來源較早收集於 82m

AI 驅動的駭客攻擊導致 DeFi 協議損失數百萬美元

閱讀原文: The Next Web (TNW)
#cybersecurity#defi#social-engineering#threat-intelligence

了解 AI 如何被用於 DeFi 駭客攻擊以繞過傳統安全防護,以及您必須採取哪些措施來保護您的程式碼。

30 秒速覽

有什麼變化

攻擊者利用 AI 驅動的社交工程偽裝成交易公司,從 Drift Protocol 竊取了 2.85 億美元。

為什麼重要

AI 驅動的漏洞利用趨勢迫使 DeFi 開發者採用更嚴格的多重簽名安全機制與基於 AI 的異常檢測系統。此趨勢可能會增加去中心化金融應用的安全審計與保險成本。

下一步行動

在您的平台 API 端點上實施基於 AI 的行為監控,以檢測偏離標準用戶行為的異常交易模式。

誰應關注:Developers & AI Engineers

關鍵要點

  • 攻擊者利用 AI 驅動的社交工程偽裝成交易公司,從 Drift Protocol 竊取了 2.85 億美元。
  • 另一個組織利用了 Kelp DAO 中的單一驗證器漏洞,顯示出自動化漏洞掃描的趨勢。
  • DeFi 平台正難以針對 AI 驅動的對抗性策略實施防禦措施。

深度解析

背景與延伸:來自公開資料,非原文內容。引用 39 個來源。

增強重點摘要

  • AI significantly lowers the cost and time required for vulnerability discovery, compressing the process from months to days or even hours, thereby expanding the attack surface for cybercriminals.
  • North Korean hackers are leveraging AI across the entire cyberattack lifecycle, from initial reconnaissance and target selection to crafting highly convincing phishing campaigns, assisting in malware development, and even streamlining money laundering processes.
  • AI-driven social engineering now includes hyper-realistic deepfakes, voice cloning, and personalized phishing messages that are increasingly difficult to distinguish from legitimate communications, enabling attacks at an unprecedented scale.
  • The Kelp DAO exploit was not a traditional smart contract vulnerability but rather a configuration flaw in its LayerZero cross-chain bridge, specifically a 1-of-1 Decentralized Verifier Network (DVN) setting, which AI tools could have identified.
  • Google has reported the first documented instance of cybercriminals successfully developing a zero-day exploit with AI, targeting an unnamed open-source, web-based IT admin tool.

技術深入

  • Large Language Models (LLMs) are foundational to AI-powered attacks, enabling the generation of human-like text for social engineering and automated code analysis.
  • AI tools can perform both static and dynamic analysis of smart contract code to identify vulnerabilities such as reentrancy or economic exploits, and utilize unsupervised machine learning for anomaly detection.
  • Attackers leverage AI for prompt injection, model poisoning, and exploiting LLM APIs to extract data or trigger malicious actions.
  • AI agents have demonstrated the capability to autonomously detect vulnerabilities, construct transaction sequences, and generate complete exploit scripts, as shown in research using models like GPT-5 and Claude Opus 4.5.
  • AI-powered vulnerability scanning can reduce the average cost of scanning a smart contract to as low as $1.22.
  • AI is employed for semantic code similarity analysis, dependency analysis, and cross-chain deployment detection to identify inherited vulnerabilities in forked protocols.

前景展望基於引用來源的 AI 分析

Regulatory bodies will mandate continuous, AI-aware audits for DeFi platforms and smart contracts.
The rapid evolution of AI-driven exploits necessitates proactive and continuous security assessments that can adapt to new AI-generated threats, pushing regulators to require more stringent, AI-integrated auditing processes.
The cost of vulnerability detection will trend towards zero, making it easier for even low-skill criminals to launch sophisticated attacks.
AI dramatically lowers the barrier to entry for cybercrime by automating complex tasks like vulnerability scanning and exploit generation, increasing the frequency and sophistication of attacks from a wider range of actors.
Defensive AI systems will increasingly be deployed to counter adversarial AI, leading to an 'AI vs. AI' cybersecurity arms race.
As attackers leverage AI for more sophisticated and scalable threats, defenders will need to adopt AI-powered threat detection, response automation, and continuous monitoring to keep pace and effectively protect digital assets.

時間線

2016
North Korean-linked actors begin a decade of crypto theft, accumulating an estimated $6.75 billion by early 2026.
2023
Samsung employees inadvertently leak sensitive internal data by submitting it to ChatGPT, highlighting early AI-related data security risks.
2024-01
South Korea's intelligence agency reports North Korean hackers are using generative AI for cyberattacks and target identification.
2025-02
Bybit suffers a $1.46 billion breach, the largest single crypto hack in history, largely attributed to North Korean actors.
2026-04-01
Drift Protocol is exploited for $285 million through a months-long social engineering operation, suspected to involve North Korean actors.
2026-04-18
Kelp DAO is exploited for $292 million due to a single-verifier flaw in its LayerZero cross-chain bridge, attributed to North Korean hackers.
2026-05-11
Google reports the first instance of cybercriminals successfully developing a zero-day exploit with AI.

來源 (39)

Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.

1Google Search Sourcevertexaisearch.cloud.google.com2Google Search Sourcevertexaisearch.cloud.google.com3Google Search Sourcevertexaisearch.cloud.google.com4Google Search Sourcevertexaisearch.cloud.google.com5Google Search Sourcevertexaisearch.cloud.google.com6Google Search Sourcevertexaisearch.cloud.google.com7Google Search Sourcevertexaisearch.cloud.google.com8Google Search Sourcevertexaisearch.cloud.google.com9Google Search Sourcevertexaisearch.cloud.google.com10Google Search Sourcevertexaisearch.cloud.google.com11Google Search Sourcevertexaisearch.cloud.google.com12Google Search Sourcevertexaisearch.cloud.google.com13Google Search Sourcevertexaisearch.cloud.google.com14Google Search Sourcevertexaisearch.cloud.google.com15Google Search Sourcevertexaisearch.cloud.google.com16Google Search Sourcevertexaisearch.cloud.google.com17Google Search Sourcevertexaisearch.cloud.google.com18Google Search Sourcevertexaisearch.cloud.google.com19Google Search Sourcevertexaisearch.cloud.google.com20Google Search Sourcevertexaisearch.cloud.google.com21Google Search Sourcevertexaisearch.cloud.google.com22Google Search Sourcevertexaisearch.cloud.google.com23Google Search Sourcevertexaisearch.cloud.google.com24Google Search Sourcevertexaisearch.cloud.google.com25Google Search Sourcevertexaisearch.cloud.google.com26Google Search Sourcevertexaisearch.cloud.google.com27Google Search Sourcevertexaisearch.cloud.google.com28Google Search Sourcevertexaisearch.cloud.google.com29Google Search Sourcevertexaisearch.cloud.google.com30Google Search Sourcevertexaisearch.cloud.google.com31Google Search Sourcevertexaisearch.cloud.google.com32Google Search Sourcevertexaisearch.cloud.google.com33Google Search Sourcevertexaisearch.cloud.google.com34Google Search Sourcevertexaisearch.cloud.google.com35Google Search Sourcevertexaisearch.cloud.google.com36Google Search Sourcevertexaisearch.cloud.google.com37Google Search Sourcevertexaisearch.cloud.google.com38Google Search Sourcevertexaisearch.cloud.google.com39Google Search Sourcevertexaisearch.cloud.google.com

AI 週報

閱讀本週精選 AI 大事摘要 →

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: The Next Web (TNW)

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週電子報

每週一封,可隨時退訂。