Wall Street’s trillion-dollar dilemma: Why AI-powered hackers are keeping big banks off the blockchain
CertiK says institutional crypto adoption is being slowed by near-daily DeFi hacks, many amplified by AI. April was its worst month in four years.
Intelligence analysis by GPT-5.4 Mini

CertiK’s Ronghui Gu says banks want to move trillions onchain, but repeated DeFi exploits, smart-contract flaws, oracle attacks, and bridge hacks are making that shift look too risky.
Big banks want to move money onto a new kind of internet money system because it can be faster and cheaper. But they are scared, because thieves keep finding holes in the code.
Think of it like moving treasure into a house that still has broken locks. If the locks keep failing, the treasure owners will wait before bringing in more gold.
The story says the thieves may be using smart tools to hunt for weak spots faster. That makes the defenders’ job harder, and it can slow down how fast big money joins the blockchain.
Analysis
Security is the bottleneck
CertiK CEO Ronghui Gu says traditional financial institutions are interested in putting large amounts of capital onchain, but security failures are still the main obstacle. In his view, the pitch is simple: blockchain infrastructure could eventually carry trillions of dollars, but conservative institutions will not move money into systems that are still being hit by frequent exploits.
April’s hack streak
Gu said CertiK saw hacks on almost every day in April, with only three days without an incident. He described it as the worst month in four years and argued the pace and scale of recent attacks suggest AI is helping attackers find weaknesses faster. The article points to vulnerabilities in smart contracts, oracle systems, and cross-chain bridges as recurring weak spots.
A resource mismatch
The article frames the situation as a structural imbalance. Attackers can keep scanning for flaws for days or weeks and can justify spending thousands of dollars in computing resources if a target holds enough value. Defenders, by contrast, work within limited project budgets and finite review windows. Gu says CertiK serves many clients, but each review is still bounded by cost and time, while attackers can keep pressing until they find a mistake.
The piece highlights several examples to show the size of the problem: the Bybit hack in February 2025, which it says was worth $1.46 billion, and attacks on Drift Protocol and Kelp Dao that drained nearly $600 million combined in April. It also cites DefiLlama data showing more than $1.1 billion lost to DeFi hacks in a year. The larger takeaway is that security failures are no longer isolated incidents; they are a system-level risk that can slow the bridge between DeFi and TradFi.
Key points
- CertiK says institutional interest in moving assets onchain is growing, but security risks remain a major blocker.
- Gu said April was the worst month in four years for DeFi exploits, with hacks on 27 of 30 days.
- The article highlights smart contracts, oracle manipulation, and cross-chain bridges as common weak points.
- It says attackers can outspend defenders on continuous scanning and exploit hunting.
- Recent large losses, including Bybit and DeFi protocol hacks, are used to show the scale of the problem.



