction patterns that deviate from standard user behavior.

Who should care:Developers & AI Engineers

Key Points

  • Attackers used AI-driven social engineering to impersonate trading firms and drain $285 million from Drift Protocol.
  • A separate group exploited a single-verifier flaw in Kelp DAO, indicating a trend of automated vulnerability scanning.
  • DeFi platforms are struggling to implement defensive measures against AI-powered adversarial tactics.

Deep Insight

Background and context from public sources — not the original article. 39 sources cited.

Enhanced Key Takeaways

  • AI significantly lowers the cost and time required for vulnerability discovery, compressing the process from months to days or even hours, thereby expanding the attack surface for cybercriminals.
  • North Korean hackers are leveraging AI across the entire cyberattack lifecycle, from initial reconnaissance and target selection to crafting highly convincing phishing campaigns, assisting in malware development, and even streamlining money laundering processes.
  • AI-driven social engineering now includes hyper-realistic deepfakes, voice cloning, and personalized phishing messages that are increasingly difficult to distinguish from legitimate communications, enabling attacks at an unprecedented scale.
  • The Kelp DAO exploit was not a traditional smart contract vulnerability but rather a configuration flaw in its LayerZero cross-chain bridge, specifically a 1-of-1 Decentralized Verifier Network (DVN) setting, which AI tools could have identified.
  • Google has reported the first documented instance of cybercriminals successfully developing a zero-day exploit with AI, targeting an unnamed open-source, web-based IT admin tool.

Technical Deep Dive

  • Large Language Models (LLMs) are foundational to AI-powered attacks, enabling the generation of human-like text for social engineering and automated code analysis.
  • AI tools can perform both static and dynamic analysis of smart contract code to identify vulnerabilities such as reentrancy or economic exploits, and utilize unsupervised machine learning for anomaly detection.
  • Attackers leverage AI for prompt injection, model poisoning, and exploiting LLM APIs to extract data or trigger malicious actions.
  • AI agents have demonstrated the capability to autonomously detect vulnerabilities, construct transaction sequences, and generate complete exploit scripts, as shown in research using models like GPT-5 and Claude Opus 4.5.
  • AI-powered vulnerability scanning can reduce the average cost of scanning a smart contract to as low as $1.22.
  • AI is employed for semantic code similarity analysis, dependency analysis, and cross-chain deployment detection to identify inherited vulnerabilities in forked protocols.

Future ImplicationsAI analysis grounded in cited sources

Regulatory bodies will mandate continuous, AI-aware audits for DeFi platforms and smart contracts.
The rapid evolution of AI-driven exploits necessitates proactive and continuous security assessments that can adapt to new AI-generated threats, pushing regulators to require more stringent, AI-integrated auditing processes.
The cost of vulnerability detection will trend towards zero, making it easier for even low-skill criminals to launch sophisticated attacks.
AI dramatically lowers the barrier to entry for cybercrime by automating complex tasks like vulnerability scanning and exploit generation, increasing the frequency and sophistication of attacks from a wider range of actors.
Defensive AI systems will increasingly be deployed to counter adversarial AI, leading to an 'AI vs. AI' cybersecurity arms race.
As attackers leverage AI for more sophisticated and scalable threats, defenders will need to adopt AI-powered threat detection, response automation, and continuous monitoring to keep pace and effectively protect digital assets.

Timeline

2016
North Korean-linked actors begin a decade of crypto theft, accumulating an estimated $6.75 billion by early 2026.
2023
Samsung employees inadvertently leak sensitive internal data by submitting it to ChatGPT, highlighting early AI-related data security risks.
2024-01
South Korea's intelligence agency reports North Korean hackers are using generative AI for cyberattacks and target identification.
2025-02
Bybit suffers a $1.46 billion breach, the largest single crypto hack in history, largely attributed to North Korean actors.
2026-04-01
Drift Protocol is exploited for $285 million through a months-long social engineering operation, suspected to involve North Korean actors.
2026-04-18
Kelp DAO is exploited for $292 million due to a single-verifier flaw in its LayerZero cross-chain bridge, attributed to North Korean hackers.
2026-05-11
Google reports the first instance of cybercriminals successfully developing a zero-day exploit with AI.

Sources (39)

Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.

1Google Search Sourcevertexaisearch.cloud.google.com2Google Search Sourcevertexaisearch.cloud.google.com3Google Search Sourcevertexaisearch.cloud.google.com4Google Search Sourcevertexaisearch.cloud.google.com5Google Search Sourcevertexaisearch.cloud.google.com6Google Search Sourcevertexaisearch.cloud.google.com7Google Search Sourcevertexaisearch.cloud.google.com8Google Search Sourcevertexaisearch.cloud.google.com9Google Search Sourcevertexaisearch.cloud.google.com10Google Search Sourcevertexaisearch.cloud.google.com11Google Search Sourcevertexaisearch.cloud.google.com12Google Search Sourcevertexaisearch.cloud.google.com13Google Search Sourcevertexaisearch.cloud.google.com14Google Search Sourcevertexaisearch.cloud.google.com15Google Search Sourcevertexaisearch.cloud.google.com16Google Search Sourcevertexaisearch.cloud.google.com17Google Search Sourcevertexaisearch.cloud.google.com18Google Search Sourcevertexaisearch.cloud.google.com19Google Search Sourcevertexaisearch.cloud.google.com20Google Search Sourcevertexaisearch.cloud.google.com21Google Search Sourcevertexaisearch.cloud.google.com22Google Search Sourcevertexaisearch.cloud.google.com23Google Search Sourcevertexaisearch.cloud.google.com24Google Search Sourcevertexaisearch.cloud.google.com25Google Search Sourcevertexaisearch.cloud.google.com26Google Search Sourcevertexaisearch.cloud.google.com27Google Search Sourcevertexaisearch.cloud.google.com28Google Search Sourcevertexaisearch.cloud.google.com29Google Search Sourcevertexaisearch.cloud.google.com30Google Search Sourcevertexaisearch.cloud.google.com31Google Search Sourcevertexaisearch.cloud.google.com32Google Search Sourcevertexaisearch.cloud.google.com33Google Search Sourcevertexaisearch.cloud.google.com34Google Search Sourcevertexaisearch.cloud.google.com35Google Search Sourcevertexaisearch.cloud.google.com36Google Search Sourcevertexaisearch.cloud.google.com37Google Search Sourcevertexaisearch.cloud.google.com38Google Search Sourcevertexaisearch.cloud.google.com39Google Search Sourcevertexaisearch.cloud.google.com

Weekly AI Recap

Read this week's curated digest of top AI events →

AI-curated news aggregator. All content rights belong to original publishers.
Original source: The Next Web (TNW)

This is a summary, not the original. Read the source, or get the weekly briefing.

The weekly digest

One email a week. Unsubscribe anytime.