Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

AI-Assisted Hackers Drain $36.7M From Hidden Smart Contracts in 2026

Chainalysis warns that AI-powered tools are helping attackers reverse-engineer hidden smart contract code, exposing vulnerabilities across the crypto ecosystem.

Written By Isha Chavda
Fact Checked by Divya Mistry
Published 2026-06-10·Updated 4 months ago
Make The Crypto Times preferred on GoogleGoogle
AI-Assisted Hackers Drain $36.7M From Hidden Smart Contracts in 2026
Show AI Summary
Attackers stole $36.7 million from DeFi protocols over six months by exploiting unverified contracts
Major incidents occurred between January and May 2026, with the largest attack on Truebit on January 8
Vulnerabilities were identified in unverified contracts, including integer overflows and access-control flaws, from 2021 onwards

A growing number of crypto hackers are targeting unverified smart contracts, exploiting vulnerabilities hidden within closed-source code and stealing millions of dollars in the process.

According to a new security brief released by blockchain analytics firm Chainalysis, attackers have stolen approximately $36.7 million from five major decentralized finance (DeFi) protocols over the past six months by exploiting vulnerabilities in contracts whose source code was never publicly verified.

The findings suggest that advances in artificial intelligence and smart contract decompilation tools are making it easier than ever for attackers to reverse-engineer hidden code and identify exploitable weaknesses.

The four major exploits

Chainalysis identified four key incidents involving unverified protocol contracts between January and May 2026.

The largest attack targeted Truebit on January 8, resulting in losses of approximately $26.2 million. Investigators said the exploit stemmed from an integer overflow vulnerability inside the protocol’s bonding curve mechanism.

Other incidents included Trusted Volumes, which saw $5.9 million stolen through an access-control flaw. Aperture Finance: $3.2 million lost through an input validation bypass in January, and Ekubo saw $1.4 million stolen after a callback function failed to verify the payer’s identity in May.

In every case, the affected contracts were unverified on block explorers and lacked publicly available source code at the time of exploitation. Notably, this represents only a small portion of the more than $1 billion stolen from DeFi protocols during the same period, but the trend is what matters.

Truebit exploit highlights a growing threat

The Truebit attack has become one of the most notable examples of the trend.

According to Chainalysis, the vulnerable contract had been deployed since 2021 and remained unverified on Etherscan. Attackers allegedly exploited an integer overflow bug within the protocol’s pricing mechanism, allowing them to mint hundreds of millions of tokens for almost no cost before redeeming them for real ETH.

Investigators also discovered evidence suggesting the attacker had been systematically hunting vulnerable contracts before escalating to the multi-million-dollar exploit.

“This was not an opportunistic find,” Chainalysis noted, adding that the attacker appeared to be testing vulnerabilities across multiple protocols before executing the larger attack.

AI rewrites the economics of exploitation

Chainalysis argues that advances in artificial intelligence may be accelerating this trend. Modern decompilation tools can convert EVM bytecode into readable Solidity-like code. Once reconstructed, that code can be analyzed by large language models capable of identifying common vulnerability patterns, including reentrancy flaws, access-control failures, and arithmetic errors.

Researchers increasingly believe attackers are building automated pipelines capable of scanning thousands of contracts simultaneously and prioritizing targets based on exploitability and potential profit.

According to the report, what previously required days of manual reverse engineering can now be partially automated at scale.

Why attackers like unverified contracts

While unverified contracts require additional effort to analyze, they also offer significant advantages to attackers.

Unlike verified contracts, closed-source deployments receive little scrutiny from independent researchers, white-hat hackers, or competitive auditors. Many are also excluded from bug bounty programs, reducing the likelihood that vulnerabilities will be discovered and responsibly disclosed before exploitation.

As a result, attackers often face less competition when searching for exploitable flaws.

The report suggests that some protocols mistakenly assume hiding source code improves security, even as modern tooling continues to erode that advantage.

Recent exploits highlight broader security risks

The Chainalysis findings come amid a series of major crypto security incidents that have exposed vulnerabilities across smart contract and bridge infrastructure.

Earlier this week, Humanity Protocol disclosed that attackers compromised administrator keys controlling parts of its bridge system, stealing more than $36 million worth of H tokens and minting hundreds of millions of additional tokens on BNB Chain. The incident triggered a sharp selloff, with the H token losing roughly 80% of its value.

Meanwhile, Syscoin paused its bridge operations after a validation flaw allowed an attacker to create approximately 5 billion unauthorized SYS tokens. The project has since implemented a fix and coordinated with exchanges to track and restrict the affected funds.

While these incidents differ from the unverified smart contract exploits highlighted by Chainalysis, they demonstrate how weaknesses in smart contract infrastructure, bridge validation systems, and administrative controls continue to present significant security risks across the crypto ecosystem.

Chainalysis concludes that protocols should treat source code verification as a minimum security standard rather than an optional feature.

The firm recommends verifying all production contracts, expanding bug bounty coverage, auditing deployed code rather than development versions, and implementing real-time monitoring capable of detecting suspicious on-chain activity before losses escalate.

As AI-powered analysis tools continue improving, protocols relying on hidden code may increasingly find that secrecy alone is no longer enough to protect user funds.

Also read: Bleak May 2026: Over $60M Stolen, $20B TVL Melt, and DeFi’s “Unsafe” Reckoning

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Artificial Intelligence (AI)Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Curve DAO Token (CRV) physical coin positioned in front of a green financial chart background.
CRV Jumps Over 10% to $0.38 as Trading Activity Increases
Coinbase and VanEck 3D app icon blocks side-by-side on a reflective dark surface.
Coinbase Wallet Adds Polymarket to Its Crypto App Ecosystem
U.S. Securities and Exchange Commission (SEC) official seal mounted on a stone wall exterior.
SEC Charges Entities Over Alleged $15M Crypto and AI Investment Fraud
Turnkey and Wealthsimple partnership graphic displaying both brand logos connected by a collaboration emblem.
Wealthsimple Launches Self-Custody Wallet for DEX Trading in Canada
Smartphone displaying Aave token price metrics and a green chart held in front of an illuminated Aave logo.
AAVE Price Jumps 16% to $169 as Rally Tests $175 Resistance

Find Us on Socials

You may also like

Aave ghost mascot holding a purple Monad token against a repeated Monad and Aave logo pattern.

Aave Proposes Monad V4 Hub for Tokenized Equity Lending

Blockaid Warns Token Metadata Can Expose AI Agents to Crypto Attacks 

Blockaid Warns Token Metadata Can Expose AI Agents to Crypto Attacks 

An illuminated blue Coinbase logo on a dark wall beside a breached metallic vault spilling gold Bitcoin coins onto the floor.

Coinbase Accused of Hiding Hack Losses and $25M in Unrepaid Client Funds 

A physical silver Ethereum coin standing upright in front of a blue illuminated Bitget logo on a reflective dark surface.

Bitget Reopens ETH Withdrawals, Reports 651 ETH Net Inflow in First Hour After $387.5M Hack

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information