
{"id":218233,"date":"2026-08-25T14:06:14","date_gmt":"2026-08-25T14:06:14","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=218233"},"modified":"2026-08-25T14:06:14","modified_gmt":"2026-08-25T14:06:14","slug":"2026-cryptos-most-hacked-year-and-the-ai-race-to-defend-it","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=218233","title":{"rendered":"2026 Crypto\u2019s Most-Hacked Year, and the AI Race to Defend It"},"content":{"rendered":"<p><strong>TL;DR.<\/strong> 2026 has recorded more crypto exploits than any year on record, over 200 in the first half alone, more than one a day. The dollars stolen are actually lower than 2025, because no single theft matched last year\u2019s $1.5 billion Bybit hack, but the number of attacks has roughly doubled. The driver is AI, which has lowered the cost and skill needed to probe software until attacking a small protocol became economical for the first time. That same technology is now the strongest defense.<\/p>\n<h3>What the numbers actually\u00a0show<\/h3>\n<p>The clearest way to see 2026 is to separate two things that usually get merged, how often protocols are attacked and how much is taken when they\u00a0are.<\/p>\n<p>The picture is a divergence. Total value stolen peaked in 2021 and 2022, dipped through the bear market, and has stayed well below those highs. The number of incidents did the opposite, holding steady for years and then climbing sharply. By CoinGecko\u2019s count,<a href=\"https:\/\/www.coingecko.com\/learn\/crypto-hacks-and-exploits-2016-to-2026\"> 2026 logged 164 separate incidents through early August, already more than any full prior year<\/a>, with the next-highest annual figure being 2025\u2019s 97. TRM Labs recorded<a href=\"https:\/\/www.trmlabs.com\/resources\/blog\/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion\"> 207 hacks in just the first half of 2026, more than double the 83 from the same period a year earlier<\/a>, and Blockaid independently verified\u00a0212.<\/p>\n<p>The dollar figures need care, because they are easy to misread as good news. H1 2026 losses came in<a href=\"https:\/\/cryptobriefing.com\/crypto-most-hacked-half-year-1b-stolen\/\"> around $972 million to $1.1 billion<\/a>, below H1 2025. But as TRM\u2019s Ari Redbord noted, that decline happened almost entirely because North Korea did not repeat an operation on the scale of the $1.5 billion Bybit hack. One outlier event in 2025 flattered the year-over-year comparison. Set it aside and the trend is more attacks, spread across more protocols, each taking less. That is a specific signature, and it points to a specific\u00a0cause.<\/p>\n<h3>The evidence for the AI\u00a0thesis<\/h3>\n<p>There is a straightforward economic reading of that signature. If attacks suddenly get cheaper to run, you would expect many more of them, reaching down to targets that were previously too small to bother with. That is what the data shows, and it lines up with what the security firms are measuring directly. TRM reported in August 2026 that<a href=\"https:\/\/www.theblock.co\/news\/web3\/2026-08-21-ai-adoption-in-crypto-crime-trm-412297\"> AI adoption across crypto crime rose 40% year on year<\/a>, and framed the mechanism plainly, AI did not invent new crimes, it removed the constraints on old ones. The skill floor dropped, the scale ceiling lifted, and fake identity went industrial.<\/p>\n<p>The economics were put most directly at the Wyoming Blockchain Symposium, where Global Settlement Network\u2019s Ryan Kirkley observed that it<a href=\"https:\/\/www.theblock.co\/news\/ecosystems\/2026-08-19-ai-agents-todays-billion-dollar-crypto-hacks-look-like-pennies-industry-leaders-412278\"> used to be too costly to hack someone worth $20,000, because the time was not worth it, and that an AI agent can now go after everyone at once<\/a>. Three recent incidents show the range of what that\u00a0enables.<\/p>\n<h4><strong>Small teams overwhelmed by\u00a0volume<\/strong><\/h4>\n<p>In August 2026, two Bitcoin swap services shut down within weeks of each other citing the same cause. Boltz suspended operations, describing months of steadily rising automated, AI-assisted probing that its team could not patch fast enough. Atomiq followed, taking its swap routes offline because, as a small team, it could not fight the numerous sophisticated AI-assisted attacks on its infrastructure.<\/p>\n<h4><strong>Governance nobody was\u00a0watching<\/strong><\/h4>\n<p>On August 23, Term Labs lost about $8.5 million, and the mechanism is worth understanding because no code was broken. Term\u2019s vaults were governed by a token almost nobody had bothered to hold. The attacker simply acquired the governance tokens, which cost a few dollars in vault shares, then held 100% of the vote on five of the drained vaults. He opened a proposal styled to look like a routine parameter update, waited out the six-day minimum, and executed a bundle of 17 actions that recalled every asset into a strategy contract he controlled.<\/p>\n<h4><strong>Scale as the\u00a0point<\/strong><\/h4>\n<p>On August 22, Blockaid detected an ongoing exploit of The Sandbox\u2019s SAND token on Base, where attackers hijacked LayerZero delegate permissions and minted unbacked SAND across hundreds of transactions. The mechanism was a permissions oversight, and the automation is what made it relentless.<\/p>\n<p>The frontier of this is already visible. Researchers disclosed<a href=\"https:\/\/www.theblock.co\/news\/web3\/2026-08-21-ai-adoption-in-crypto-crime-trm-412297\"> JadePuffer, described as the first fully agentic ransomware, where an AI agent ran reconnaissance, credential theft, lateral movement, and encryption end to end<\/a>, and Blockaid flagged a $216,000 exploit of an AI trading agent as the first of its kind, expecting prompt-injection attacks on agents to grow through the\u00a0year.<\/p>\n<h3>Why this is a whole-industry problem, not a crypto\u00a0flaw<\/h3>\n<p>It is worth being precise about what these incidents do and do not say about crypto. Very little of the 2026 record is smart-contract cryptography failing. The two largest H1 losses, Drift at roughly $285 million and KelpDAO at roughly $292 million, both traced to LinkedIn social engineering leading to a compromised multisig signer, the same human-layer attack that hits banks and enterprises. The Bybit hack that defined 2025 was a compromised interface at a wallet infrastructure provider, not a flaw in Ethereum.<\/p>\n<p>And on the pure-code side, the direction is genuinely encouraging. Immunefi\u2019s six-year data shows DeFi protocol losses fell about 80% from the 2022 peak of $2.62 billion to $534 million in 2024, with the median loss per incident dropping from $6 million to $1.5 million even as total value locked grew substantially. The old ecosystem-class attacks, flash-loan oracle manipulations and reentrancy, collapsed from nearly 19% of losses in 2022 to under 1% in 2025. Crypto\u2019s core smart-contract security has been maturing, not decaying. What changed in 2026 is not that the code got worse. It is that AI made probing every layer, especially the human and operational layers, cheap enough to do at scale, and that pressure is arriving everywhere software runs. Crypto simply feels it first, because its infrastructure is open-source, its value is liquid, and its teams are often\u00a0small.<\/p>\n<h3>The defense is the same technology, but access to it is\u00a0gated<\/h3>\n<p>The encouraging half of the story is that the capability driving the attacks is also the strongest available defense. The important qualifier is that this defense is not something a protocol can simply switch on, and that is by\u00a0design.<\/p>\n<p>Anthropic launched<a href=\"https:\/\/www.anthropic.com\/glasswing\"> Project Glasswing on April 7, 2026<\/a> on a deliberate premise. It had built a frontier model, Claude Mythos, that it assessed could surpass all but the most skilled humans at finding and exploiting software vulnerabilities. Releasing that openly would hand the same capability to attackers, so Anthropic did the opposite and distributed it narrowly, to defenders of software whose compromise would be catastrophic. The launch cohort was around 50 organizations and reads like a list of the world\u2019s most critical infrastructure, Apple, Microsoft, Amazon, Google, NVIDIA, JPMorgan Chase, Cisco, CrowdStrike, and the Linux Foundation among them. Access is invitation-only with no self-serve signup, and every organization has to meet Anthropic\u2019s security requirements before it is granted the\u00a0model.<\/p>\n<p>The early results were substantial. In roughly a month, Glasswing partners used the model to find more than 10,000 high- or critical-severity vulnerabilities across systemically important software, including a critical flaw in a cryptographic library used by billions of devices, since patched, and one partner bank used it to detect and stop a fraudulent $1.5 million wire transfer. In May the program expanded to roughly 150 organizations across more than 15 countries, still centered on critical infrastructure in power, water, healthcare, and communications, and the US Federal Reserve and Treasury convened bank leaders over its implications. Anthropic has signaled that a broader, application-based access program for security organizations is in development, but it is not open\u00a0yet.<\/p>\n<p>That gating is why crypto\u2019s entry point matters. In August 2026,<a href=\"https:\/\/www.coindesk.com\/tech\/2026\/08\/17\/kraken-parent-payward-joins-anthropic-s-project-glasswing-for-ai-security-push\"> Payward, the parent company of Kraken, joined Project Glasswing and adopted Claude Mythos for security<\/a>, which makes it one of the first crypto firms known to reach this tier of defensive capability. It is a large, regulated exchange, exactly the profile the program targets, and its inclusion is a signal rather than a broadly available option. Most crypto teams cannot join Glasswing today. What they can do is use the widely available Claude and other AI models for defensive review, adopt the third-party security tooling being built on top of them, and prepare for the moment the capability becomes more accessible, which by Anthropic\u2019s own timeline is months, not years, away for both\u00a0sides.<\/p>\n<h3>How this could\u00a0progress<\/h3>\n<p>Reading the current evidence forward, a few things look likely rather than\u00a0certain.<\/p>\n<h4><strong>Incident counts keep rising before they\u00a0fall<\/strong><\/h4>\n<p>As long as running an attack stays cheap, the frequency stays high, and the targets keep getting smaller. The near-term trend line is more incidents, lower average value, which is the 2026 signature intensifying rather than reversing.<\/p>\n<h4><strong>The human and operational layers become the main battleground<\/strong><\/h4>\n<p>The largest losses of 2026 were social engineering and unwatched governance, not broken math. Hardware-enforced signing, out-of-band verification of large transfers, active governance participation, and multisig hygiene are where the most value can be protected, and where AI-driven phishing will keep applying pressure.<\/p>\n<h4><strong>Defensive AI adoption widens as access opens\u00a0up<\/strong><\/h4>\n<p>Today the most powerful defensive models sit behind gated programs like Glasswing, reaching a handful of large, vetted firms such as Kraken\u2019s parent. But Anthropic expects Mythos-class capability to be available from multiple providers within 6 to 12 months, and is building a broader application-based access path. As that gate widens, running these models on your own systems first shifts from a rare advantage to a baseline expectation, and the teams that prepared their processes early will move fastest when it\u00a0does.<\/p>\n<h4><strong>Patch cadence compresses toward machine\u00a0speed.<\/strong><\/h4>\n<p>When bugs are found in hours, quarter-long patch windows are untenable. The maintainers who keep pace, and the disclosure norms that let them, become as important as the audits themselves.<\/p>\n<p>The honest summary is the one the security firms keep returning to. AI removed the constraints that used to limit attacks, and that will not be undone. But the same technology, in defenders\u2019 hands, finds the same flaws first, and the industries deploying it are moving. Crypto is early to this fight because of how it is built, open, liquid, and lean, and that makes it the clearest place to watch how the balance settles. The goal is not an unhackable system, which has never existed in any industry. It is to close the speed gap, and 2026 is the year that race began in\u00a0earnest.<\/p>\n<h3>Sources<\/h3>\n<p><a href=\"https:\/\/www.theblock.co\/news\/web3\/2026-08-21-ai-adoption-in-crypto-crime-trm-412297\">TRM Labs: AI in crypto crime (via The Block)<\/a> and<a href=\"https:\/\/www.trmlabs.com\/resources\/blog\/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion\"> H1 2026 hacks\u00a0report<\/a><a href=\"https:\/\/www.coingecko.com\/learn\/crypto-hacks-and-exploits-2016-to-2026\">CoinGecko: crypto hacks 2016\u20132026<\/a><a href=\"https:\/\/immunefi.com\/blog\/research\/the-ecosystem-vulnerability-scoreboard-6-years-of-defi-loss-data\/\">Immunefi: six years of DeFi loss\u00a0data<\/a><a href=\"https:\/\/cryptobriefing.com\/crypto-most-hacked-half-year-1b-stolen\/\">Blockaid H1 2026 coverage: CryptoBriefing<\/a>,<a href=\"https:\/\/www.fxstreet.com\/cryptocurrencies\/news\/crypto-hacks-hit-record-high-with-212-exploits-in-h1-2026-202607290212\"> FXStreet<\/a>,<a href=\"https:\/\/primexbt.com\/news\/crypto-hack-incidents-hit-a-record-in-h1-2026-as-losses-pass-1-billion-blockaid\/\"> PrimeXBT<\/a><a href=\"https:\/\/www.theblock.co\/news\/ecosystems\/2026-08-19-ai-agents-todays-billion-dollar-crypto-hacks-look-like-pennies-industry-leaders-412278\">The Block: AI agents and future\u00a0hacks<\/a><a href=\"https:\/\/www.anthropic.com\/glasswing\">Anthropic: Project Glasswing<\/a> and<a href=\"https:\/\/www.anthropic.com\/research\/glasswing-initial-update\"> initial\u00a0update<\/a><a href=\"https:\/\/thehackernews.com\/2026\/05\/claude-mythos-ai-finds-10000-high.html\">The Hacker News<\/a>,<a href=\"https:\/\/techcrunch.com\/2026\/06\/02\/anthropic-scales-claude-mythos-to-critical-infrastructure-in-15-countries\/\"> TechCrunch<\/a>,<a href=\"https:\/\/www.cnbc.com\/2026\/07\/21\/fed-mythos-ai-cybersecurity-banks-project-glasswing.html\"> CNBC<\/a>,<a href=\"https:\/\/www.coindesk.com\/tech\/2026\/08\/17\/kraken-parent-payward-joins-anthropic-s-project-glasswing-for-ai-security-push\"> CoinDesk on\u00a0Payward<\/a><a href=\"https:\/\/thedefiant.io\/news\/defi\/bitcoin-bridge-boltz-halts-swaps-indefinitely-citing-ai-assisted-attacks\">The Defiant: Boltz halts\u00a0swaps<\/a>Incident disclosures:<a href=\"https:\/\/x.com\/term_labs\"> Term Labs<\/a>,<a href=\"https:\/\/x.com\/atomiqlabs\"> Atomiq<\/a>,<a href=\"https:\/\/x.com\/blockaid_\"> Blockaid on\u00a0Sandbox<\/a><\/p>\n<p><a href=\"https:\/\/medium.com\/coinmonks\/2026-cryptos-most-hacked-year-and-the-ai-race-to-defend-it-9ff0a1a17dec\">2026 Crypto\u2019s Most-Hacked Year, and the AI Race to Defend It<\/a> was originally published in <a href=\"https:\/\/medium.com\/coinmonks\">Coinmonks<\/a> on Medium, where people are continuing the conversation by highlighting and responding to this story.<\/p>","protected":false},"excerpt":{"rendered":"<p>TL;DR. 2026 has recorded more crypto exploits than any year on record, over 200 in the first half alone, more than one a day. The dollars stolen are actually lower than 2025, because no single theft matched last year\u2019s $1.5 billion Bybit hack, but the number of attacks has roughly doubled. The driver is AI, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":218234,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-218233","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interesting"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/218233"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=218233"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/218233\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/media\/218234"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=218233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=218233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=218233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}