LIVE MARKET DATA SUN 12 JUL 2026 UTC [ VIEW ALL COINS ]
// DeFi

CertiK data: $1.32B lost in H1 2026 as AI scanning revives old contract exploits

H1 2026 losses hit $1.32B as attackers mine years-old bugs in shut-down and dormant protocols, with AI scanners now cutting both ways.

Tomas Keller · ·upd ·3 min read
CertiK data: $1.32B lost in H1 2026 as AI scanning revives old contract exploits

Crypto exploits totaled $1.32 billion in H1 2026, per CertiK data published Monday. The standout signal in the dataset isn’t the headline number — it’s where the losses are coming from: a rising share of attacks are hitting old, previously audited codebases rather than fresh launches.

Legacy infrastructure, live losses

Two separate incidents this June show dead protocols still carry exploitable balances. On June 14, attackers pulled $2.1 million from Aztec Connect through a smart-contract vulnerability — despite the protocol having been shut down since March 2023. Five days later, on June 19, mySwap lost $300,000 to a contract exploit more than six months after its front end had stopped accepting new liquidity deposits.

Not every legacy-code event resulted in a net loss. In May, white hat “0xflorent” recovered 1,003 ETH — roughly $1.72 million at the time — for 48 investors, unwinding a decade-old bug in the auto-refund function of the 2016 Hong Coin ICO after the sale had missed its funding target.

Same tooling, both sides of the trade

The clearest data point on AI-assisted vulnerability discovery came from Zcash. Shielded Labs security engineer Taylor Hornby ran a custom auditing agent built on Anthropic’s Claude Opus 4.8 against the Orchard shielded pool and surfaced a critical bug that had sat undetected for four years — one that could have enabled undetectable counterfeiting inside a core privacy feature before it was patched.

CertiK’s report attributes the broader pattern of attackers revisiting old code to “improved automated tooling for identifying latent vulnerabilities at scale” — tooling that isn’t exclusive to attackers. A December Anthropic study cited in the report found AI agents surfaced $4.6 million worth of exploitable vulnerabilities across smart contracts, underscoring that both offense and defense are now running the same class of scans against a base of more than $72.3 billion in TVL spread across hundreds of DeFi protocols.

What CertiK and TRM Labs are telling operators

CertiK’s operational takeaway is direct: “The window of maximum vulnerability does not close after launch. Projects operating legacy infrastructure should treat reauditing as a recurring operational requirement rather than a one-time exercise conducted at deployment.”

TRM Labs head of policy Ari Redbord told Cointelegraph the data “argues for continuous review rather than a one-time audit,” noting that “attack techniques are moving faster than a single audit from launch day can account for” and that “an audit built for last year’s attack patterns leaves a protocol exposed to this year’s as bad actors are changing up.” He added that hardened contracts only solve half the equation: “Protocols can lock their doors, but someone still has to go after the actor breaking in” — a pointed reference to the continued need to disrupt state-linked hacking groups and laundering networks tied to North Korea and China.

Read more: ADA Drops 5% as EMURGO Exits Pentad Governance After $2.4M SecondFi Hack

Sources

More DeFi

Leave a Reply

Your email address will not be published. Required fields are marked *