State of AI in DeFi Security

State of AI in DeFi Security

AI is no longer an experiment in smart-contract security. It is already finding vulnerabilities, winning security competitions, earning bug bounties, and running against production code.

But there is an important distinction the industry is still learning:

What is true today — defect location vs full attack path (a16z, Apr 2026)
AI ALREADY DOES Point at the defect Flags the weak code path Root cause ID is reliable STILL FAILS AT Plan the attack path Full tx sequence · leverage loops Capital · composition · profit proof

In 2026, we have seen AI systems reproduce historical exploits, win major audit competitions, earn six-figure bug bounties, find issues in heavily reviewed codebases, generate adversarial tests, and operate continuously inside security workflows — and we have also seen where they still break down.

2026 is the year AI security stopped being hypothetical

For a long time, “AI auditing” largely meant putting Solidity into a chatbot and asking “Find vulnerabilities.” That is no longer the frontier.

Modern security agents can navigate repositories, compile code, run tests, inspect traces, interact with forked chains, generate exploit code, modify contracts, and iterate on hypotheses. The strongest evidence is no longer a demo — it is real security outcomes.

2026 timeline — from benchmarks to bounty leaderboards
FEB SPRING SUMMER AUG OCT EVMbench 117 vulns OpenAI × Paradigm Frosty Coinbase AI Continuous layer $100K+ Octane bounty + Monad #1 Aave study 71 → 20 valid 0 Crit/High OCT 2026 GregoAI reaches #17 on Immunefi — 3 Critical, 5 High, $197K+ #17

Octane

$100K

Immunefi bounty from an AI-powered engine. First place in the $500K Monad competition — 3 of 4 highs, human-in-the-loop.

Blockian

$250K

Maximum-critical Immunefi bounty as an AI-assisted finding. Immunefi highlighted the result.

GregoAI

#17

AI agent on Immunefi’s leaderboard — 3 Criticals, 5 Highs in 2026, more than $197K earned.

The AI security stack is becoming much more sophisticated

The biggest change is not simply better models. It is the emergence of security agents with tools, memory, workflows and feedback loops.

Cantina's Apex reported that across 1,610 production runs, doubling compute produced roughly 40% more validated findings — sub-linear scaling. 74% of scans were still improving at the budget they were given.

Compute vs validated findings — sub-linear scaling
Findings Compute budget → Linear (ideal) ~40% more findings per 2× compute Observed (Apex) Linear reference 74% of scans still scaling at stop

Old question

“Which auditor should review this code?”

New question

“How much adversarial search should we run — and when is more search no longer worth the cost?”

AI is also becoming a continuous security layer

Coinbase's Frosty (April 2026) showed AI can run in roughly one to two hours at a fraction of manual-audit cost — optimized for high-signal detection and triage, not as a replacement for expertise.

Point-in-time audit vs continuous AI layer
POINT-IN-TIME AUDIT dev mainnet One expensive entry Context rebuilds each time CONTINUOUS LAYER AI agent always in loop PR upgrade oracle collateral deploy Reviews every meaningful change

Less interesting

AI replaces a six-week audit.

More interesting

AI reviews the code every time the code changes.

Aave is perhaps the clearest evidence that AI works best as a layer

Aave Labs (August 2026) ran three AI security tools against V3 and V4 after more than 340 days of cumulative security review — manual audits, formal verification, invariant testing, fuzzing, and a six-week public contest.

Aave AI findings funnel — raised → validated → severity
71 findings raised 20 accepted after validation 0 Critical / High 100% 28% Low / Info only

Human review was required to separate real issues from false positives, duplicates, and correct behaviour under the protocol's trust model. AI should strengthen the stack — not displace it.

The biggest problem with AI security is not finding bugs

It is understanding which bugs matter.

From surface finding to economic impact
On-chain price Easy to detect HARD QUESTIONS Liquidity · capital · flash loans Atomicity · slippage · fees Exit path to liquid assets Protocol loss? Economic proof
  • How much liquidity exists behind that price?
  • Can an attacker move it — and with what capital?
  • Can that capital be obtained through a flash loan?
  • Can the manipulated price be consumed before rebalance?
  • Does the attack remain profitable after slippage and fees?

We have already seen AI struggle with exactly this

a16z crypto gave an agent a contract address, block number, forked Ethereum, Etherscan, and Foundry — then measured success on historical price-manipulation cases.

a16z experiment — answer-key leakage vs isolated environment
0 10 20 10/20 With future tx leakage 2/20 Isolated — 10% success Profitable PoCs on historical price-manipulation cases

Real-world exploit benchmarks are much harder

CyberChainBench evaluates agents on 541 real-world DeFi exploit incidents across nine EVM chains — detection, exploitation, and patching under reconstructed historical conditions.

CyberChainBench — best reported configuration
Detection 37.5% Exploitation 43.7% Patching 23.4% 0% 50% 100%

Progress is real. The gap is equally real — especially on patching.

Detection is not exploitation

Three different problems
1 · DETECT Name the weak point “Accounting issue here” 2 · EXPLOIT Prove attacker value State · txs · profit 3 · PATCH Close without regressing Hardest of the three

A protocol does not lose money when an AI points at defective code. It loses money when an attacker plans the full attack path — the transaction sequence that converts the weakness into real value.

Patching may be harder than finding

Cantina's Apex Fix Review covered 1,258 reviews / 644 findings / 51 repos. Of 193 client PRs with final verdicts, 62 produced 97 issue-category findings — fix still reachable, or a new security problem introduced.

Fix review outcomes — closed ticket ≠ closed vulnerability
193 PRs with final verdicts 62 → 97 PRs with fix-category issues Still reachable · or new problem

That is why an AI security workflow needs a fix-verification loop, not just a finding-generation loop.

AI is beginning to specialize for security

On October 1, Cantina released Apex Flash-1 — an open-weights security model post-trained with GRPO on verified exploit trajectories. Coding models and security models optimize for opposite outcomes.

Different training objectives
CODING MODEL Make it work Pass tests · ship features ≠ SECURITY MODEL Make it fail Unanticipated paths · exploit trajectories

The whitehat ecosystem is changing too

AI is not only used by protocols — it is used by the people hunting them. Agentic submissions now sit on the same Immunefi leaderboards as human researchers.

Both sides get continuous search
Defenders AI in CI / audit loop Protocol Static audit ages faster Hunters AI on bounty boards

What this means for protocol teams

A realistic 2026 stack is layered coverage — not a single audit checkbox.

Layered security stack
LAYER 01 Human research depth Economics · trust model LAYER 02 AI adversarial search Breadth · every change LAYER 03 Exploit verification Prove real impact LAYER 04 Fix verification Close without regressing

Teams that treat AI as a layer — not a substitute — get the upside without the false confidence.

Message us on Telegram