TechFlow Logo
Login/ Sign up
ETH Gas
Gwei
Fear
gas
$786 million stolen this year—DeFi’s security crisis shouldn’t be blamed on AI

$786 million stolen this year—DeFi’s security crisis shouldn’t be blamed on AI

2026.04.27
Share

TechFlow Selected TechFlow Selected

techFlow

$786 million stolen this year—DeFi’s security crisis shouldn’t be blamed on AI

Traditional finance veteran lashes out at DeFi: “Don’t use AI as an excuse—you’re simply doing a terrible job.”

2026.04.27 - 03:20:51
DeFiAI
Traditional finance veteran lashes out at DeFi: “Don’t use AI as an excuse—you’re simply doing a terrible job.”

Author: DLNews

Translation & Editing: TechFlow

TechFlow Intro: Cryptocurrency hacks have surged explosively this year—but the real threat isn’t code vulnerabilities; it’s people. From Bybit’s $1.5 billion breach to Drift’s $300 million loss, hackers have manipulated developers through social engineering—yet the industry is deflecting attention with “AI threat” narratives to mask its own failures in security practices. For investors and practitioners alike, this means even the most rigorous technical audits cannot guard against human weakness; project selection must prioritize team security awareness and process management.

Michael Pearl feels he’s being phished.

Michael Pearl, Strategic Vice President at cybersecurity firm Cyvers, told DL News that suspicious individuals approach him at cryptocurrency conferences, pitching implausible “too-good-to-be-true” stories.

“I’ve encountered this several times and suspected I was under a social engineering attack,” he said.

“Someone approaches you with an unbelievable story—saying they want to invest in your company or buy your product—and then sends you a highly suspicious link.”

Social engineering is a tactic used by cybercriminals to trick victims into clicking links embedded with malware. It’s a form of psychological manipulation designed to lower people’s guard. Often, it serves as the first step in digital attacks targeting crypto projects—and can originate from anywhere.

For example, the notorious North Korean hacking group Lazarus Group has a documented history of using fake job postings on LinkedIn to lure victims.

The February 2025 $1.5 billion Bybit hack, the January theft of $282 million from a cryptocurrency holder, and this month’s Drift Protocol attack—all began with social engineering.

And the situation is worsening. In October last year, crypto security firm Elliptic warned that social engineering attacks targeting crypto projects are on the rise—a growing concern among blockchain investigators and traders who’ve observed a sharp spike in cybercrime this year.

“The Primary Target”

A handful of headlines this year paint a grim picture.

The team behind Solana-based exchange Drift was approached at a conference by seemingly well-intentioned businesspeople—and shortly thereafter, the project lost nearly $300 million.

In early April, a hacker deceived HyperBridge, a crypto bridge, into creating uncollateralized tokens, minting $1.2 billion worth of counterfeit cryptocurrency out of thin air.

Days later, one of the industry’s most prominent billionaires—Justin Sun—publicly appealed to the North Korean hackers allegedly behind the Kelp DAO breach, urging them to come forward for negotiations.

Last year, hackers stole a record amount of cryptocurrency. According to DefiLlama data, over $2.5 billion was stolen. So far this year, criminals have stolen $786 million from crypto projects.

While decentralized finance (DeFi) protocols have drawn specific scrutiny, centralized systems—including Coinbase, the largest U.S. exchange—are actually the biggest targets.

Now, hackers have turned renewed attention to DeFi. This fast-moving, experimental sector—once infamous for vulnerabilities and widely believed to have matured—is back in the spotlight—for all the wrong reasons.

“Right now, DeFi appears to be the primary target,” Pearl said. “Overall, everything has shifted toward attacking humans—not systems.”

Attacking Humans

What’s driving this surge in thefts? Security experts point to humans as the core failure point.

“The initial intrusion point often begins with a person,” Matt Price, Vice President of Investigations at Elliptic, told DL News, adding that AI is helping bad actors refine their social engineering techniques.

The largest hack in cryptocurrency history—the $1.5 billion breach of crypto exchange Bybit—occurred after attackers impersonated trusted open-source contributors and convinced developers to install malicious software.

This year’s attacks unfolded similarly.

According to blockchain security firm Chainalysis, the Drift Protocol was targeted by hackers who had built rapport with the exchange’s team, posing as members of legitimate trading organizations.

They then tricked Drift employees into signing transactions they didn’t fully understand—handing over administrative control. The hackers walked away with nearly $300 million in assets.

Just an Excuse?

Since the proliferation of better, cheaper AI models, hackers have gained access to more sophisticated tools—and according to some, this has indeed helped.

This week, lawmakers grilled cybersecurity experts during a joint hearing held by the House Subcommittee on Border Security and Enforcement and the Subcommittee on Cybersecurity and Infrastructure Protection. A consensus emerged: hackers are operating more efficiently, leveraging previously inaccessible AI tools to accelerate their work.

Last month, security experts told DL News that cybercriminals are increasingly using AI to scan DeFi protocols for vulnerabilities—and exploit bugs that auditors may have missed.

Others remain skeptical—and argue the AI narrative is merely serving as an excuse.

“The story DeFi is trying to tell is, ‘We’re facing an unimaginable threat—AI—that will find the tiniest, most obscure vulnerabilities,’” said David Schwed, COO of SVRN and a veteran cybersecurity professional in the industry.

“But that’s not true. The reality is: you built something extremely flawed and insecure—and [hackers] are simply finding it faster.”

Schwed, who previously led digital asset product development at BNY Mellon, added that unless DeFi projects begin thinking like traditional financial institutions—putting security first—hacks will continue to occur.

Join TechFlow official community to stay tuned

Add to Favorites
Share to Social Media

Related Articles

2026.07.27

Nomura Research Report Analysis: CXMT Surges 471% on First-Day Opening, AI Storage Shortage Continues Until 2030, Target Price 116 Yuan

ChangXin, as the world's fourth-largest DRAM manufacturer, is currently at an inflection point for explosive capacity expansion and domestic substitution.

Nomura Research Report Analysis: CXMT Surges 471% on First-Day Opening, AI Storage Shortage Continues Until 2030, Target Price 116 Yuan
2026.07.27

Google's Most Profitable Quarterly Report in History: Behind Billions in Profit, the AI Arms Race Has Burned Into Negative Cash Flow

While closed-source large models are still lobbying the government in Washington to ban open source, the real moat has long ceased to be at the model layer.

Google's Most Profitable Quarterly Report in History: Behind Billions in Profit, the AI Arms Race Has Burned Into Negative Cash Flow
2026.07.24

Podcast Notes | Jensen Huang's Latest Interview: Chip Industry Needs to Expand Another 5 to 10 Times, Chinese Models Benefit Everyone

China has more AI researchers than the rest of the world combined. It is destined that China will become extraordinary in this field.

Podcast Notes | Jensen Huang's Latest Interview: Chip Industry Needs to Expand Another 5 to 10 Times, Chinese Models Benefit Everyone
2026.07.24

AI has finished writing the code for you, but no one is willing to take a serious look at it anymore.

Major tech companies are building their own tools to cope, but mature solutions remain in the experimental stage.

AI has finished writing the code for you, but no one is willing to take a serious look at it anymore.
2026.07.24

Selling Tools or Selling Results? AI Companies Are Heading Toward Two Completely Different Futures

Hand over what can be automated to AI, and use humans as a fallback for the rest.

Selling Tools or Selling Results? AI Companies Are Heading Toward Two Completely Different Futures
2026.07.24

Retail Investor Bonuses Fade, Prediction Markets Enter AI Arms Race

July Fed rate decision night, a "quant shadow war" over pricing power.

Retail Investor Bonuses Fade, Prediction Markets Enter AI Arms Race
2026.07.23

AI is transitioning from a "tool" that helps you work to a "labor market" that generates income for you.

Every major technological revolution gives rise to a new generation of entrepreneurs.

AI is transitioning from a "tool" that helps you work to a "labor market" that generates income for you.
2026.07.23

Goldman Sachs Research Report Analysis: Momentum Unwinding Shocks Global Stock Markets, AI Spending Boom Conceals Hidden Risks

Before the efficiency gains from AI technology implementation are truly reflected in corporate profits, if the marginal return rate on capital expenditure declines first, tech stock valuations will come under dual pressure.

Goldman Sachs Research Report Analysis: Momentum Unwinding Shocks Global Stock Markets, AI Spending Boom Conceals Hidden Risks
2026.07.23

AI Impersonating Human Writing Is Polluting the Internet, Substack Decides to Hand Judgment Over to Readers

One scan tells you whether the article is human-written or machine-written.

AI Impersonating Human Writing Is Polluting the Internet, Substack Decides to Hand Judgment Over to Readers
2026.07.23

A Brief History of AI Victories: Wherever There Is a Rating System, There Is AI Invasion

When a field establishes scoring criteria, it sets a countdown for its own conquest.

A Brief History of AI Victories: Wherever There Is a Rating System, There Is AI Invasion
TechFlow Logo

Navigating Web3 tides with focused insights

Contribute An Articleemail
Media Requestsmsg

Risk Disclosure: This website's content is not investment advice and offers no trading guidance or related services. Per regulations from the PBOC and other authorities, users must be aware of virtual currency risks. Contact us / [email protected] ICP License: 琼ICP备2022009338号