MACROKremlin silent as Zelenskiy cites 30,000 North Korean troops bound for VoronezhJul 27, 2026
WORLDCXMT soars 466% on debut, briefly claiming China's most valuable listed slot in mainland's biggest IPO since 2010Jul 27, 2026
CRYPTOTriple-A treasury breach: $11.8M in losses confirmed, client funds intactJul 27, 2026
CRYPTO$52.5M crypto sale gives World fresh capital for Sam Altman's iris-scanning identity projectJul 27, 2026
ENERGYChina industrial profit growth slows again in June as oil prices retreatJul 27, 2026
WORLDHamas names Khalil al-Hayya political bureau chief after nearly two years without a leaderJul 27, 2026
REGULATORYDSA co-chair backs abolishing Senate, ICE and borders as Democratic infighting deepensJul 26, 2026
DEALSPCSIX declares $0.0502 monthly cash dividend, payment set for July 23Jul 26, 2026
MACROKremlin silent as Zelenskiy cites 30,000 North Korean troops bound for VoronezhJul 27, 2026
WORLDCXMT soars 466% on debut, briefly claiming China's most valuable listed slot in mainland's biggest IPO since 2010Jul 27, 2026
CRYPTOTriple-A treasury breach: $11.8M in losses confirmed, client funds intactJul 27, 2026
CRYPTO$52.5M crypto sale gives World fresh capital for Sam Altman's iris-scanning identity projectJul 27, 2026
ENERGYChina industrial profit growth slows again in June as oil prices retreatJul 27, 2026
WORLDHamas names Khalil al-Hayya political bureau chief after nearly two years without a leaderJul 27, 2026
REGULATORYDSA co-chair backs abolishing Senate, ICE and borders as Democratic infighting deepensJul 26, 2026
DEALSPCSIX declares $0.0502 monthly cash dividend, payment set for July 23Jul 26, 2026

AI is eroding crypto audit shelf life, researchers warn

Millions of dollars in customer funds have been drained from defunct decentralized finance protocols, with hackers exploiting codebases that passed their original security reviews. Researchers warn that AI is now compressing the period in…

By Sofia Almeida·Jul 9, 2026·1 min read·crypto

Millions of dollars in customer funds have been drained from defunct decentralized finance protocols, with hackers exploiting codebases that passed their original security reviews. Researchers warn that AI is now compressing the period in which a completed audit can be trusted. The two pressures, stale certified code and faster automated vulnerability discovery, are arriving together.

Defunct protocols as a recurring target

Hackers have found a repeatable approach in the codebases of protocols that have shut down or gone dormant. The code remains deployed on-chain; the audit certification stays on file. The team that could respond to a newly discovered exploit class is no longer present. Researchers flag the combination as a structural gap in how the DeFi sector accounts for post-audit risk.

The shelf-life problem

Security audits have always been point-in-time assessments. Researchers warn that AI tools are accelerating the pace at which new vulnerability classes emerge, shortening the gap between a clean audit result and a viable attack path. An audit accurate at publication does not automatically cover attack methods that AI-assisted scanning can develop and test at speed. The implication is that the industry's current audit cadence may be calibrated against a threat model that no longer holds.

Related reading

Share
Source: NewsMeter
© 2026 NewsMeter

Key takeaways

Frequently asked

Why are defunct DeFi protocols a target for hackers?

Their code remains deployed on-chain and the audit certification stays on file, but the team that could respond to a newly discovered exploit is no longer present, creating a structural gap in post-audit risk.

How is AI affecting the reliability of security audits?

AI tools are accelerating the pace at which new vulnerability classes emerge, shortening the gap between a clean audit result and a viable attack path.

What is the 'shelf-life problem' described by researchers?

It is the idea that security audits are point-in-time assessments whose trustworthiness is being shortened because an audit accurate at publication does not cover new AI-assisted attack methods.

What two pressures are arriving together according to the article?

Stale certified code from defunct protocols and faster automated vulnerability discovery driven by AI are converging at the same time.