AI-driven hacks drain $1.46B from Bybit and halt trillion-dollar TradFi blockchain migration
Key Takeaways
AI-powered exploits drained $1.46B from Bybit and $600M from lending pools, creating a security asymmetry that blocks traditional finance institutions from migrating trillions of dollars to decentralized ledgers.
Traditional financial institutions are poised to migrate trillions of dollars in assets onto blockchain networks, yet the escalating threat of AI-driven cyberattacks is halting this transition. Ronghui Gu, CEO of blockchain security firm CertiK, highlighted that while legacy banks envision a future where tens of trillions of dollars operate on decentralized ledgers within a decade, current operational risks remain prohibitive. The primary obstacle is not a lack of interest in efficiency but the inability of conservative capital allocators to mitigate sophisticated threats including smart contract vulnerabilities, oracle manipulation, and cross-chain bridge exploits. This security gap has turned the potential asset migration into a stalled initiative as institutions weigh the efficiency gains against the probability of catastrophic loss.
The intensity of these threats reached a critical peak in April, which CertiK identified as the worst month for security breaches in four years. Data compiled by Woofun AI shows that hacks occurred nearly every single day during this period, with only three days passing without a successful exploit. Gu attributed this unprecedented surge directly to the integration of artificial intelligence in attack vectors, noting that the frequency and sophistication of breaches suggest human-only efforts could not achieve such results. The financial impact of this trend was starkly illustrated by two major incidents in April where North Korean cybercriminals targeted Drift Protocol and Kelp Dao, draining nearly $600 million from these lending crypto pools in separate exploits.
The scale of financial destruction expanded significantly in February 2025 when Bybit suffered a $1.46 billion attack, marking the largest hack in cryptocurrency history. This event underscores the systemic fragility of the ecosystem, as recent data from DefiLlama indicates that more than $1.1 billion was lost to DeFi hacks over the past year. These figures expose how vulnerabilities in cross-chain infrastructure can rapidly propagate, threatening the broader financial ecosystem. The sheer volume of lost capital serves as a warning to traditional finance entities that the current security posture is insufficient for safeguarding institutional-grade assets.
Ronghui Gu characterizes the current landscape as an 'unfair game' where malicious actors hold a distinct structural advantage due to their access to infinite resources. Hackers target protocols with massive total value locked (TVL) because the economic incentives justify pumping immense capital into their operations. A single attacker can easily expend between $10,000 and $20,000 worth of compute tokens to run advanced AI engines that conduct continuous vulnerability scans against a specific protocol for days or weeks. This persistent, automated hunting capability allows attackers to identify and exploit code cracks that intermittent human audits might miss.
In contrast, protocol defenders operate under strict, localized budgetary constraints that limit their ability to match this relentless pressure. Gu explained that with 5,000 clients, security firms must adhere to specific commercial contracts that cap the duration and scope of their audits. When a client requests a scan, the defense team is bound to spend a predetermined amount of tokens and human expert hours within that budget. This creates a massive asymmetry where a defense team might scan a protocol for a few hours, while hacker machines never stop hunting for a single entry point. Woofun AI notes that this structural disparity leaves even well-funded projects exposed to continuous, low-cost automated probing.
The trajectory of these exploits suggests that the speed and efficiency of attacks will continue to accelerate as AI technology evolves. Gu warned that the nearly-daily trend observed in April is likely to persist through the end of the year, posing an existential risk to any institution attempting to move assets onchain without robust, AI-native defense mechanisms. Until the structural imbalance between unlimited attacker resources and constrained defender budgets is resolved, the migration of trillions of dollars from traditional finance to blockchain remains a high-risk proposition. The industry faces a critical juncture where security innovation must outpace offensive capabilities to unlock the full potential of decentralized finance.
Comments