It Turns Out the First Real-World Application of AI x Crypto is in Security Auditing

marsbit发布于2026-06-26更新于2026-06-26

文章摘要

The article explores the surprising trend where AI's first major impact on crypto has been in security auditing, not in areas like trading or analytics. It details how AI-powered tools are dramatically lowering the barrier to finding smart contract vulnerabilities, enabling attackers to scan thousands of contracts and execute exploits within minutes. This has rendered traditional, manually-produced audit reports with their month-long validity periods increasingly obsolete, creating a critical "structural crack" in the old security model. Cases like Drift Protocol and KelpDAO show that even extensively audited protocols can be hacked through social engineering, operational flaws, or infrastructure misconfigurations beyond pure code review. Attackers are also using AI to find and exploit vulnerabilities in years-old, deployed contracts. Notably, OpenZeppelin's co-founder has expressed a grim view that "all DeFi is insecure" due to AI's asymmetric advantage. In response, the audit industry is undergoing a fundamental shift. While there's a short-term spike in defensive re-audits, the long-term business model is changing. Firms are developing AI-assisted systems and moving from one-time report deliveries towards embedded, continuous services like real-time monitoring and formal verification. Examples include AI tools uncovering critical, previously missed vulnerabilities in heavily audited protocols like Curve Finance and Zcash. The conclusion is that security must become a con...

Data shows that as of June, DeFi TVL has dropped from about $115 billion at the beginning of the year to approximately $70 billion, a decline of 39%, decreasing almost every month.

Simultaneously, security incidents have brought another layer of pressure to DeFi. According to statistics, since 2026, there have been 121 hacker attacks in the DeFi sector, resulting in cumulative losses of about $942 million. Among these, 85 incidents occurred in the second quarter alone, causing losses of $775 million, making it the quarter with the most frequent attacks during that statistical period.

With the proliferation of next-generation AI tools, the cost and skill requirements for finding smart contract vulnerabilities have significantly decreased, forcing security audit firms to stand at the center of this transformation.

I. The AI-ization of Attack Vectors, Old Security Defenses Are Failing

The Collapse of the Old Logic

When the industry discusses the impact of AI on the crypto field, the first reactions are often about quantitative trading, robo-advisors, or on-chain data analysis. But reality has taken an unexpected turn: the first area that AI has fundamentally penetrated is the business originally considered the most stable in this industry—security auditing.

Two or three years ago, security audit companies were seen by investment institutions as conservative bets to participate in the crypto industry's growth. The logic was straightforward: as long as new protocols launched, audits were needed; the more prosperous the industry, the higher the audit demand; high per-client revenue, stable income, independent of token price fluctuations.

Immunefi data shows that DeFi protocol losses due to hacker attacks had dropped 74% from their 2022 peak of $2.62 billion to approximately $680 million in 2025. Cross-chain bridge attacks' share of total DeFi losses significantly decreased from 73% in 2022 to 3% in 2025. The industry generally believed that the ongoing maturity of security audits was playing a role.

However, this judgment is gradually being proven wrong.

On June 9th, Anthropic released its next-generation AI model, Claude Mythos. A viewpoint subsequently emerged in the market: the abnormal recent increase in the frequency of attacks on leading protocols may be linked to the continuous leap in the capabilities of cutting-edge AI models.

Simon Dedic, founder of Moonrock Capital, pointed out that with the proliferation of next-generation AI tools, the cost and skill requirements for finding smart contract vulnerabilities will drop to essentially zero. Protocols without audits will become targets, and known vulnerabilities will be repeatedly exploited.

Chainalysis data confirms this trend: In the past six months, attacks targeting only contracts with unverified source code have caused approximately $36.7 million in losses. Attackers use AI-assisted decompilation of raw bytecode to find vulnerabilities, and large language models can now identify vulnerability patterns at scale, systematically scanning thousands of contracts, including Truebit, Aperture Finance, Ekubo, and others.

The entire process from discovery to execution by attackers is being compressed to the minute level. The validity period of traditional audit reports is measured in months. This time gap is the most fatal structural crack in the old audit model.

Audited, Still Hacked?

The main targets of hacker attacks are no longer second or third-tier small protocols. Drift Protocol is a leading perpetuals platform on Solana, its smart contracts having undergone multiple rounds of audits by several well-known security firms. However, an investigation by security firm TRM Labs revealed that the attacker used a six-month-long social engineering attack to gradually infiltrate Drift team members, ultimately obtaining privileged admin keys.

A similar situation occurred with KelpDAO. The attacker exploited a vulnerability in the single-validator-node configuration of the LayerZero cross-chain bridge to forge deposits and mint uncollateralized tokens, stealing $293 million within 46 minutes. It was later determined that a multi-validator-node configuration had been recommended previously but was not adopted. The contract passed the audit, but a flaw in the infrastructure configuration still led to the loss.

In those audited protocols, while code correctness was covered, attackers bypassed them through business logic and operational processes.

On the other hand, AI's scanning scope isn't limited to new protocols. Web3 security company GoPlus Security points out that attackers are using AI technology to extensively mine vulnerabilities in historical contracts deployed years ago. On June 9th, a 7-year-old Ethereum contract, Token of Power, was attacked, losing about $1.5 million; on May 25th, a 3-year-old WUSD.fi contract was attacked, losing about $200,000; an old contract deployed 2 years ago for Aztec Network was attacked twice on June 14th and 18th, with combined losses exceeding $4 million. This suggests that the protective validity period of old audit reports may have already reached zero.

Just last month, Manuel Aráoz, co-founder of crypto security company OpenZeppelin, stated that he now believes "all DeFi is insecure" and has advised friends and family to exit all DeFi positions, including those in Aave, MakerDAO, and Compound. His reasoning is that AI programming agents' ability to find vulnerabilities has reached superhuman levels, while the structure of smart contract security is extremely asymmetric—defenders must patch every vulnerability, while attackers only need to find one effective entry point.

OpenZeppelin has provided audit services for Aave, Compound, Uniswap, Coinbase, and is one of the most important smart contract security infrastructure providers in the crypto industry. Such a statement carries unusual weight coming from him.

However, there is market debate on this. Aave ecosystem contributor Marc Zeller mentioned that in the past year, less than 10% of DeFi losses stemmed from code vulnerabilities, with the rest coming from misconfigured risk parameters, improper collateral management, and weak operational security. 0G Labs CEO Michael Heinrich also pointed out that DeFi lending security has improved by about 98% compared to the 2020 baseline.

The current issue is that the scope covered by code audits is becoming increasingly limited, while attackers' attack surface continues to expand. The old security framework can no longer provide a convincing answer.

II. Responses and Restructuring by Projects and Audit Firms

Although old audit standards show obvious cracks in the face of AI attacks, this does not mean audit demand will disappear. On the contrary, both project teams and audit companies will adjust according to the new reality.

Short-term: Centralized Release of Defensive Audit Demand

Many leading protocols that have already undergone audits are now under pressure to be re-audited according to new security standards of the AI era. Project teams are beginning to realize that with the continuous improvement of AI attack capabilities, the protection cycle of traditional audits is shortening.

The nature of this demand is defensive spending, not a signal of healthy industry growth. Security firm CertiK noted in its 2026 regulatory report that smart contract security audits are upgrading from an industry best practice to a regulatory entry requirement, becoming a necessary threshold for license approval and token listings.

In the short term, this defensive spending will generate some audit demand, but it is more of a passive investment by projects to reduce risk.

Long-term: Fundamental Divergence in Audit Companies' Business Models

Audit firms are also feeling the pressure. As attack-side AI tools continue to evolve, leading companies are accelerating the development of their own detection capabilities. Several major audit firms have launched AI-assisted audit systems between 2025 and 2026, using multi-model parallel analysis and automated detection to improve efficiency.

While efficiency improves, the traditional model faces compression. The commercial value of delivering a one-time audit report is declining. In the long run, firms relying on point-to-point reports face the risk of shrinking business volume.

JPMorgan analysts explicitly stated that persistent DeFi security incidents are limiting the entry of major institutional investors. This is not just about market sentiment; it is a public challenge to the very existence value of the entire audit industry.

The smart contract audit platform Code4rena, known for its competitive audit model, recently announced its shutdown, with client and researcher resources transferred to Immunefi. This platform had raised $6 million from Paradigm in 2023 and was once seen as a strong complement to the traditional audit model, ceasing operations less than two years after being acquired.

Image Source: RootData

The DeFi lending protocol Radiant, after experiencing a hacker attack in October 2024, announced its entry into a shutdown phase after 18 months of unsuccessful efforts to recover funds. Ionic Protocol also announced an immediate halt to all operations due to the expanding impact of a security vulnerability.

However, change is not unidirectional. AI also demonstrates superhuman capabilities on the defense side—the question is who uses it first.

AI-native audit tool Firepan disclosed that during an independent audit of Curve Finance's new AMM contract in April 2026, it discovered a critical combinatorial vulnerability: each attribute alone was normal code, but under a specific combination of operations, an attacker could bypass the donation protection mechanism and withdraw funds.

Curve had previously undergone multiple rounds of review by six independent audit firms and is considered one of the most heavily audited protocols in DeFi, yet this vulnerability remained hidden in the blind spot of manual audits.

Curve Finance founder Michael Egorov later commented that AI is indeed helpful for smart contract security. However, he also noted that AI's success in detecting vulnerabilities in browsers and the Linux kernel cannot be directly applied to smart contracts—smart contracts are usually only a few thousand lines of code, which humans and conventional AI can fully reason about. The real risks to be wary of come more from OpSec-level key leaks and supply chain attacks, rather than the code vulnerabilities themselves.

A similar case has emerged in the privacy coin space. Security engineer Taylor Hornby, commissioned by the non-profit Shielded Labs, used the Anthropic Opus 4.8 model to audit the Zcash protocol and discovered a critical vulnerability in the Zcash Orchard privacy pool that had gone undetected since 2022. Theoretically, it could allow an attacker to mint unlimited counterfeit ZEC that cannot be detected on-chain.

Zcash founder Zooko Wilcox publicly thanked Anthropic afterwards. Hornby also stated that he has added Monero (XMR) to the audit queue and will conduct security reviews on more privacy coin projects in the future.

It is reported that OpenZeppelin has launched the Skills system, providing AI programming agents with authoritative knowledge from its audited smart contract libraries, moving the defense line forward to the development stage.

This is the new direction traditional audit firms are forced to take—transitioning from post-hoc review to full-process embedding, from one-time delivery to continuous monitoring, formal verification, and real-time on-chain risk detection.

Conclusion

Overall, the security audit sector is transitioning from a growth model to a competitive one. AI accelerates both attack efficiency and defense system upgrades. This process not only affects the commercial form of audit companies but also requires the entire DeFi ecosystem to rethink how it approaches security investment.

For project teams, the era of "one audit, security for life" is over. Security is no longer just a pre-launch formality but an infrastructure requiring continuous investment.

For audit firms, passively keeping up with AI is no longer sufficient. Players that can more quickly complete a comprehensive restructuring from tools to service models are more likely to remain at the table in the next phase.

相关问答

QAccording to the article, what unexpected application of AI is first making a significant impact in the cryptocurrency space?

AThe article states that the first major and unexpected impact of AI in the crypto space is on security auditing, as AI tools drastically lower the cost and skill required to find vulnerabilities in smart contracts.

QWhat are the two main reasons why the old security audit model is becoming ineffective according to the analysis?

AThe two main reasons are: 1) Attackers using AI tools can now find and exploit vulnerabilities in minutes, while traditional audit reports are only valid for months, creating a critical structural gap. 2) AI can systematically scan and find vulnerabilities in even older, previously audited contracts, making old audit reports effectively obsolete.

QThe article mentions that even audited top protocols can be hacked. What are some examples of vulnerabilities that bypassed code-focused audits?

AExamples include social engineering attacks (e.g., Drift Protocol attackers infiltrating the team over 6 months to steal admin keys), infrastructure configuration flaws (e.g., KelpDAO's single validator node setup for a bridge), and attacks on historical contracts that were not actively monitored for years-old vulnerabilities.

QHow is the business model of security audit companies expected to change in the long term due to AI's influence?

AAudit companies are shifting from a model of delivering one-time reports to a model focused on continuous, embedded security. This includes offering real-time monitoring, formal verification, and chain-based risk detection, moving from a point-in-time service to a continuous service.

QWhat were two key vulnerabilities discovered in major protocols (Curve Finance and Zcash) using AI audit tools, as mentioned in the article?

A1) In Curve Finance's new AMM contract, AI discovered a combinatorial flaw where specific operation combinations could bypass donation protection and drain funds. 2) In Zcash's Orchard privacy pool, AI found a critical vulnerability, undetected since 2022, that theoretically allowed unlimited, undetectable minting of fake ZEC tokens.

你可能也喜欢

老登股估值大溃败,一代资产的估值坐标系之死

《老登股估值大溃败:一代资产的估值坐标系之死》一文剖析了中国与美国科技巨头面临的共同估值困境。文章指出,以阿里巴巴、腾讯为代表的中国互联网公司经历了估值体系的系统性崩塌。曾经的“美国对标打折”模型已失效,地缘政治、监管变化及资金撤离导致其估值持续压缩。 与此同时,美国科技“七巨头”如微软同样陷入困境。尽管基本面稳健,但市场担忧其巨额AI资本开支侵蚀自由现金流,且旧有高利润率商业模式面临AI时代按消耗计费模式的颠覆性挑战。中美这些昔日的平台巨头,如今均被视为需要证明自己不被未来淘汰的“老登股”。 文章以日本资产泡沫破裂后的长期低迷为参照,指出旧估值框架(如“日本统治全球”或“中美深度融合”)破灭后,新框架的建立往往需要漫长的时间。日本经历了约25年的估值真空,直到巴菲特以“低估值+高股息+治理改革”的新逻辑为其重新定价。 当前,中国互联网头部公司虽仍盈利,但正处于类似的“旧框架已死,新框架未生”的真空期。潜在的“新估值语言”可能来自向AI基础设施的成功转型,或通过持续回购与分红构建价值底线,但这两种路径都伴随着巨大不确定性。文章认为,这场估值体系的重塑过程可能远比市场预期的更为漫长。

marsbit17分钟前

老登股估值大溃败,一代资产的估值坐标系之死

marsbit17分钟前

STRC 大幅折价、mNAV 跌破盈亏线,Strategy 估值逻辑已被改写

近日,MSTR与STRC行情出现大幅波动,比特币储备企业的商业模式更接近银行,而非软件科技公司,应采用银行估值逻辑。核心指标为市净率(mNAV),即企业市值除以权益净资产值。当前Strategy的mNAV为1.10倍,其每股净比特币价值代表股东实际拥有的比特币数量。 若以当前股价增发10亿美元股权,资金用途有四种方案:加仓比特币、回购STRC、扩充现金储备、或两者各半。分析显示,加仓比特币对改善每股净比特币价值效果最弱,因其以溢价发行股票购买平价资产,反而稀释了市场关注的总比特币持仓指标。相比之下,折价回购STRC能立即创造价值,提升每股净比特币,降低债务占比,并优化资产负债表。同时,扩充现金储备可大幅提升分红现金覆盖月数,增强企业流动性安全。 当前STRC大幅折价,现金储备覆盖分红不足10个月,企业原有扩张假设已失效。在此估值区间,继续加仓比特币仅优化表层指标,却忽视了优先级债务高企、融资渠道收紧的核心风险。通过回购STRC或扩充现金储备,可修复资产负债表,提振STRC价格,从而降低分红收益率,重新打通面值增发渠道。 因此,对比特币储备企业的评估应聚焦银行式指标:市净率、每股账面价值及债务偿付能力。在当前环境下,优化财务结构比单纯增持比特币更为关键。

Foresight News19分钟前

STRC 大幅折价、mNAV 跌破盈亏线,Strategy 估值逻辑已被改写

Foresight News19分钟前

Collector Crypt晋升链上“印钞机”:日活不足千人,巨鲸撑起97%收入

近期,TCG项目Collector Crypt凭借强劲的盈利能力冲入全网协议收入榜前十,并一度登顶Solana收入最高协议,成为市场焦点。它将收藏和抽卡玩法搬到链上,推动了代币化TCG赛道的增长。 链上TCG市场在2026年6月交易额突破4.9亿美元,同比增长超7倍,月活用户约5300人。其表现已超过同期的NFT市场,这得益于实体卡牌的价值支撑、游戏属性和链上流动性。Solana凭借先发优势和Collector Crypt等应用,占据了该市场超80%的份额。 Collector Crypt在该赛道占据统治地位,其近一周交易额占市场总额的74.3%,单周协议收入约520万美元。然而,其收入高度集中于少数“巨鲸”用户:仅占用户总数14.6%的高消费用户,贡献了平台约97.1%的收入。同时,平台毛利率持续走低,收入留存率也偏低。 推动其增长的核心是链上扭蛋(Gacha)机制,它刺激了用户的重复消费。宝可梦IP是主要流量来源,占平台代币化收藏品价值的73.8%。其原生代币CARDS通过回购机制和空投激励,构建了增长飞轮,年内涨幅显著。但需注意,代币将持续解锁,可能带来市场抛压。 总体而言,Collector Crypt验证了链上TCG商业模式的潜力,但该赛道仍处早期,在用户拓展和降低对巨鲸依赖等方面面临挑战。

marsbit39分钟前

Collector Crypt晋升链上“印钞机”:日活不足千人,巨鲸撑起97%收入

marsbit39分钟前

交易

现货
活动图片