AI agents exploited 51.11% of 405 smart contract vulnerabilities in simulated environments, generating $550.1 million in theoretical stolen funds, according to an Anthropic Fellows Program study published in 2026. In parallel, real-world incidents — a Morse-code prompt injection that drained $174...
"Right now, agents are no longer just answering questions in a chat window. They are beginning to call external tools, read local files, trigger workflows, and interact with financial infrastructure. But if you do not isolate the execution environment and scan these tools first, you are handing a compromised identity broad internal access to your entire network." — Ronghui Gu, Co-founder & CEO, CertiK
AI agents exploited 51.11% of 405 smart contract vulnerabilities in simulated environments, generating $550.1 million in theoretical stolen funds, according to an Anthropic Fellows Program study published in 2026. In parallel, real-world incidents — a Morse-code prompt injection that drained $174,000 from a Grok-linked wallet, a $6 million flash-loan exploit on Summer.fi's AI-automated vaults, and a 14-wallet breach of the Bankr AI trading platform — demonstrate that AI is not just enhancing DeFi defense. It is simultaneously expanding the attack surface.
CertiK's Hack3d H1 2026 report, released July 8, documented $1.31 billion lost across 344 security incidents. Adjusted for the $1.45 billion Bybit outlier in H1 2025, losses are approximately 28% higher on a comparable basis. The report arrived days after Immunefi counted 207 hack incidents in H1 2026 — the highest incident count ever recorded. Within this environment, AI is accelerating both sides of the security equation, and the data suggests offense is outpacing defense.
In February 2026, OpenAI and Paradigm released EVMbench, an open-source benchmark evaluating whether AI agents can detect, patch, and exploit smart contract vulnerabilities. The dataset comprises 120 curated vulnerabilities sourced from 40 audits, primarily from open code audit competitions. GPT-5.3-Codex, running via Codex CLI, scored 72.2% in exploit mode — up from 31.9% for GPT-5 approximately six months prior.
Separately, the Anthropic Fellows Program evaluated 10 frontier AI models against SCONE-bench, a corpus of 405 smart contracts with known exploits spanning 2020–2025. Results:
The zero-day discovery cost GPT-5 an estimated $3,476 in API fees to scan 2,849 recently deployed contracts with no known vulnerabilities. Anthropic estimated the average cost of scanning a single contract at $1.22.
One year prior, AI agents exploited only 2% of similar benchmark problems. The jump to 55.88% on post-cutoff contracts indicates a capability trajectory that outpaces most protocol security upgrade cycles.
The economics are structurally unfavorable for defenders. Anthropic's data shows attackers become profitable at roughly $6,000 in exploit value — a threshold met by most non-trivial DeFi contracts. An attacker using AI agents can scan hundreds of newly deployed contracts per day at minimal cost.
Defenders face compounding expenses: manual audits, formal verification, bug bounties, monitoring infrastructure, and incident response. CertiK CEO Ronghui Gu described the dynamic as "an unfair game," stating that attackers possess functionally infinite resources while defenders operate under fixed budgets.
The gap is quantifiable. A 2025 academic paper cited by multiple security firms identified a structural 10x imbalance between attack and defense costs. AI amplifies this: the attacker pool expands as technical barriers fall, while defenders face rising costs from increased attack frequency and surface area.
Immunefi's H1 2026 data underscores the velocity problem. The 207 recorded incidents represent the highest attack count for any half-year period. Per-incident losses have declined — suggesting more attempts against smaller targets — but aggregate losses remain near $1 billion ($972 million per Immunefi; $1.31 billion per CertiK, which uses a broader incident classification).
An attacker drained approximately $174,000 in DRB tokens from a Grok-linked wallet on the Base network through a two-stage attack:
Stage 1 — Privilege Escalation: The attacker sent a Bankr Club Membership NFT to Grok's associated wallet. The Bankr system interpreted this as a legitimate permission expansion, unlocking transfer and swap capabilities that were previously restricted.
Stage 2 — Prompt Injection via Morse Code: The attacker posted a reply to Grok on X (formerly Twitter), embedding a transfer instruction encoded in Morse code. To Grok's safety layer, the input appeared to be a benign translation request. Once decoded, the Bankr trading bot treated the output as an authenticated financial command and executed a transfer of 3 billion DRB tokens to the attacker's wallet.
SlowMist classified the vulnerability as a combination of OWASP LLM01:2025 (Prompt Injection) and OWASP LLM06:2025 (Excessive Agency). Approximately 80% of funds were eventually returned after community members identified the attacker.
Two weeks after the Grok incident, the Bankr AI trading platform paused all swaps and transfers after confirming an attacker had accessed 14 wallets. Addresses linked by investigators held roughly $440,000, with some users reporting losses near $150,000 per wallet. Bankr pledged full reimbursement.
The breach exposed a fundamental architectural flaw: AI agents with wallet access lack the ability to reliably distinguish between conversational context and executable instructions.
Blockaid's exploit detection system flagged an ongoing attack on Summer.fi's Lazy Summer Protocol, an automated yield platform that routes deposits across lending markets such as Aave and Morpho. The exploiter obtained a $65.4 million flash loan from Morpho and routed funds through Curve, Uniswap, and Balancer to manipulate vault liquidity and share prices, draining approximately $6 million from USDC vaults.
Summer.fi paused all Lazy Summer vaults. The SUMR token fell 18%. While the exploit was a flash-loan attack rather than an AI-specific vulnerability, it highlighted the risk embedded in automated vault architectures — the same infrastructure now increasingly managed by AI controllers.
DeFi's automated vault sector has grown substantially. Morpho alone holds approximately $6.5–7.2 billion in total value locked, roughly 3.5x the entire legacy yield-aggregator category (Yearn, Beefy, and others at approximately $1.6 billion combined). Apollo Global Management, managing $940 billion in traditional assets, acquired up to 9% of Morpho's token supply over four years. Kraken launched DeFi Earn in January 2026, routing centralized exchange deposits into on-chain lending vaults.
Next-generation vaults increasingly incorporate AI controllers that reallocate capital based on live market conditions, optimizing across hundreds of variables. This introduces a new dependency layer between user deposits and smart contract execution — a layer that is neither fully transparent nor fully auditable by current methods.
CertiK's Gu identified this as a structural shift in attack strategy: "As smart contract auditing standards improve, attackers are increasingly targeting supply chain, operational security, and infrastructure layers." Automated vaults, with their keeper networks, rebalancing logic, and now AI decision engines, represent precisely this kind of expanded infrastructure layer.
The Summer.fi incident — where the vulnerability sat in vault accounting logic rather than in a base-layer smart contract — illustrates how automated complexity creates audit blind spots.
CertiK's Hack3d H1 2026 report, released July 8, provides a comprehensive view:
| Metric | H1 2026 | H1 2025 | Change | |--------|---------|---------|--------| | Total Losses | $1.31B | $2.47B | -46.8% | | Adjusted Losses (excl. Bybit) | $1.31B | ~$1.02B | +28% | | Total Incidents | 344 | 345 | -0.3% | | Wallet Compromise Losses | $445M (33 incidents) | — | — | | Phishing Losses | $366M (63 incidents) | — | — | | Code Vulnerability Losses | $152M (204 incidents) | — | — |
April 2026 was the costliest month: $651 million across 61 incidents. The two largest events — the KelpDAO RPC compromise ($291 million) and the Drift Protocol breach ($285 million) — together accounted for 44% of all H1 losses.
CertiK's assessment: "A headline reading of 'losses down nearly 50%' would suggest a meaningfully safer ecosystem. The data does not support that conclusion."
Wallet compromise has emerged as the most financially destructive category per incident. Code vulnerabilities, while generating lower per-incident losses ($152 million across 204 incidents), represent the highest-frequency vector — and the one most directly susceptible to AI-accelerated exploitation.
The intersection of AI and DeFi security has direct consequences for institutional capital allocation. CoinDesk reported in late May 2026 that DeFi vulnerabilities remain traditional finance's biggest blocker for on-chain deployment. The near-daily exploit cadence documented by CertiK — "only three days without hacks" in April, per Gu — makes institutional risk committees structurally cautious.
DeFi total value locked fell approximately 39% in 2026 to roughly $70 billion, per CryptoRank data. Compressed yields and elevated risk perception are cited as primary drivers. For institutional allocators evaluating on-chain yield products — particularly automated vaults — the AI security dimension adds a new variable to already complex risk models.
Formal verification remains the gold standard for smart contract security, but it does not extend to AI decision layers, keeper networks, or the infrastructure stack surrounding automated vaults. As Gu noted: "Even if you run an AI model for 30 hours and it doesn't find a vulnerability, it can't prove that your code is bug-free. The only known way is through formal verification." The implication is that AI-augmented security tooling supplements but does not replace mathematical proof — and the AI layers themselves remain outside the scope of formal verification.
The data from H1 2026 describes a DeFi security environment where AI operates as a dual-use technology with no equilibrium in sight. On defense, AI-powered monitoring tools (Blockaid, CertiK, PeckShield) detect exploits faster. On offense, frontier models autonomously synthesize exploit scripts for more than half of known vulnerability types at negligible cost.
The practical implication is that time-to-exploit — the window between a vulnerability's deployment and its extraction — is compressing. Contracts that might have survived months with an undiscovered flaw now face scanning by automated agents within hours of deployment. Protocols that rely on post-deployment monitoring without pre-deployment formal verification operate with a shrinking margin of safety.
For the DeFi ecosystem, the AI security dimension is not a future concern. It is a current operating condition.