MACRO10-year Treasury yield reaches 5.07 percent, highest since 2007Oct 1, 2026
FPHFive Point Holdings Extends Great Park Development Agreement to 2028Oct 1, 2026
$BTCBitcoin Dips 3.2% as Clarity Act Vote Fails in SenateOct 1, 2026
EARNINGSOshkosh Backlog Slides 3.3% Year Over Year Amid Margin PressureOct 1, 2026
WORLDMaine poll shows Collins leads Jackson by 3 pointsOct 1, 2026
WORLDFDA nominee Heidi Overton declines to call healthcare a human rightOct 1, 2026
WORLDFox News outdraws CNN and MS NOW combined in Q3 2026Sep 30, 2026
RVPRetractable Technologies declares quarterly preferred dividendsSep 30, 2026
MACRO10-year Treasury yield reaches 5.07 percent, highest since 2007Oct 1, 2026
FPHFive Point Holdings Extends Great Park Development Agreement to 2028Oct 1, 2026
$BTCBitcoin Dips 3.2% as Clarity Act Vote Fails in SenateOct 1, 2026
EARNINGSOshkosh Backlog Slides 3.3% Year Over Year Amid Margin PressureOct 1, 2026
WORLDMaine poll shows Collins leads Jackson by 3 pointsOct 1, 2026
WORLDFDA nominee Heidi Overton declines to call healthcare a human rightOct 1, 2026
WORLDFox News outdraws CNN and MS NOW combined in Q3 2026Sep 30, 2026
RVPRetractable Technologies declares quarterly preferred dividendsSep 30, 2026

AI is eroding crypto audit shelf life, researchers warn

Millions of dollars in customer funds have been drained from defunct decentralized finance protocols, with hackers exploiting codebases that passed their original security reviews. Researchers warn that AI is now compressing the period in…

By Reuben Salcedo·Jul 9, 2026·1 min read·crypto

Key takeaways

  • Millions of dollars in customer funds have been drained from defunct decentralized finance protocols by hackers exploiting codebases that had passed their original security audits.
  • Researchers warn that AI is compressing the period during which a completed audit can be trusted by accelerating the discovery of new vulnerability classes.
  • Defunct or dormant protocols are a recurring target because their code stays deployed on-chain and audit certifications remain on file while the team that could respond is gone.
  • Security audits are point-in-time assessments that do not automatically cover attack methods AI-assisted scanning can develop and test after publication.
  • Researchers suggest the industry's current audit cadence may be calibrated against a threat model that no longer holds.

Millions of dollars in customer funds have been drained from defunct decentralized finance protocols, with hackers exploiting codebases that passed their original security reviews. Researchers warn that AI is now compressing the period in which a completed audit can be trusted. The two pressures, stale certified code and faster automated vulnerability discovery, are arriving together.

Defunct protocols as a recurring target

Hackers have found a repeatable approach in the codebases of protocols that have shut down or gone dormant. The code remains deployed on-chain; the audit certification stays on file. The team that could respond to a newly discovered exploit class is no longer present. Researchers flag the combination as a structural gap in how the DeFi sector accounts for post-audit risk.

The shelf-life problem

Security audits have always been point-in-time assessments. Researchers warn that AI tools are accelerating the pace at which new vulnerability classes emerge, shortening the gap between a clean audit result and a viable attack path. An audit accurate at publication does not automatically cover attack methods that AI-assisted scanning can develop and test at speed. The implication is that the industry's current audit cadence may be calibrated against a threat model that no longer holds.

Related reading

Share
© 2026 NewsMeter

Frequently asked

Why are defunct DeFi protocols a target for hackers?

Their code remains deployed on-chain and the audit certification stays on file, but the team that could respond to a newly discovered exploit is no longer present, creating a structural gap in post-audit risk.

How is AI affecting the reliability of security audits?

AI tools are accelerating the pace at which new vulnerability classes emerge, shortening the gap between a clean audit result and a viable attack path.

What is the 'shelf-life problem' described by researchers?

It is the idea that security audits are point-in-time assessments whose trustworthiness is being shortened because an audit accurate at publication does not cover new AI-assisted attack methods.

What two pressures are arriving together according to the article?

Stale certified code from defunct protocols and faster automated vulnerability discovery driven by AI are converging at the same time.