DeFi protocols lost more than $840 million in the first five months of 2026, with April recording exploits on 27 of 30 calendar days — the worst month in four years, according to CertiK. The surge coincides with the emergence of AI coding agents capable of autonomously scanning smart contracts fo...
"Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds." — Manuel Aráoz, Co-Founder, OpenZeppelin
DeFi protocols lost more than $840 million in the first five months of 2026, with April recording exploits on 27 of 30 calendar days — the worst month in four years, according to CertiK. The surge coincides with the emergence of AI coding agents capable of autonomously scanning smart contracts for vulnerabilities faster than human auditors can patch them. OpenZeppelin co-founder Manuel Aráoz publicly declared on May 26 that he considers "all of DeFi unsafe," citing the structural asymmetry between attackers who need a single exploit and defenders who must eliminate every flaw.
The financial damage is concentrated: the $292 million Kelp DAO bridge exploit and the $286 million Drift Protocol hack — both attributed to North Korean state-linked actors — account for roughly 69% of 2026 losses. Total value locked across DeFi dropped $20 billion year-to-date, from $105 billion to approximately $85 billion as of mid-May, driven by a combination of exploit-triggered liquidations and capital flight. CertiK CEO Ronghui Gu stated that near-daily hacks targeting smart contracts, oracles, and cross-chain bridges represent the single largest barrier to institutional on-chain adoption.
The defense industry is consolidating under pressure. Code4rena, the competitive audit platform backed by a $6 million Paradigm raise, shut down in May 2026. Immunefi absorbed its security researchers and bounty programs. The audit market itself ranges from $5,000 for simple token reviews to $500,000+ for complex bridge or ZK-rollup assessments — budgets that are structurally outmatched by attackers spending as little as $10,000–$20,000 on continuous AI-powered vulnerability scanning.
In 2026 through May, DeFi exploit losses exceeded $840 million across dozens of incidents, according to data compiled by CertiK and Immunefi. The trailing 12-month figure surpasses $1.1 billion. For multi-year context, Immunefi's research shows 425 publicly disclosed hacks drained $11.9 billion over five years through 2025. CertiK independently recorded $3.35 billion across 2025 blockchain security incidents, with the average loss per incident rising 66.6% year-over-year.
April 2026 was the inflection point. CertiK detected exploits on 27 of 30 days, making it the highest-frequency month on record since the firm began tracking in 2020. The average direct theft per protocol hack in 2026 stands at roughly $25 million, per Immunefi.
Two incidents dominate the loss distribution:
| Incident | Date | Amount | Attack Vector | Attribution | |---|---|---|---|---| | Kelp DAO Bridge | April 18, 2026 | $292M | Bridge infrastructure compromise | Lazarus Group (North Korea) | | Drift Protocol | April 1, 2026 | $286M | Social engineering / privileged access | UNC4736 (North Korea) | | Other 2026 incidents | Jan–May 2026 | ~$262M | Various | Multiple actors |
The concentration is notable: two incidents, both attributed to DPRK-affiliated threat actors, account for approximately 69% of all 2026 losses.
Manuel Aráoz, who co-founded OpenZeppelin in 2015 and served as CTO until 2019, posted on X on May 26 that he now considers all major DeFi protocols — naming Aave, MakerDAO, and Compound — unsafe. His core argument: AI coding agents have reached "superhuman" capability in identifying smart contract vulnerabilities, and the defender-attacker asymmetry has tilted decisively toward offense.
The technical basis for this concern is specific. Anthropic's restricted Claude Mythos model and similar frontier AI systems can autonomously discover software vulnerabilities and develop working exploits, according to Aráoz and corroborated by multiple security researchers cited in CoinDesk reporting. These capabilities exceed existing automated security tools in both speed and coverage.
CertiK CEO Ronghui Gu provided supporting data in a May 28 interview: attackers now deploy "advanced engines" for continuous vulnerability scanning at costs of $10,000–$20,000 per campaign. By contrast, a pre-launch security audit for a mid-complexity DeFi protocol costs $60,000–$120,000, and annual security budgets for protocols with meaningful TVL run $150,000–$500,000, according to Sherlock's 2026 market pricing data.
The economic math is unfavorable for defenders. An attacker's scanning cost represents 2–4% of a typical protocol's annual security budget. The attacker needs one vulnerability; the protocol must find them all.
OpenZeppelin distanced itself from Aráoz's conclusions. A company spokesperson stated that "Aráoz's views do not represent OpenZeppelin's current position," arguing that "continuous, AI-augmented security" is the appropriate response rather than retreat from DeFi.
Kelp DAO ($292 million, April 18, 2026)
The Kelp DAO breach was not a smart contract logic error. Attackers compromised two RPC nodes hosted by LayerZero, then launched a DDoS attack against external nodes to force failover to attacker-controlled infrastructure. The single-verifier configuration (a 1-of-1 DVN setup) treated the compromised nodes as the sole source of truth, allowing the attackers to fabricate a phantom token burn and trigger release of 116,500 rsETH on Ethereum.
Kelp stated this 1-of-1 DVN configuration was the default shipped by LayerZero for new deployments. LayerZero later recommended a multi-DVN setup. The stolen rsETH represented approximately 18% of the token's circulating supply. Kelp's contracts were paused to prevent a second $95 million theft. The Arbitrum Security Council froze over 30,000 ETH in downstream attacker funds.
According to Chainalysis forensic analysis, the attack methodology is consistent with Lazarus Group operations.
Drift Protocol ($286 million, April 1, 2026)
The Drift breach originated from a six-month social engineering operation attributed with "medium-high confidence" to UNC4736, a North Korean state-affiliated group previously linked to the 2024 Radiant Capital hack. The attribution was supported by investigations from the SEAL 911 team and corroborated by Elliptic and TRM Labs.
Attackers gained privileged access to Drift's infrastructure through prolonged social engineering of team members, beginning in fall 2025. This was the largest exploit in Solana ecosystem history after the $326 million Wormhole bridge exploit in 2022. Drift's TVL collapsed from approximately $550 million to under $250 million. The protocol outlined a recovery plan on May 5.
Both exploits share a common pattern: the attack surface was not in audited smart contract logic but in surrounding infrastructure — RPC nodes, access controls, social engineering of team members.
The DeFi security industry underwent structural consolidation in May 2026. Code4rena, the competitive audit platform where independent "wardens" competed to find smart contract vulnerabilities, announced its wind-down. Immunefi absorbed its researchers, bounty programs, and client relationships.
Code4rena's trajectory illustrates the economics of DeFi security: $6 million raise from Paradigm in 2023, acquisition by Zellic in 2024 with promises of independent operation, and shutdown less than two years later. The competitive audit model — designed to apply market incentives to vulnerability discovery — could not sustain itself as exploit frequency outpaced audit throughput.
The 2026 audit market, per Sherlock and Zealynx pricing data:
| Project Complexity | Audit Cost | Timeline | |---|---|---| | Simple ERC-20 token | $5,000–$15,000 | 1–2 weeks | | DeFi protocol (DEX, lending) | $50,000–$100,000 | 4–8 weeks | | Cross-chain bridge / ZK-rollup | $150,000–$500,000 | 8–16 weeks |
Rush engagements add 30–50% to these figures. Most established protocols now combine three defense layers: a firm audit pre-launch, a competitive contest for breadth, and a standing bug bounty program. Total annual security budgets for meaningful-TVL protocols range from $150,000 to $500,000.
The structural problem: audits are point-in-time assessments. AI-powered scanning is continuous. A protocol audited in January may face novel AI-discovered attack vectors by March.
CertiK's Gu framed the security problem in institutional terms: "When they move assets onchain, they need to face all these AI attacks, smart contract vulnerabilities, oracle manipulation, and cross-chain bridge hacks."
This observation aligns with the broader pattern documented in CoinDesk's May 28 reporting. Traditional financial institutions planning to tokenize and move trillions of dollars in assets on-chain cite DeFi security as their primary technical blocker. The near-daily exploit cadence in April 2026 reinforced hesitation among what CoinDesk described as "conservative capital allocators."
The timing is significant. DTCC has deployed three blockchains under $114 trillion in custody. Paxos received SEC registration as the first blockchain clearing agency. Mastercard obtained a BitLicense. The institutional infrastructure is being built. But the security risk profile of on-chain environments — where code is transparent and attackable, and where AI can scan faster than humans can patch — remains the constraint.
CertiK maintains approximately 5,000 clients and detected exploits on 27 of 30 days in April. The firm attributes the sudden increase in exploit frequency to AI involvement, though it did not release specific technical attribution data to support this assessment.
Total DeFi TVL contracted from $105 billion at the start of 2026 to approximately $85 billion by mid-May, a decline of roughly $20 billion. The sharpest single drop occurred April 18–20, following the Kelp DAO exploit, when TVL fell from $99.5 billion to $86.3 billion in 48 hours.
Aave, the largest lending protocol by TVL, lost $8.45 billion in the two-day period following the Kelp hack, dropping to $17.9 billion. The mechanism: stolen rsETH used as collateral triggered cascading liquidations across lending platforms.
Ethereum's share of DeFi TVL declined from 63.5% at the start of 2025 to approximately 53% by mid-May 2026, approaching a multi-year low. Solana holds 6.81%, BSC 6.59%, Bitcoin 6.16%, Tron 6.00%, and Base 5.36%.
The TVL decline reflects both exploit-driven losses and precautionary capital withdrawal. Aráoz publicly stated he advised "family and friends" to exit positions in Aave, MakerDAO, and Compound.
The convergence of AI-accelerated vulnerability discovery, state-sponsored attack campaigns, and structural defender-attacker asymmetry has produced the most hostile DeFi security environment on record. The data shows accelerating losses, compressing attack cycles, and a defense industry that is consolidating rather than scaling.
The economic framework is clear: the cost to attack is falling (AI-powered scanning at $10K–$20K), the cost to defend is rising (annual budgets of $150K–$500K that still fail to prevent exploits), and the potential payoff for attackers remains measured in hundreds of millions per incident. This asymmetry is not a temporary market dislocation. It is a structural feature of transparent, on-chain code in an era of increasingly capable AI systems.
Whether OpenZeppelin's official position — that "continuous, AI-augmented security" can close the gap — or Aráoz's assessment — that the gap is now uncloseable — proves correct will determine whether DeFi remains viable as infrastructure for institutional capital. The 2026 data so far supports Aráoz's side of the argument.