AI models led to a ‘vulnerability apocalypse’ in crypto security: Immunefi CEO
Immunefi CEO Mitchell Amador says new AI models are helping attackers faster than defenders, fueling a rebound in DeFi hacks.
Intelligence analysis by GPT-5.4 Mini

Mitchell Amador argues that frontier AI has tilted crypto security toward attackers, calling the current phase a vulnerability crisis. He says the industry has a few hard years ahead unless defenders use the same tools to harden code and reduce exploit windows.
A smarter lock can help both the guard and the thief. This story says new AI tools are helping hackers find weak spots faster, so crypto teams need to learn to use those same tools to build stronger locks before more money disappears.
Analysis
AI is changing the attacker-defender balance
Immunefi CEO Mitchell Amador says the latest frontier AI models have shifted the cybersecurity playing field toward attackers, contributing to a resurgence in DeFi hacks. He described the situation as a vulnerability crisis and pointed to models such as Claude Opus 4.8 and ChatGPT 5.5 as part of the reason the threat environment has worsened in 2026.
The scale of the losses
The article cites DefiLlama data showing that crypto hacking activity surged in April 2026, when illicit actors stole more than $634 million from crypto platforms. That was the highest monthly total since the Bybit hack helped drive losses to roughly $1.4 billion in February 2025. The piece uses those figures to show that security failures remain a major, recurring issue for the sector.
A narrow window for defense
Amador said crypto may need to survive the next three to four years before security teams can fully use these AI tools to build much stronger codebases. In his view, the timeline could shorten to under two years if the industry leans harder on crowdsourced security approaches while researchers adapt the new models for defense.
Why the current concern is acute
The story ties this anxiety to recent DeFi exploits, including a large Kelp DAO bridge drain on April 19 that affected its LayerZero-powered rsETH bridge. LayerZero said the setup created a single point of failure by relying on one verifier path, and said it had previously warned against that configuration. The article also notes that Anthropic’s latest model release prompted fresh concern, with the company saying its safeguards route cybersecurity-related topics to another model.
Key points
- Immunefi CEO Mitchell Amador says new frontier AI models are helping attackers more than defenders right now.
- He links that shift to a resurgence in DeFi hacks and calls it a vulnerability crisis.
- DefiLlama data in the article says April 2026 saw more than $634 million stolen from crypto platforms.
- Amador thinks the industry faces a three-to-four-year survival period unless defenders adapt faster.
- The article uses the Kelp DAO bridge exploit and a recent Anthropic model release as examples of ongoing security concerns.
If security teams use the same AI advances to write and review code, protocols could become much harder to break. Amador also suggests crowdsourced security could help narrow the danger window faster than waiting for in-house teams alone.
If attackers keep adopting new models faster than defenders, DeFi hacks could stay frequent and expensive. The article implies that bridge designs, verifier setups, and other protocol weak points may keep producing large losses until security practices catch up.



