AI DeFi Hack Fears Ease, but Agentic Threat Looms
Decentralized finance is unusually exposed to cyberattacks because its code is public, transactions settle quickly and stolen funds can be difficult to recover. OpenZeppelin founder Manuel Aráoz has warned that “all of DeFi” is unsafe as AI coding agents improve at finding smart-contract flaws. Dragonfly managing partner Haseeb Qureshi has pushed back, arguing that evidence of an AI-driven “hackpocalypse” remains limited and that established protocols have strengthened their defenses.
A Cointelegraph report published July 23 said CertiK recorded $1.32 billion in crypto-hack losses in the first half of 2026, down 46.8% from a year earlier. The median exploit fell below $500,000 from more than $2 million in 2025, even as incident counts rose. Security specialists said private-key compromises and human mistakes still drive much of the damage, but warned that increasingly autonomous Agentic AI could scan code, automate attacks and scale social engineering faster, raising the longer-term threat.
All Coverage
1 original reportsThe Backstory
The history behind this eventOpenZeppelin Co-Founder Warns AI Threats Are Making DeFi Smart-Contract Flaws Impossible to Contain
OpenZeppelin provides smart-contract libraries and security audits widely used across DeFi and has served protocols including Aave, Compound and MakerDAO. Co-founder and former chief technology officer Manuel Aráoz left the company in 2019. His warning carries weight because onchain code is public and funds move instantly: defenders must close every vulnerability, while an attacker needs to find only one.
On May 26, 2026, Aráoz said on X that AI coding agents had surpassed humans in their ability to find vulnerabilities, and advised friends and family to exit all DeFi positions, including Aave, MakerDAO and Compound. DeFi exploits caused nearly $630 million in losses in April, with the Drift and Kelp DAO incidents accounting for about $285 million and $293 million, respectively. Total value locked has fallen about 14% since mid-April.
AI Agents’ DeFi Exploit Replication Rate Rises to 70% With Structured Knowledge, a16z Crypto Says
Decentralized finance protocols are often exploited through weaknesses involving oracle design, insufficient liquidity or price manipulation. An a16z Crypto study examined whether AI agents could automatically replicate such exploits. It found that their attack capabilities depend heavily on access to structured knowledge, including historical attack paths and vulnerability patterns, carrying direct implications for protocol security defenses.
According to the a16z Crypto report, AI agents without structured knowledge replicated DeFi price-manipulation exploits at a success rate of just 10%. Adding historical cases and attack patterns raised the rate to 70%, an increase of 60 percentage points and seven times the original level. Available information did not disclose the report’s publication date, test sample size or amounts involved, leaving the figures subject to verification through the full study.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.