• bitcoinBitcoin (BTC) $ 116,358.00
  • ethereumEthereum (ETH) $ 4,299.79
  • xrpXRP (XRP) $ 2.94
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,028.69
  • solanaSolana (SOL) $ 217.70
  • usd-coinUSDC (USDC) $ 0.999701
  • dogecoinDogecoin (DOGE) $ 0.242739
  • staked-etherLido Staked Ether (STETH) $ 4,299.16
  • tronTRON (TRX) $ 0.339172
  • cardanoCardano (ADA) $ 0.837150
  • wrapped-stethWrapped stETH (WSTETH) $ 5,223.66
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,639.58
  • chainlinkChainlink (LINK) $ 22.23
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 116,347.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • avalanche-2Avalanche (AVAX) $ 30.82
  • hyperliquidHyperliquid (HYPE) $ 47.12
  • stellarStellar (XLM) $ 0.384584
  • suiSui (SUI) $ 3.42
  • bitcoin-cashBitcoin Cash (BCH) $ 590.71
  • wrapped-eethWrapped eETH (WEETH) $ 4,631.63
  • wethWETH (WETH) $ 4,300.79
  • hedera-hashgraphHedera (HBAR) $ 0.220618
  • leo-tokenLEO Token (LEO) $ 9.59
  • litecoinLitecoin (LTC) $ 110.59
  • usdsUSDS (USDS) $ 0.999764
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • usdt0USDT0 (USDT0) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 116,359.00
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • crypto-com-chainCronos (CRO) $ 0.200549
  • the-open-networkToncoin (TON) $ 2.75
  • polkadotPolkadot (DOT) $ 4.09
  • whitebitWhiteBIT Coin (WBT) $ 42.86
  • mantleMantle (MNT) $ 1.86
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • moneroMonero (XMR) $ 300.70
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.201249
  • uniswapUniswap (UNI) $ 7.87
  • daiDai (DAI) $ 1.00
  • aaveAave (AAVE) $ 285.02
  • ethenaEthena (ENA) $ 0.593912
  • pepePepe (PEPE) $ 0.000010
  • okbOKB (OKB) $ 189.80
  • memecoreMemeCore (M) $ 2.35
  • bitget-tokenBitget Token (BGB) $ 5.28
  • nearNEAR Protocol (NEAR) $ 2.81
  • jito-staked-solJito Staked SOL (JITOSOL) $ 268.47
  • aptosAptos (APT) $ 4.62
  • bittensorBittensor (TAO) $ 313.38
  • myx-financeMYX Finance (MYX) $ 15.59
  • ethereum-classicEthereum Classic (ETC) $ 19.02
  • ondo-financeOndo (ONDO) $ 0.921719
  • aster-2Aster (ASTER) $ 1.72
  • worldcoin-wldWorldcoin (WLD) $ 1.31
  • story-2Story (IP) $ 8.98
  • binance-staked-solBinance Staked SOL (BNSOL) $ 234.04
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,299.07
  • paypal-usdPayPal USD (PYUSD) $ 0.999770
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.233103
  • pump-funPump.fun (PUMP) $ 0.006739
  • arbitrumArbitrum (ARB) $ 0.435788
  • internet-computerInternet Computer (ICP) $ 4.38
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.70
  • pi-networkPi Network (PI) $ 0.274764
  • susdssUSDS (SUSDS) $ 1.07
  • kaspaKaspa (KAS) $ 0.077877
  • kucoin-sharesKuCoin (KCS) $ 15.53
  • cosmosCosmos Hub (ATOM) $ 4.22
  • gatechain-tokenGate (GT) $ 16.35
  • vechainVeChain (VET) $ 0.022671
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,917.72
  • plasmaPlasma (XPL) $ 1.07
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030555
  • flare-networksFlare (FLR) $ 0.025787
  • algorandAlgorand (ALGO) $ 0.216409
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,536.12
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 47.21
  • usdtbUSDtb (USDTB) $ 0.999821
  • render-tokenRender (RENDER) $ 3.50
  • sei-networkSei (SEI) $ 0.288541
  • hash-2Provenance Blockchain (HASH) $ 0.034649
  • falcon-financeFalcon USD (USDF) $ 0.999192
  • bfusdBFUSD (BFUSD) $ 0.999208
  • skySky (SKY) $ 0.070580
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,531.36
  • filecoinFilecoin (FIL) $ 2.26
  • bonkBonk (BONK) $ 0.000020
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,646.03
  • zcashZcash (ZEC) $ 94.22
  • official-trumpOfficial Trump (TRUMP) $ 7.57
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.566094
  • tether-goldTether Gold (XAUT) $ 3,875.25
  • jupiter-exchange-solanaJupiter (JUP) $ 0.450380
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 116,367.00
  • immutable-xImmutable (IMX) $ 0.721021
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,553.46
  • xdce-crowd-saleXDC Network (XDC) $ 0.074885
  • wbnbWrapped BNB (WBNB) $ 1,028.89
  • nexoNEXO (NEXO) $ 1.25
  • optimismOptimism (OP) $ 0.689294
  • injective-protocolInjective (INJ) $ 12.37
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 115,772.00
  • pax-goldPAX Gold (PAXG) $ 3,893.60
  • celestiaCelestia (TIA) $ 1.43
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999607
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.13
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 248.21
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,627.38
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998392
  • blockstackStacks (STX) $ 0.594086
  • sonic-3Sonic (S) $ 0.280213
  • lido-daoLido DAO (LDO) $ 1.15
  • curve-dao-tokenCurve DAO (CRV) $ 0.717941
  • msolMarinade Staked SOL (MSOL) $ 288.81
  • spx6900SPX6900 (SPX) $ 1.05
  • aerodrome-financeAerodrome Finance (AERO) $ 1.06
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 116,314.00
  • kaiaKaia (KAIA) $ 0.153524
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.59
  • the-graphThe Graph (GRT) $ 0.084127
  • clbtcclBTC (CLBTC) $ 114,092.00
  • fasttokenFasttoken (FTN) $ 2.02
  • pyth-networkPyth Network (PYTH) $ 0.151705
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 4,097.70
  • flokiFLOKI (FLOKI) $ 0.000084
  • saros-financeSaros (SAROS) $ 0.307355
  • pendlePendle (PENDLE) $ 4.67
  • ripple-usdRipple USD (RLUSD) $ 0.999468
  • conflux-tokenConflux (CFX) $ 0.147386
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,300.54
  • raydiumRaydium (RAY) $ 2.79
  • ether-fiEther.fi (ETHFI) $ 1.45
  • dogwifcoindogwifhat (WIF) $ 0.743318
  • tbtctBTC (TBTC) $ 116,141.00
  • tezosTezos (XTZ) $ 0.691881
  • ousgOUSG (OUSG) $ 112.76
  • global-dollarGlobal Dollar (USDG) $ 0.999680
  • theta-tokenTheta Network (THETA) $ 0.717274
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.10
  • iotaIOTA (IOTA) $ 0.173106
  • galaGALA (GALA) $ 0.015092
  • ethereum-name-serviceEthereum Name Service (ENS) $ 20.66
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997632
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,294.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.08
  • the-sandboxThe Sandbox (SAND) $ 0.273939
  • newton-projectAB (AB) $ 0.008310
  • gtethGTETH (GTETH) $ 4,302.72
  • stader-ethxStader ETHx (ETHX) $ 4,601.87
  • vaultaVaulta (A) $ 0.405504
  • fartcoinFartcoin (FARTCOIN) $ 0.639430
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,299.84
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.84
  • aethirAethir (ATH) $ 0.052016
  • swissborgSwissBorg (BORG) $ 0.642229
  • jasmycoinJasmyCoin (JASMY) $ 0.012977
  • starknetStarknet (STRK) $ 0.145365
  • beldexBeldex (BDX) $ 0.085328
  • jito-governance-tokenJito (JTO) $ 1.63
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.242546
  • morphoMorpho (MORPHO) $ 1.81
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,633.17
  • walrus-2Walrus (WAL) $ 0.402897
  • bittorrentBitTorrent (BTT) $ 0.00000060
  • flowFlow (FLOW) $ 0.363269
  • decentralandDecentraland (MANA) $ 0.301196
  • swethSwell Ethereum (SWETH) $ 4,737.84
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,733.76
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.47
  • zero-gravity0G (0G) $ 2.63
  • usual-usdUsual USD (USD0) $ 0.997907
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 37.72
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,626.13
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 116,406.00
  • dexeDeXe (DEXE) $ 9.29
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.27
  • usdaiUSDai (USDAI) $ 1.04
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • wrapped-avaxWrapped AVAX (WAVAX) $ 30.81
  • wormholeWormhole (W) $ 0.106059
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 47.07
  • true-usdTrueUSD (TUSD) $ 0.999481
  • bitcoin-svBitcoin SV (BSV) $ 24.76
  • loaded-lionsLoaded Lions (LION) $ 0.016088
  • sun-tokenSun Token (SUN) $ 0.025463
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,298.27
  • frax-etherFrax Ether (FRXETH) $ 4,282.70
  • bybit-staked-solBybit Staked SOL (BBSOL) $ 241.34
  • dydx-chaindYdX (DYDX) $ 0.604171
  • usddUSDD (USDD) $ 1.00
  • heliumHelium (HNT) $ 2.50
  • ethena-staked-enaEthena Staked ENA (SENA) $ 0.599751
  • instadappFluid (FLUID) $ 6.04
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999733
  • solmevSolMev (SN116) $ 2,398.72

Bug Bounties Hit Limits as AI Puts Crypto Hackers on Equal Footing

0 2

Bug Bounties Hit Limits as AI Puts Crypto Hackers on Equal Footing

AI has handed crypto attackers the same tools defenders use, and the results are costing the industry billions, experts say.

Mitchell Amador, CEO of Immunefi, told Decrypt during the start of Token2049 week in Singapore that AI has turned vulnerability discovery into near-instant exploitation, and that the advanced auditing tools his firm built are no longer exclusive to the good guys.

“If we have that, can the North Korean Lazarus group build similar tooling? Can Russian Ukrainian hacker groups build similar such tooling?” Amador asked. “The answer is that they can.”



Immunefi’s AI auditing agent outperforms the vast majority of traditional auditing firms, but that same capability is within reach of well-funded hacking operations, he said.

“Audits are great, but it’s nowhere near enough to keep up with the rate of innovation and the rate of the compounding improvement of the attackers,” he said.

With over 3% of total value locked stolen across the ecosystem in 2024, Amador said that while security is no longer an afterthought, projects “struggle to know how to invest and how to allocate resources there effectively.” 

The industry has moved from “a prioritization problem, which is a wonderful thing, into it being a knowledge and educational problem,” he added.

AI has also made sophisticated social engineering attacks dirt cheap, according to Amador. 

“How much do you think that phone call costs?” he said, referring to AI-generated phishing calls that can impersonate colleagues with disturbing accuracy. “You can execute that for pennies with a well-thought-out system of prompts, and you can execute those in mass. That is the scary part of AI.”

The Immunefi CEO said groups such as Lazarus likely employ “at least a few hundred guys, if not probably low thousands working around the clock” on crypto exploits as a major revenue source for North Korea’s economy. 

“The competitive pressures stemming from North Korea’s annual revenue quotas,” drive operatives to protect individual assets and ‘outperform colleagues’ rather than coordinate security improvements, a recent SentinelLABS intelligence report found.

“The game with AI-driven attacks is that it speeds up the rate at which something can go from discovery to exploit,” Amador told Decrypt. “To defend against that, the only solution is even faster countermeasures.”

Immunefi’s response has been to embed AI directly into developers’ GitHub repositories and CI/CD pipelines, catching vulnerabilities before code reaches production, he noted, while predicting this approach will trigger a “precipitous drop” in DeFi hacks within one to two years, potentially reducing incidents by another order of magnitude.

Dmytro Matviiv, CEO of Web3 bug bounty platform HackenProof, told Decrypt that “manual audits will always have a place, but their role will shift.”

“AI tools are increasingly effective at catching ‘low-hanging fruit’ vulnerabilities, which reduces the need for large-scale manual reviews of common mistakes,” he said. “What remains are the subtle, context-dependent issues that require deep human expertise.”

To defend against AI-powered attacks, Immunefi has implemented a whitelist-only policy for all company resources and infrastructure, which Amador said has “arrested thousands of these attempted spear phishing techniques very effectively.” 

But this level of vigilance isn’t practical for most organizations, he said, noting “we can do that at Immuneify because we are a company that lives and breathes security and vigilance. Normal people can’t do that. They have lives to live.”

Bug bounties hit a wall

Immunefi has facilitated over $100 million in payouts to white-hat hackers, with steady monthly distributions ranging from $1 million to $5 million. However, Amador told Decrypt that the platform has “hit the limits” as there aren’t “enough eyeballs” to provide the necessary coverage across the industry.

The constraint isn’t just about researcher availability, as bug bounties face an intrinsic zero-sum game problem that creates perverse incentives for both sides, according to Amador. 

Researchers must reveal vulnerabilities to prove they exist, but they lose all leverage once disclosed. Immunefi mitigates this by negotiating comprehensive contracts that specify everything before disclosure occurs, Amador said.

Meanwhile, Matviiv told Decrypt that he doesn’t think “we’re anywhere close to exhausting the global pool of security talent,” noting that new researchers join platforms annually and progress quickly from “simple findings to highly complex vulnerabilities.”

“The challenge is making the space attractive enough in terms of incentives and community for those new faces to stick around.”

Bug bounties have likely reached their “zenith in efficiency” outside of net-new innovations that don’t even exist in traditional bug bounty programs, Amador added. 

The company is exploring hybrid AI solutions to give individual researchers greater leverage to audit more protocols at scale, but these remain in R&D.

Bug bounties remain essential as “a diverse, external community will always be best positioned to discover edge cases that automated systems or in-house teams miss,” Matviiv noted, but they’ll increasingly work alongside AI-powered scanning, monitoring, and audits in “hybrid models.”

The biggest hacks aren’t coming from code

While smart contract audits and bug bounties have matured considerably, the most devastating exploits are increasingly bypassing code entirely. 

The $1.4 billion Bybit hack earlier this year highlighted this shift, Amador said, with attackers compromising Safe’s front-end infrastructure to replace legitimate multi-sig transactions rather than exploiting any smart contract vulnerability.

“That wasn’t something that would have been caught with an audit or bug bounty,” he said. “That was a compromised internal infrastructure system.”

Despite security improvements in traditional areas like audits, CI/CD pipelines, and bug bounties, Amador noted that the industry is “not doing so hot” on multi-sig security, spear phishing, anti-scam measures, and community protection.

Immunefi has launched a multi-sig security product that assigns elite white-hat hackers to manually review every significant transaction before execution, which it said would have caught the Bybit attack. But he acknowledged it’s a reactive measure rather than a preventative one.

This uneven progress explains why 2024 became the worst year for hacks despite improvements in code security, as hack patterns follow a predictable mathematical distribution, making single large incidents inevitable rather than anomalous, Amador said. 

“There’s always going to be one big outlier,” he said. “And it’s not an outlier, it’s the pattern. There’s always one big hack per year.”

Smart contract security has matured considerably, Matviiv said, but “the next frontier is definitely around the broader attack surface: multi-sig wallet configurations, key management, phishing, governance attacks, and ecosystem-level exploits.”

Effective security requires catching vulnerabilities as early as possible in the development process, Amador told Decrypt. 

“Bug bounty is the second most expensive, the most expensive being the hack,” he said, describing a hierarchy of costs that increases dramatically at each stage.

“We’re catching bugs before they hit production, before they even hit an audit,” Amador added. “It would never even be included in an audit. They wouldn’t waste their time with it.”

While hack severity remains high, Amador said that “the incidence rate is going down, and the level of severity of most of the bugs is going down, and we’re catching more and more of these things in the earlier stages of the cycle.”

When asked what single security measure every project at Token2049 should adopt, Amador called for a “Unified Security Platform,” addressing multiple attack vectors.

That’s essential, as fragmented security essentially forces projects to “do the research yourself” on products, limitations, and workflows, he said. 

“We are not yet to the point where we can handle trillions and trillions of assets. We’re just not quite there at prime time.”

Source

Leave A Reply

Your email address will not be published.