← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] Q1 DeFi Exploits Hit $138M as AI Code Enters Threat Model

Zephyra|March 25, 2026|BPF
EXECUTIVE SUMMARY

DeFi protocols lost at least $138.35 million across 15 documented exploits in Q1 2026, according to tracker data aggregated by Cryptopolitan and CryptoAdventure, exceeding Q1 2025 losses of $106.8 million by 29.5%. The quarter's damage was concentrated in four incidents: Step Finance ($27.3 milli...

"Claude Opus 4.6 wrote vulnerable code, leading to a smart contract exploit with a $1.78 million loss. Is this the first hack of vibe-coded Solidity code?" — Pashov, Smart Contract Security Auditor

Executive Summary

DeFi protocols lost at least $138.35 million across 15 documented exploits in Q1 2026, according to tracker data aggregated by Cryptopolitan and CryptoAdventure, exceeding Q1 2025 losses of $106.8 million by 29.5%. The quarter's damage was concentrated in four incidents: Step Finance ($27.3 million), Truebit ($26.2 million), Resolv ($25 million), and SwapNet ($13.4 million). Private key compromise, not smart contract logic errors, was the dominant attack vector.

A new variable entered the threat model. In February, the Moonwell lending protocol lost $1.78 million after an oracle misconfiguration linked to AI-generated code — what security researchers have termed "vibe coding." Pull request 578 on the Moonwell repository was co-authored by Claude Opus 4.6, an AI coding assistant, and contained a pricing formula error that went undetected through governance and deployment. The incident coincided with a Tenzai study that found 69 vulnerabilities across 15 applications built with five major AI coding agents. OpenAI responded by launching EVMbench, a smart contract security benchmark, with $10 million in API credits for defensive research. The quarter illustrates a structural tension: DeFi's $105 billion in TVL is protected by audit infrastructure that demonstrably fails to catch deployed vulnerabilities, while a new generation of AI-assisted code introduces error patterns that existing review processes were not designed to detect.

Table of Contents

  1. Q1 2026 Exploit Ledger: The Numbers
  2. Anatomy of the Big Four
  3. The Vibe Coding Problem
  4. The Audit Paradox
  5. OpenAI's EVMbench and the AI Security Arms Race
  6. Economic Value Analysis: Who Bears the Cost
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

Q1 2026 Exploit Ledger: The Numbers

PeckShield data records $112.53 million in crypto hack losses across January and February 2026 alone. Adding March incidents — including the $25 million Resolv exploit on March 22, the $128 million Balancer exploit aftermath, and additional smaller incidents — the Q1 DeFi-specific tally exceeds $138 million.

Monthly breakdown (protocol hacks only):

| Month | Incidents | Total Losses | Largest Single Incident | |-------|-----------|-------------|------------------------| | January 2026 | 16 | $86.01M | Step Finance ($27.3M) | | February 2026 | 15 | $26.52M | YieldBlox DAO ($10M) | | March 2026 (through 3/23) | ~5 | $25M+ | Resolv ($25M) | | Q1 Total | ~36 | $138.35M+ | Step Finance ($27.3M) |

For context, January 2026's combined crypto theft — including social engineering and phishing — reached approximately $370 million, according to CertiK. A single phishing victim lost $284 million, representing over 80% of the month's social engineering total. Protocol hacks accounted for just 23% of January's total theft.

February saw a 69.2% decline from January and a 98.2% year-on-year decrease compared with February 2025, when the $1.4 billion Bybit exploit dominated the figures.

Attack vector distribution across Q1 2026 incidents:

  • Private key compromise: 4 incidents (~$60M)
  • Smart contract logic errors: 5 incidents (~$40M)
  • Oracle misconfiguration: 3 incidents (~$12M)
  • Arbitrary call / approval exploitation: 2 incidents (~$17M)
  • Minting vulnerability: 2 incidents (~$27M)

Anatomy of the Big Four

Step Finance — $27.3 Million (January 31)

The Solana-based portfolio tracker suffered the quarter's largest single loss when attackers gained access to executive team devices, compromising private keys controlling treasury wallets. The attackers unstaked 261,854 SOL before transferring funds — a pattern consistent with key compromise rather than protocol-level exploitation. Step Finance announced permanent closure on February 24. The STEP token lost 96% of its value. Affiliate projects SolanaFloor and Remora Markets also shut down.

Root cause: Device compromise leading to private key exfiltration. No smart contract vulnerability was involved.

Truebit — $26.2 Million (January 9)

The first DeFi hack of 2026 targeted a five-year-old closed-source smart contract within the Truebit ecosystem. The attacker exploited an integer overflow vulnerability in a purchase contract, setting the token purchase price to zero and extracting 8,535 ETH ($26.44 million) at near-zero cost. The TRU token collapsed 99.9% within 24 hours.

Root cause: Overflow vulnerability in a legacy closed-source contract that had never been updated or re-audited since deployment.

Resolv — $25 Million (March 22)

An attacker gained access to Resolv's AWS Key Management Service, where a privileged signing key was stored. Using the protocol's own permissions, the attacker minted 80 million unbacked USR tokens — depositing just 100,000 USDC and receiving 50 million USR in return. The stablecoin crashed from $1.00 to $0.025 on Curve Finance within 17 minutes. According to Chainalysis, the exploit stemmed from structural design failures: single-key controlled privileged account, no oracle or amount checks, and no maximum mint limits.

Root cause: Compromised AWS KMS key combined with absence of minting guardrails.

SwapNet — $13.4 Million (January, Late)

Attackers leveraged an arbitrary call flaw in SwapNet's DEX aggregator contracts, draining funds from users who had granted infinite token approvals. The confirmed losses of $13.43 million hit 20 users across Ethereum, Arbitrum, Base, and Binance Smart Chain. One user lost $13.34 million. SwapNet paused contracts 45 minutes after the initial exploit on Base, but 13 additional users were affected on other chains during that window.

Root cause: Insufficient input validation on call data, enabling arbitrary token transfers via existing approvals.

The Vibe Coding Problem

On February 15, 2026, Moonwell DAO executed proposal MIP-X43, enabling Chainlink OEV wrapper contracts across its Base and Optimism markets. One oracle was misconfigured: instead of deriving cbETH's USD price by multiplying the cbETH/ETH feed by ETH/USD, it transmitted only the raw cbETH/ETH ratio. The oracle reported cbETH at $1.12 instead of approximately $2,200.

Liquidation bots immediately attacked collateralized cbETH positions, repaying approximately $1 of debt and receiving 1,096.317 cbETH in return. Total bad debt: $1.78 million.

Security auditor Pashov identified that pull request 578, which introduced the faulty configuration, was co-authored by Claude Opus 4.6. The observation ignited an industry debate, though Pashov noted that "behind the AI is a person who checks the finished work, and possibly a security auditor."

The Moonwell incident did not occur in isolation. A December 2025 study by security firm Tenzai tested five AI coding agents — Claude Code, Cursor, Windsurf, Replit, and Devin — using identical prompts to build 15 applications. Results:

  • 69 vulnerabilities identified across all 15 applications
  • 6 critical-severity findings
  • Business logic and authorization failures were the dominant categories
  • No agent implemented Content Security Policy, HSTS, X-Frame-Options, or proper CORS headers
  • Every application except one shipped login pages with zero rate limiting

A separate March 2026 study by Help Net Security confirmed that AI coding agents "keep repeating decade-old security mistakes," with authorization and access control errors dominating the findings.

The pattern is consistent: AI coding tools generate syntactically correct, functionally working code that systematically omits context-dependent security controls — exactly the type of checks that prevent oracle misconfigurations, unauthorized minting, and privilege escalation.

The Audit Paradox

The Q1 data reinforces a structural problem in DeFi security infrastructure. According to Coinlaw's 2026 audit statistics report, the median time between a DeFi protocol passing an audit and getting exploited is 47 days. Between 2020 and 2025, over $4.2 billion was drained from audited protocols.

The audit market itself reflects this tension. A mid-complexity DeFi protocol's pre-launch security budget in 2026 ranges from $60,000 to $120,000, according to Sherlock's pricing benchmark. Enterprise-grade multi-chain systems can exceed $250,000. Yet audit scope typically covers a snapshot of code at a fixed point in time. Post-audit changes — including governance proposals like Moonwell's MIP-X43 — frequently bypass the original audit perimeter.

Attack vectors in Q1 2026 illustrate the gap:

  • Truebit's exploited contract was five years old and closed-source — effectively invisible to the audit pipeline
  • Step Finance's compromise occurred at the device/key level, outside any smart contract audit scope
  • Resolv's vulnerability was architectural (single-key KMS, no mint caps) — a design flaw that a code-level audit may not flag
  • Moonwell's oracle error was introduced via governance proposal after any prior audit

The common thread: the exploited surface is increasingly outside the boundaries of what traditional smart contract audits cover.

OpenAI's EVMbench and the AI Security Arms Race

On February 18, 2026 — three days after the Moonwell exploit — OpenAI and Paradigm launched EVMbench, a benchmark evaluating AI agents' ability to detect, patch, and exploit smart contract vulnerabilities. The benchmark draws from 120 vulnerabilities identified across 40 prior audits, plus vulnerability scenarios from Paradigm's Tempo blockchain.

Performance results:

| Task | GPT-5.3-Codex | GPT-5 | |------|--------------|-------| | Exploit mode | 72.2% | 31.9% | | Detection mode | Lower | Lower | | Patching mode | Lower | Lower |

The exploit score of 72.2% means GPT-5.3-Codex could successfully drain funds from vulnerable contracts in nearly three-quarters of test cases. Detection and patching scores were materially lower — indicating that AI is currently better at exploiting vulnerabilities than fixing them.

OpenAI announced $10 million in API credits for cyber defense work, with priority given to open-source software and critical infrastructure projects. The timing was not coincidental. The Moonwell incident demonstrated that AI tools can introduce vulnerabilities into production DeFi contracts, while EVMbench demonstrated that AI tools can also find and exploit them.

This creates a dual-use problem with no clear resolution. The same model architecture that generates vulnerable oracle code can also be deployed to scan for those exact vulnerabilities. The economic incentive structure favors offensive use: a single successful exploit yields millions, while defensive security remains a cost center.

Economic Value Analysis: Who Bears the Cost

Applying the economic value framework to Q1 2026's $138 million in exploit losses reveals where value destruction concentrates.

Direct loss bearers:

  • Liquidity providers and depositors: ~$95M (Step Finance treasury holders, Resolv USR holders, SwapNet approval grantors)
  • Token holders (via price collapse): ~$40M+ (STEP -96%, TRU -99.9%, USR -97.5%)
  • Protocol treasuries: ~$3M (Moonwell bad debt, others)

Indirect costs absorbed by the ecosystem:

  • Audit spending that failed to prevent exploits: estimated $2-5M across affected protocols
  • Legal and recovery costs: undisclosed but material (Step Finance explored acquisition before closure)
  • Insurance payouts: negligible — consistent with the $97B DeFi insurance gap identified in prior analyses

Value redistribution (to attackers):

  • On-chain profit extracted: ~$90M+ across Q1 incidents
  • Recovered funds: ~$18M (Balancer whitehat recovery from November 2025 exploit)

The pattern confirms that DeFi's security costs are almost entirely socialized to end users, while the economic value of successful exploits flows to attackers with near-zero friction. Insurance mechanisms cover less than 0.5% of TVL at risk, and audit expenditures provide probabilistic — not deterministic — protection.

Key Takeaways

  • $138.35M lost across ~36 DeFi exploits in Q1 2026, a 29.5% increase over Q1 2025's $106.8M
  • Private key compromise, not smart contract bugs, was the single most damaging vector (~$60M across 4 incidents)
  • AI-generated code entered the DeFi threat model in February when a Claude Opus 4.6-co-authored oracle configuration caused $1.78M in bad debt at Moonwell
  • 69 vulnerabilities were found across 15 applications built by five major AI coding agents in a December 2025 benchmark study
  • The median time between audit completion and exploitation is 47 days; $4.2 billion has been drained from audited protocols since 2020
  • OpenAI's EVMbench showed GPT-5.3-Codex can exploit 72.2% of known vulnerabilities but is less effective at detecting or patching them
  • Two protocols permanently closed (Step Finance, Balancer Labs) as a direct result of exploit-related losses in the quarter

Conclusion

Q1 2026 data shows DeFi's security problem is not improving. Losses increased year-over-year despite lower total crypto market activity and reduced TVL. The attack surface is expanding beyond smart contract logic into key management, governance processes, and now AI-assisted code generation.

The Moonwell incident is particularly instructive. The vulnerability was not in the protocol's core contracts but in a governance-approved configuration change, co-authored by an AI tool, that bypassed existing audit coverage. As AI coding agents become standard development tooling — the Tenzai study tested tools already widely adopted across the industry — the volume of context-dependent security errors entering production code is likely to increase.

OpenAI's EVMbench and $10 million defensive commitment represent early-stage responses to this dynamic, but the economic incentives remain misaligned. Offensive exploitation is immediately profitable. Defensive security spending is a recurring cost with uncertain returns. Until insurance penetration, formal verification tooling, or regulatory requirements alter that equation, DeFi's $105 billion TVL will continue to subsidize a $100M+ quarterly transfer of value from depositors to attackers.

Sources & References

  1. IoTeX, Resolv Labs move on from exploits as 2026 DeFi losses hit $137M — Cryptopolitan, Q1 2026 aggregate loss data
  2. DeFi Exploits Have Already Cost at Least $138.35 Million in 2026 — CryptoAdventure, comprehensive exploit tracker
  3. Step Finance shuts operations after $27 million January hack — CoinDesk, Step Finance closure announcement
  4. Truebit token crashes 99.9% after hacker drains $26.6 million — CoinDesk, Truebit exploit details
  5. Resolv stablecoin crashes 70% as attacker extracts $25 million — CoinDesk, Resolv exploit coverage
  6. The Resolv Hack: How One Compromised Key Printed $23 Million — Chainalysis, root cause analysis
  7. Matcha Meta users hit in $13.4 million SwapNet contract exploit — The Block, SwapNet exploit details
  8. Claude vibe-coded smart contract cost DeFi protocol $1.8M in losses — Cybernews, Moonwell AI code incident
  9. $1.78M 'Vibe-Coded' Oracle Bug Puts AI-Coauthored Contracts Under Scrutiny — CoinTelegraph, Moonwell analysis
  10. AI coding agents keep repeating decade-old security mistakes — Help Net Security, AI coding agent security study
  11. 69 Vulnerabilities in 5 AI Coding Platforms — AppSec Weekly / Tenzai, vulnerability benchmark data
  12. Introducing EVMbench — OpenAI, smart contract security benchmark launch
  13. OpenAI and Paradigm partner on AI agent tool for smart contract security — The Block, EVMbench details
  14. Smart Contract Security Risks and Audits Statistics 2026 — Coinlaw, audit effectiveness data
  15. Crypto hack losses hit $112.5m in first two months of 2026 — AMBCrypto / PeckShield, monthly loss data
  16. Crypto Theft Hit Nearly $400 Million in January 2026 — Yahoo Finance / CertiK, January 2026 total theft data
  17. DeFi's value holds up despite crypto sell-off — CoinDesk, Q1 2026 DeFi TVL data
  18. Balancer Labs to Shut Down Post $128M Exploit — Yahoo Finance, Balancer closure