
DeFi security researchers are warning that artificial intelligence is tipping the scales in favor of hackers over defenders after a particularly rough stretch of exploits this year. According to reports from The Block, CertiK co-founder and CEO Ronghui Gu revealed that in April alone, there were only three days without hacks, with more than $690 million hacked from DeFi protocols. If the February 2025 Bybit exploit is excluded, April marked the highest monthly financial loss from DeFi hacks since March 2022. Gu made these remarks during an interview with The Block's Gareth Jenkinson at the Consensus Miami conference, emphasizing the unprecedented scale of recent attacks.
Gu attributed much of the recent surge to AI tools that are making it easier for attackers to discover vulnerabilities and replicate attacks across protocols. As reported by The Block, he called this "an unfair game" because attackers can pour computing resources into probing a single protocol for weaknesses while security firms are forced to spread resources across dozens of clients. The CEO noted that because smart contract auditing standards have improved significantly, hackers are now going after security and supply-chain vulnerabilities instead of code flaws. "Smart contracts become safer, so hackers look for supply chain, operational security, and so on," Gu explained, adding that "the industry and most projects right now don't pay enough attention to this."
The April incidents included attacks on Drift Protocol and Kelp DAO that together accounted for nearly $600 million in losses. According to The Block, Drift Protocol suffered an exploit estimated at around $280 million, later linked to an admin takeover tied to suspected North Korean attackers. Kelp DAO's $292 million exploit similarly stemmed from infrastructure and governance failures, with attackers compromising a LayerZero validator setup before routing stolen assets through Aave. These attacks gave security experts a closer look at how attackers are shifting their strategies from traditional code vulnerabilities to operational security weaknesses.
Gu warned that legal fallout from the Arbitrum asset freeze could complicate future industry-wide hack response efforts. As reported by The Block, the controversial freeze of roughly $72 million in assets by Arbitrum became tied up in legal disputes after plaintiffs from separate North Korean terrorism judgments sought to claim the funds as restitution. The CEO emphasized that the industry needs to work together to react as fast as possible to reduce losses and coordinate token freezes. "The industry needs to work together," Gu said, highlighting the complex incident responses that require protocols, blockchain, and exchanges to coordinate freezes and recoveries against bad actors.