EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Researchers say AI is helping hackers break through encryption audits faster

2026-07-10 00:15:37
Bookmark

Encryption Security News

A single smart contract audit is no longer enough to ensure the security of decentralized protocols. This is the judgment of multiple blockchain security researchers, who believe that artificial intelligence tools are helping hackers discover smart contract vulnerabilities more quickly than current industry audit practices.

CertiK reported that the amount of stolen encryption protocols reached US$1.32 billion in the first half of 2026, and attackers are using increasingly sophisticated methods as industry security standards tighten. One pattern that emerged during this period was for attackers to revisit dormant codebases and detect smart contracts with closed protocols. CertiK said the attacks were likely aided by automated tools capable of scanning for potential vulnerabilities on a large scale.

Why old code becomes new target

On June 14, hackers used a smart contract vulnerability to steal $2.1 million from Aztec Connect, a protocol that has been closed since March 2023. The smart contract remained deployed on the chain after the service was shut down, leaving attackers with an unguarded entry point more than three years after the product was out of service. Five days later, a smart contract on the decentralized exchange mySwap was used and lost $300,000. The mySwap interface stopped accepting new liquid deposits more than six months before the attack.

In May, a different result emerged: a white-hat researcher with the pseudonym \"0xflorent\" recovered 1003 Ethereum (ETH) from a smart contract related to Hong Coin (HONG)\'s initial coin offering (ICO) dating back to 2016. The ICO failed to launch because it failed to meet its financing goals, and a loophole in the automatic contract refund function resulted in funds being locked up for nearly a decade. Researchers returned more than $1.72 million worth of ETH to 48 investors.

The Zcash (ZEC) network demonstrates how AI works in both directions. Shielded Labs security engineer Taylor Hornby used a custom audit agent built based on Anthropic\'s Claude Opus 4.8 to discover a critical vulnerability in Zcash\'s Orchard privacy pool, the core privacy feature. The vulnerability went undetected for four years and could allow undetectable counterfeiting in the pool. After Hornby identified it, the vulnerability has been fixed.

Why continuous review is now the standard

Ari Redbord, policy director at TRM Labs, said the data supports continuous review rather than a one-time audit. \"Attack technology is developing faster than a single audit can respond to from the day it is launched,\" he added, adding that audits designed based on last year\'s threat model cannot defend against attackers \'current methods.

A study conducted by Anthropic in December 2025 found that AI agents identified exploitable vulnerabilities worth $4.6 million in smart contracts. With more than $72.3 billion in crypto assets locked in hundreds of decentralized finance (DeFi) protocols, the economic incentive to find and exploit weak contracts is huge.

CertiK urges projects running legacy infrastructure to view re-audits as a recurring operating cost rather than a one-time step at the time of deployment. Redbord added that stronger code was only part of what was needed, and he also pointed to the broader challenge of combating North Korea\'s cyberattack and money laundering networks that divert stolen funds. \"Agreements can lock the door,\" he said,\"but someone has to go after the intruders. \"

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP