AI Dividends, Social Engineering Hunting, and Trust Hijacking: Who is Stealthily Hunting Web3?
As AI fundamentally changes the economics of attacks, the targets of attackers shift from code to people...
Written by: ChandlerZ, Foresight News
In the first half of 2026, the crypto sector has reported 344 security incidents, with total losses of approximately $1.32 billion.
According to the Hack3d report released by CertiK in July, excluding last year's single loss of $1.46 billion from Bybit, the number of security incidents in the first half of the year has also increased by 28% compared to 2025.
The number of security incidents in the second quarter surged from 145 last year to 194, representing a year-on-year increase of 34%. The median loss per incident also saw a significant year-on-year increase of 60.6%, reaching approximately $169,000, indicating that even small to medium-sized attacks are now causing significantly greater damage.
Comparatively, the $1.32 billion loss in the first half of 2026 is actually about 28% higher than the same period last year.
Data Source: CertiK
It is noteworthy that incidents causing significant asset losses are increasingly concentrated in operational aspects, with attackers tending to target key management, identity credentials, and supply chains. Although these types of attacks are not the most numerous, once they breach critical permissions, they can directly impact core project assets, leading to substantial financial losses.
On April 1, 2026, Drift Protocol, one of Solana's largest perpetual contract platforms, had approximately $285 million transferred away in just 12 minutes. The attacker disguised themselves as a quantitative trading company for six months, establishing trust that ultimately led a multi-signature signer to pre-sign hidden authorizations. In the same month, the cross-chain re-staking protocol KelpDAO lost approximately $292 million when attackers compromised the third-party verification infrastructure relied upon by the project and forged cross-chain messages. In June, Humanity Protocol lost $36 million due to a phishing email.
None of the three largest security incidents in the first half of the year were due to vulnerabilities in the smart contract code itself.
The SlowMist security team, in an exclusive interview with Foresight News, stated that as of the first half of 2026, among the 182 incidents recorded, operational failures (key leaks, social engineering, supply chain attacks) accounted for only 53 incidents, or 29.1%, but caused losses of $732 million, or 76.6% of total losses.
Security company TRM Labs also released a report indicating that in the security incidents of the first half of the year, vulnerabilities in infrastructure and operations accounted for only about 15% of the total incidents, yet caused approximately 76% of total losses, far exceeding the impact of over 100 smaller-scale smart contract vulnerabilities.
Monthly loss amounts caused by various types of attacks in the first half of 2026.
Data Source: TRM Labs
Based on this situation, Foresight News conducted in-depth discussions with the SlowMist security team and CertiK senior security engineer Yuannan Yang to clarify the driving forces behind these numbers and the "new problems" emerging in the crypto security field.
In the interviews, we found that multiple forces are simultaneously at play behind these numbers. On one hand, AI is fundamentally changing the economics of attacks, making previously unprofitable attacks lucrative. On the other hand, attackers' targets are shifting from code to people, with social engineering and key management failures replacing smart contract vulnerabilities as the largest sources of loss. The entire security infrastructure built around code auditing is facing unprecedented challenges.
AI is rewriting the economics of attacks
Over the past year, several independent studies have begun to quantify the impact of AI on smart contract attacks, with conclusions pointing in the same direction: the cost, speed, and accessibility of attacks are undergoing orders of magnitude changes.
Anthropic's SCONE benchmark tested 405 real exploited smart contracts, finding that the success rate of exploiting contract vulnerabilities after the knowledge base cutoff date (after March 2025) reached 55.8%, with a single scan cost of about $1.22, simulating an attack value of $4.6 million.
Even on contracts that the model had never seen before, vulnerabilities worth $4.6 million were still discovered.
In simulated tests, the profits obtained from exploiting stolen simulated funds approximately double every 1.3 months.
Data Source: Anthropic
Professor Arthur Gervais and Liyi Zhou from University College London built an agent system called "A1" that can turn any large language model into an end-to-end vulnerability exploitation generator. In tests targeting 36 real historical vulnerabilities (such as access control flaws, logic and signature verification vulnerabilities, etc.), A1 extracted approximately $9.33 million in attack value during the validation process, with a single vulnerability yielding as much as $8.59 million.
This research also reveals a severe economic asymmetry between attackers and defenders. The paper points out that attackers only need about $6,000 to break even and make a profit, while defenders need to invest about $60,000 to achieve profitability or break even. This enormous cost gap of up to 10:1 means that previously overlooked attack targets due to unfavorable cost-benefit ratios are now becoming profitable.
These quantified trends have direct correspondences on-chain. Groth16 is a cryptographic algorithm used by many zero-knowledge proof protocols to verify transaction legitimacy. In the first half of 2026, a setup vulnerability of this algorithm was exploited on-chain for the first time. Just five days later, larger-scale attacks targeting similar vulnerabilities emerged. Aztec Connect, which had been out of operation for three years, was also exploited twice by different attackers within five days.
Cryptographic vulnerabilities are technically far more complex than conventional code logic errors, which previously required professional researchers weeks to understand and reproduce. The emergence of imitators within five days indicates that the speed of knowledge dissemination regarding attacks is being redefined. UCL's paper also found that the success rate of exploiting vulnerabilities immediately after they are made public is as high as 86% to 89%, plummeting to 6% to 21% after a week.
The attack window is extremely short, yet it is deadly for projects without real-time monitoring capabilities.
Attack patterns upgrade, speed increases, and spread widens
In addition to acceleration, AI is also expanding the range of potential targets.
Yuannan Yang, a senior security engineer at CertiK, stated that cryptography is fundamental; objectively speaking, in terms of the number of lines of code and mathematical operations involved, vulnerabilities targeting cryptographic implementations are technically more complex than conventional accounting vulnerabilities.
AI can handle decompiled code and even low-level bytecode, inferring the core logic of protocols and identifying vulnerabilities without high-level semantic information. "With the assistance of AI, attackers can learn these exploitation mechanisms in just a few days, find new vulnerable contracts, and apply new attack techniques."
In the past, contracts without publicly available source code were almost black boxes for attackers. Yuannan Yang pointed out that attacks on such contracts are rapidly increasing, with 19 out of 186 vulnerabilities exploited in the first half of 2025, 17 out of 176 in the second half, and 37 out of 257 in the first half of 2026.
A number of abandoned contracts still locked with funds have thus been re-exposed, with over 1,400 positions in DxSale's old locked contract being extracted in bulk, and the Truebit contract, which had not been maintained for three years, also came under attack. The teams behind these projects have long since disbanded, the contracts are non-upgradable, and no one is available to fix them.
To what extent is AI involved in actual attacks? Yuannan Yang believes that in terms of speed (the time window from vulnerability discovery to exploitation) and automation, it is difficult to quantify the differences in attacks in 2026 compared to the previous two years.
The reason is that in most incidents, specific vulnerabilities are first discovered by attackers, who may be the only ones aware of that time window. However, this year has seen unprecedented cases showing that attackers are learning and applying new attack vectors at an extremely fast pace.
The SlowMist security team also believes that AI-assisted attacks have become quite common, observing that AI is widely used in social engineering and the preparation phase of attacks, such as generating phishing pages, fake websites, recruitment materials, social engineering scripts, and malicious code, making the attack content more realistic and personalized. In some publicly available attack samples, traces of AI tools can also be clearly seen in the generated content. Additionally, technologies like Deepfake voice and video are beginning to be used in social engineering attacks targeting high-value targets.
The most typical public case is the fake recruitment attack launched by the Lazarus Group-affiliated organization HexagonalRodent. Attackers used AI tools like ChatGPT and Cursor to create fake corporate websites, recruitment materials, and communication content, generating some code to lure Web3 developers into installing malicious programs or leaking sensitive information.
Moreover, as more and more project developers use AI Coding, new attack patterns targeting this model are also emerging. In May, the Socket.dev security research team disclosed a supply chain poisoning attack operation spanning npm, PyPI, and Crates.io, named TrapDoor. This operation involved over 34 malicious packages, with a total of 384 versions released, targeting developers in the cryptocurrency, DeFi, Solana, AI, and security fields.
Data Source: Socket.dev
Attackers exploit the native execution mechanisms of various package ecosystems (such as npm's postinstall hooks, PyPI's import entry points, and Crates.io's build.rs compilation scripts) to automatically trigger malicious logic during the installation or compilation phase, stealing high-value data such as SSH keys, blockchain wallet configurations, cloud credentials, and browser session tokens.
The fundamental asymmetry in offense and defense lies in the fact that attackers only need to find one breakthrough, while defenders must cover all fronts.
Both sides are accelerating, and the attackers naturally run faster.
The biggest vulnerability has always been human
In recent years, DeFi has established a relatively mature code security industry. Before launching, projects undergo smart contract audits, fuzz testing, and formal verification, and after going live, they have bug bounty programs and on-chain monitoring, with significant funding invested in preventing code errors. Despite the challenges posed by the widespread application of AI, the safety of funds often still hinges on a few specific individuals.
Data from CertiK shows that the number of phishing incidents in the first half of 2026 decreased by 52.3% year-on-year, which seems like good news. However, the amount of losses only decreased by 10.8%, indicating that attack patterns are concentrating on "a small number of high-value targets."
Yuannan Yang explained that unlike traditional phishing, which casts a wide net to a massive user base, this type of attack specifically targets already identified high-value wallets, conducting background reconnaissance on the targets and tailoring attack plans. If a target wallet contains hundreds of millions of dollars, spending weeks specifically targeting one person is extremely cost-effective from the attacker’s economic perspective.
A typical case is the theft incident involving the perpetual contract trading platform Drift Protocol on the Solana chain. In the fall of 2025, a group claiming to be from a quantitative trading firm began engaging with the Drift team. They invested over $1 million in real money trading on Drift, participated in community discussions, and built trust over six months. On April 1, 2026, they induced a multi-signature signer (one of the authorized individuals controlling the contract funds) to pre-sign a hidden authorization in what appeared to be a normal transaction.
In just 12 minutes, approximately $285 million in user assets was transferred away.
Attackers quickly exploited the compromised signer keys
Data Source: PeckShield
Subsequent investigations attributed the attack to the North Korean government-associated hacking group UNC4736, which has been continuously targeting the cryptocurrency and fintech industries since 2018, stealing digital assets through supply chain attacks, social engineering, and malware delivery. Known large-scale attacks by this group include the March 2023 3CX supply chain attack, the theft of approximately $50 million from Radiant Capital in 2024, and the recent theft of about $285 million from Drift, totaling approximately $335 million in stolen funds according to available statistics.
Drift is an extreme case of social engineering, but vulnerabilities in operational security take many forms. In the first half of the year, failures in key management and infrastructure layers occurred frequently. Attackers of Kelp DAO compromised the third-party RPC infrastructure relied upon by the project, transferring approximately $291 million by forging cross-chain message validations; Resolv Labs conducted 18 security audits but ultimately lost about $26.85 million due to a breach of AWS cloud key management services; in mid-July, Ostium suffered a security incident resulting in over $23.75 million in losses, also stemming from the leakage of administrator account private keys, with hackers breaching off-chain infrastructure related to the protocol's pricing system.
Social engineering, infrastructure breaches, cloud key leaks, and exposed code repositories have expanded the attack surface to every aspect where humans are involved.
SlowMist has been tracking North Korean-related attack organizations for years and observed a clear tactical shift: social engineering techniques are evolving from quickly gaining access to long-term trust-building, resulting in longer attack cycles, greater resource investment, and increased stealth.
As defenders, the crypto industry still lacks universal operational security standards. SlowMist mentioned in an interview that many teams still equate security with a one-time code audit before going live, severely underinvesting in key management, permission isolation, and employee security awareness.
Some mature projects have established relatively complete security systems, but the reality is that many small and medium-sized projects lack even basic multi-signature configurations and key rotation.
The SlowMist security team places key management as the top priority in the minimum operational security standards for DeFi projects, advocating that critical assets and management permissions should adopt a multi-signature architecture, establishing standardized mechanisms for key generation, storage, backup, and rotation. They believe that "operational security is essentially human security; the most fundamental change in Web3 security in the first half of the year is that the focus of attacks is shifting from finding code vulnerabilities to breaking through people and processes." As social engineering attacks continue to escalate, project teams need to continuously conduct security training and attack-defense drills to enhance members' ability to recognize new attack methods such as phishing and AI-generated content.
CertiK has already established operational security assessments as an independent OpSec audit service, covering key management architecture, multi-signature configurations, and employee device security policies, while also providing authorized phishing drills and emergency response exercises. Yuannan Yang stated that the demand from project parties is continuously increasing.
The security industry itself is being reshaped
As the main battleground of attacks shifts from code to operations, the entire security infrastructure built around code audits faces reevaluation.
Analysis from the security research organization SigIntZero shows that 89.2% of attacked projects had previously undergone audits. Hacken's Q1 report also pointed out that at least six protocols that passed audits were successfully attacked in the first half of the year, including Resolv Labs, which conducted 18 audits, yet vulnerabilities still appeared in areas never covered by audits.
Upgrading from one-time audits to continuous security operations is a direction pointed out by both interviewed organizations, emphasizing minimizing key permissions and multi-signatures, setting on-chain limits for minting and withdrawal, continuous monitoring, and automatic suspension, with each code change undergoing re-examination.
However, upgrades require funding, and many projects struggle to survive during bear markets. In February 2026, the decentralized lending protocol Zerolend announced its shutdown, a situation that can be summarized as comprehensive hemorrhaging: liquidity continued to decline, oracle support ceased, lending profits were compressed, and security threats simultaneously increased.
Yuannan Yang remarked, "As revenues and liquidity decline, the costs of security measures such as audits, bug bounties, monitoring, and emergency responses become difficult to sustain. Projects choose to cut expenses, operate in the open, or even migrate on-chain deployments, which inherently amplifies security risks until an attack occurs, and when losses become irreparable, projects ultimately choose to shut down."
Under the catalysis of the bear market, the security industry is becoming more polarized. Institutional-level projects are increasing security investments in response to escalating attacks and compliance pressures, increasingly inclined to embed audits into the development cycle. The situation for small and medium-sized projects is entirely different; lacking liquidity and facing difficulties in financing, security often becomes one of the budget cuts, and the demand for audits for new projects is also slowing down.
The SlowMist security team stated that from their actual observations, market cycle changes do indeed affect the demand for security services, but this impact is more reflected in the adjustment of demand structure. For example, during bear market phases, the demand for audits for new projects may slow down. Many budget-constrained startup teams may reduce or postpone audits, or even choose cheaper small auditing teams, while some projects may take advantage of the bear market to lay out their strategies.
Additionally, the first response of project parties after experiencing an attack is usually to quickly confirm the attack status and impact scope, including determining whether the attack is still ongoing, the range of affected systems or contracts, and the extent of financial losses, and taking emergency measures based on the situation, such as limiting risky operations, adjusting permissions, protecting remaining assets, while coordinating internal teams and external security organizations for analysis.
In practice, the level of emergency preparedness varies significantly among different projects. Some mature projects establish monitoring alerts, emergency processes, and collaboration mechanisms in advance, while others only begin to establish response mechanisms after an incident occurs.
Summary
Phishing, social engineering, key leaks—old problems in the field of crypto security are being replayed in every cycle. After conversations with SlowMist and CertiK, it is evident that what has truly changed in the first half of the year is the economics of attacks, the cost-benefit structure for attackers has fundamentally changed. AI has simultaneously lowered the costs and thresholds for attacks; as attacks become cheaper, old problems will reappear with higher frequency and larger scale.
Key storage, cloud permissions, employee security awareness, and third-party dependencies—the areas that need protection far exceed just the code; every link could become a breakthrough point. The security industry is transitioning from code audits to full-stack protection, and how quickly this transformation can run will determine how many old problems will reappear on a new scale in the second half of the year.
Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.
You may also like

Isn't it AI or War, but Japan that the US Stock Market Should Worry About?

Gold Bounces Back as Managers Consider It Undervalued

HR Wisdom Summit 2026: Why the HR Director Became the Owner's Right Hand and How Their Role Changed During the War

The Next Five Years Will Not Be Dominated by a Single Sector: Exilist Analyzes the Rise of On-Chain Finance Combining Stablecoins, RWA, and AI

Goldman Sachs Analysis: Intel's Q2 Surpasses Expectations, Manufacturing Transformation Still Awaits Realization

Stripe Plans to Acquire OpenRouter: Is AI the Focus of Future Payment Landscapes?

Bitcoin Mining: Kazakhstan to Charge Crypto Miners to Fill Its Strategic Reserve

LayerZero and Keeta bring tokenized bank deposits to major chains

China completes first digital yuan payment to Singapore

Flow Traders tests Lombard’s Bitcoin-backed stablecoin credit

New EU Sanctions Seriously Complicate Access to Cryptos for Russians

Reassessing the Fit Between Founders and the Market in a Crypto Bear Market

Crypto, AI, Slavery: The UN Unveils a $114 Billion Criminal Empire

CLARITY Act's Passage Prospects Dim as Trump's Crypto Conflicts of Interest Become Major Obstacle

Hester Peirce Warns Crypto Asset Custodians and On-Chain Lenders—Indicates Application of Securities Law and Enhanced Oversight

The yen experiences its worst drop in four decades

SEC sets September talks as 24-hour stock trading moves closer

Boundless Enters AI Inference Market, Aiming for Up to 50% Cost Reduction

Bitcoin Under Pressure: U.S. Bonds Become Its New Rival

Block Announces Open Source AI-Powered Chat "Buzz" to Compete with Slack and GitHub

New Fields Medalist Hong Wang Also Dabbled in AI?

Alarm Bells Ringing in the U.S. Treasury Market for the First Time Since 2007

Hackers' Day | July 23: $35.5M Lost. A Reminder That Security Is a Shared Responsibility
On July 23, three major DeFi protocols lost a combined $35.5 million within just six hours, highlighting the growing importance of crypto infrastructure security. This report reviews what happened, what these incidents reveal about today's security landscape, and why building resilient protection systems has become a shared responsibility across the entire crypto industry.

Zhibao, a Listed Company, to Receive Bitcoin Worth 37 Billion Yen in Exchange for New Share Issuance

NHN KCP and Avalanche Unveil Stablecoin Payment System with 2-Second Approval and 1-Hour Settlement

U.S. Tech Giants' Hidden AI Debt Soars to $1.65 Trillion, Eightfold Increase in Four Years Raises Market Concerns

Binance Founder Changpeng Zhao Reflects: BitMEX Pioneered 100x Crypto Perpetual Contracts in 2014, Paying Tribute to Arthur Hayes

BitMEX Is Shutting Down: The End of a Crypto Pioneer and What Traders Need to Know

Play Your Hand: Deal Yourself Into WEEX Poker Party Series 4
Deal yourself into WEEX Poker Party Series 4 (Jul 21–Aug 10, 2026): every deposit, trade and invite earns card draws for a USDT pool growing up to $1,000,000. Free to join.
![[Interview] "Technology Matures When It Becomes Invisible"](/public-static/33_70806c0ee0.png?format=avif)










