Millions of dollars in customer funds have been drained from defunct decentralized finance protocols, with hackers exploiting codebases that passed their original security reviews. Researchers warn that AI is now compressing the period in which a completed audit can be trusted. The two pressures, stale certified code and faster automated vulnerability discovery, are arriving together.
Defunct protocols as a recurring target
Hackers have found a repeatable approach in the codebases of protocols that have shut down or gone dormant. The code remains deployed on-chain; the audit certification stays on file. The team that could respond to a newly discovered exploit class is no longer present. Researchers flag the combination as a structural gap in how the DeFi sector accounts for post-audit risk.
The shelf-life problem
Security audits have always been point-in-time assessments. Researchers warn that AI tools are accelerating the pace at which new vulnerability classes emerge, shortening the gap between a clean audit result and a viable attack path. An audit accurate at publication does not automatically cover attack methods that AI-assisted scanning can develop and test at speed. The implication is that the industry's current audit cadence may be calibrated against a threat model that no longer holds.