Immunefi CEO Links AI Models to Resurgence in DeFi Hacks

Immunefi CEO Mitchell Amador told Cointelegraph at the WAIB Summit in Monaco that frontier AI models, including Claude Opus 4.8 and ChatGPT 5.5, are a main driver behind a resurgence in DeFi hacks, calling it a "vulnerability apocalypse" that now favors attackers. Citing DefiLlama data, Cointelegraph reported that illicit actors stole more than $634 million from crypto platforms in April 2026, the highest monthly total since roughly $1.4 billion in February 2025. Amador said the industry has three to four years to build "impregnable" codebases using the same AI models defensively, a window that could shrink to under two years with faster crowdsourced-security adoption. The warning follows Anthropic's release of Fable 5, which the company says reroutes cybersecurity topics to Claude Opus 4.8.
For security teams and protocol engineers, Immunefi's warning is a rare on-the-record estimate of how much frontier AI models have already changed attacker economics in DeFi: not a hypothetical, but a measurable spike in stolen funds that a leading bug-bounty platform's CEO ties partly to the same models teams already use for coding help.
What happened
Immunefi CEO Mitchell Amador told Cointelegraph at the WAIB Summit in Monaco that the proliferation of frontier AI models, including Claude Opus 4.8 and ChatGPT 5.5, is a main driver behind a resurgence in DeFi hacks in 2026, calling the shift a "vulnerability apocalypse" that favors attackers. Citing DefiLlama data, Cointelegraph reported that illicit actors stole more than $634 million from crypto platforms in April 2026, the highest monthly total since roughly $1.4 billion in losses in February 2025, driven in large part by the Bybit hack. Amador said the crypto industry has a three-to-four-year window to build "impregnable" codebases using the defensive capabilities of the same AI models, a window he said could shrink to under two years if crowdsourced security solutions scale faster.
Industry context
Amador's comments followed Anthropic's release of Fable 5; Anthropic said the model has safeguards that reroute cybersecurity-related topics to Claude Opus 4.8, a response to industry concern that new frontier models could accelerate exploit development. The warning also lands amid a string of large 2026 DeFi exploits, including an April 19 attack that drained roughly $290 million to $293 million in restaked Ether from Kelp DAO's LayerZero-powered bridge; LayerZero said the loss traced to Kelp DAO's single-verifier bridge configuration, which LayerZero had previously advised against.
Technical context
Amador's framing, AI models as an attacker force-multiplier, matches a broader pattern security researchers have described: code-generation and semantic-reasoning improvements in frontier models can shorten the time needed to find and weaponize smart-contract logic bugs compared with fully manual audits. That cuts both ways, since the same capabilities are also being pitched, including by Amador himself, as tools for faster auditing, fuzzing and bug-bounty triage; the practical question for protocol teams is whether defensive-tooling adoption keeps pace with attacker adoption.
For practitioners
For teams building or auditing DeFi protocols, the immediate takeaways are to treat AI-assisted exploit development as a live threat model rather than a future one, to note that bridge and cross-chain verifier misconfiguration (like Kelp DAO's single-DVN setup) keeps surfacing as a recurring root cause independent of AI, and to track whether major model providers add explicit guardrails, the way Anthropic has for Fable 5, around cybersecurity and exploit-adjacent prompts.
What to watch
Watch monthly DefiLlama loss figures for whether April's spike persists or reverses, whether other bug-bounty platforms and auditors corroborate Amador's "vulnerability apocalypse" framing with their own data, and whether more model providers publish safeguards or usage policies specifically addressing smart-contract exploit generation.
Key Points
- 1Immunefi's CEO says frontier AI models like Claude Opus 4.8 and ChatGPT 5.5 are accelerating DeFi exploit development industry-wide.
- 2DefiLlama data shows over $634 million stolen from crypto platforms in April 2026, the highest monthly total since February 2025.
- 3Anthropic's Fable 5 now reroutes cybersecurity-related prompts to Claude Opus 4.8, reflecting industry concern about AI-accelerated exploits.
Scoring Rationale
A well-verified, notable security story: on-record comments from a leading bug-bounty platform's CEO, tied to a specific, sourced figure ($634M in April 2026 losses per DefiLlama) and a concrete industry response (Anthropic's Fable 5 cybersecurity-topic reroute). Relevant to DeFi security practitioners but resting on a single primary outlet and one executive's framing, keeping it in the notable rather than major band.
Sources
Primary source and supporting public references used for this report.
Practice with real FinTech & Trading data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all FinTech & Trading problems


