
The cryptocurrency sector faced unprecedented cybersecurity challenges in April 2026, with two major hacks netting nearly $600 million in just over two weeks. According to reports from Business Standard, the attacks targeted Drift Protocol and Kelp DAO, with the former draining over $280 million and the latter netting almost $300 million. The sophistication of these heists has alarmed cybersecurity experts, who suspect the attackers may have used artificial intelligence to plan and execute their operations.
Investigators at TRM Labs believe the hackers likely employed artificial intelligence to enhance their operations, as reported by Business Standard. Nick Carlsen, a former FBI analyst now at TRM Labs, stated that the sophistication displayed in these attacks is "all stuff North Korea never used to do." The attacks demonstrated a significant leap in criminal sophistication, with hackers spending months building relationships with platform contributors and using sophisticated social engineering techniques to gain access to private systems. The Drift Protocol attack involved creating a fictitious token with inflated trading records to trick the platform's protocols.
The hacking incidents triggered an immediate investor exodus, with $9 billion withdrawn from a lending protocol in just two days following one of the attacks. As reported by Business Standard, this demonstrates how quickly confidence can evaporate even when the platform itself wasn't the direct target. Drift Protocol was forced to shut down and plans to relaunch after receiving stablecoin funding from Tether, while another DeFi project called Carrot announced its shuttering on April 30 due to the incident's aftermath.
The $130 billion decentralized finance sector has become particularly vulnerable to these sophisticated attacks, with exploits reaching a record level in April. According to Business Standard, the number of DeFi exploits nearly doubled from the previous month, with most attacks being small but demonstrating improved criminal capabilities. The fragmented oversight structure of DeFi, where banking regulators don't stress-test cyber defenses like traditional finance, leaves the sector exposed to multiple potential targets and ecosystem-wide ripple effects when platforms are compromised.
Recent developments highlight growing concerns about multi-party computation (MPC) and threshold-signature wallet infrastructure security. THORChain experienced a $10.7-10.8 million vault exploit in May 2026, prompting the protocol to halt trading and signing activities. According to Ledger CTO Charles Guillemet, the incident may involve weaknesses tied to GG20 threshold signature protocol infrastructure, which has historically faced critical vulnerabilities including CVE-2023-33241 and TSSHOCK. Guillemet warns that advances in LLM-assisted vulnerability discovery may reduce the difficulty of compromising validator infrastructure previously considered difficult to attack.