🌍The Next Web (TNW)•較早收集於 82m
AI 驅動的駭客攻擊導致 DeFi 協議損失數百萬美元

💡了解 AI 如何被用於 DeFi 駭客攻擊以繞過傳統安全防護,以及您必須採取哪些措施來保護您的程式碼。
⚡ 30-Second TL;DR
有什麼變化
攻擊者利用 AI 驅動的社交工程偽裝成交易公司,從 Drift Protocol 竊取了 2.85 億美元。
為什麼重要
AI 驅動的漏洞利用趨勢迫使 DeFi 開發者採用更嚴格的多重簽名安全機制與基於 AI 的異常檢測系統。此趨勢可能會增加去中心化金融應用的安全審計與保險成本。
下一步行動
在您的平台 API 端點上實施基於 AI 的行為監控,以檢測偏離標準用戶行為的異常交易模式。
誰應關注:Developers & AI Engineers
關鍵要點
- •攻擊者利用 AI 驅動的社交工程偽裝成交易公司,從 Drift Protocol 竊取了 2.85 億美元。
- •另一個組織利用了 Kelp DAO 中的單一驗證器漏洞,顯示出自動化漏洞掃描的趨勢。
- •DeFi 平台正難以針對 AI 驅動的對抗性策略實施防禦措施。
🧠 深度解析
Web-grounded analysis with 39 cited sources.
🔑 增強重點摘要
- •AI significantly lowers the cost and time required for vulnerability discovery, compressing the process from months to days or even hours, thereby expanding the attack surface for cybercriminals.
- •North Korean hackers are leveraging AI across the entire cyberattack lifecycle, from initial reconnaissance and target selection to crafting highly convincing phishing campaigns, assisting in malware development, and even streamlining money laundering processes.
- •AI-driven social engineering now includes hyper-realistic deepfakes, voice cloning, and personalized phishing messages that are increasingly difficult to distinguish from legitimate communications, enabling attacks at an unprecedented scale.
- •The Kelp DAO exploit was not a traditional smart contract vulnerability but rather a configuration flaw in its LayerZero cross-chain bridge, specifically a 1-of-1 Decentralized Verifier Network (DVN) setting, which AI tools could have identified.
- •Google has reported the first documented instance of cybercriminals successfully developing a zero-day exploit with AI, targeting an unnamed open-source, web-based IT admin tool.
🛠️ 技術深入
- Large Language Models (LLMs) are foundational to AI-powered attacks, enabling the generation of human-like text for social engineering and automated code analysis.
- AI tools can perform both static and dynamic analysis of smart contract code to identify vulnerabilities such as reentrancy or economic exploits, and utilize unsupervised machine learning for anomaly detection.
- Attackers leverage AI for prompt injection, model poisoning, and exploiting LLM APIs to extract data or trigger malicious actions.
- AI agents have demonstrated the capability to autonomously detect vulnerabilities, construct transaction sequences, and generate complete exploit scripts, as shown in research using models like GPT-5 and Claude Opus 4.5.
- AI-powered vulnerability scanning can reduce the average cost of scanning a smart contract to as low as $1.22.
- AI is employed for semantic code similarity analysis, dependency analysis, and cross-chain deployment detection to identify inherited vulnerabilities in forked protocols.
🔮 前景展望AI analysis grounded in cited sources
Regulatory bodies will mandate continuous, AI-aware audits for DeFi platforms and smart contracts.
The rapid evolution of AI-driven exploits necessitates proactive and continuous security assessments that can adapt to new AI-generated threats, pushing regulators to require more stringent, AI-integrated auditing processes.
The cost of vulnerability detection will trend towards zero, making it easier for even low-skill criminals to launch sophisticated attacks.
AI dramatically lowers the barrier to entry for cybercrime by automating complex tasks like vulnerability scanning and exploit generation, increasing the frequency and sophistication of attacks from a wider range of actors.
Defensive AI systems will increasingly be deployed to counter adversarial AI, leading to an 'AI vs. AI' cybersecurity arms race.
As attackers leverage AI for more sophisticated and scalable threats, defenders will need to adopt AI-powered threat detection, response automation, and continuous monitoring to keep pace and effectively protect digital assets.
⏳ 時間線
2016
North Korean-linked actors begin a decade of crypto theft, accumulating an estimated $6.75 billion by early 2026.
2023
Samsung employees inadvertently leak sensitive internal data by submitting it to ChatGPT, highlighting early AI-related data security risks.
2024-01
South Korea's intelligence agency reports North Korean hackers are using generative AI for cyberattacks and target identification.
2025-02
Bybit suffers a $1.46 billion breach, the largest single crypto hack in history, largely attributed to North Korean actors.
2026-04-01
Drift Protocol is exploited for $285 million through a months-long social engineering operation, suspected to involve North Korean actors.
2026-04-18
Kelp DAO is exploited for $292 million due to a single-verifier flaw in its LayerZero cross-chain bridge, attributed to North Korean hackers.
2026-05-11
Google reports the first instance of cybercriminals successfully developing a zero-day exploit with AI.
📎 來源 (39)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
- Google Search Source
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: The Next Web (TNW) ↗
