The post Is an AI hacker targeting old DeFi projects in $5M spree? appeared on BitcoinEthereumNews.com. A trio of hacks targeting old DeFi projects have stolen The post Is an AI hacker targeting old DeFi projects in $5M spree? appeared on BitcoinEthereumNews.com. A trio of hacks targeting old DeFi projects have stolen

Is an AI hacker targeting old DeFi projects in $5M spree?

A trio of hacks targeting old DeFi projects have stolen approximately $5 million in the past week.

The three projects targeted were all well-known names during DeFi’s 2020-2022 cycle, and the affected contracts are all from abandoned projects, immutable, or no longer maintained.

The similarities have led some to wonder if legacy contracts are being targeted in a concentrated, AI-aided hacking campaign.

Ribbon Finance flip-flops on recovery plan

Last Friday, Aevo (formerly Ribbon Finance) informed users of an oracle-manipulation hack on “legacy Ribbon DOV vaults,” resulting in a $2.7 million loss. The post reassured Aevo users that they weren’t impacted.

In a since-deleted follow-up post, the team announced a plan to reimburse those affected using $400,000 of its own funds, as well as assets from “dormant” users.

However, the Ribbon team walked back the controversial plan a few days later, clarifying that the affected users would, in fact, suffer a 100% loss.

Read more: Cathie Wood falls for AI slop despite heavy OpenAI, Tempus bets

Defunct Rari Capital hijacked

The $2 million Rari Capital hack occurred on December 10, but was not flagged for a week.

In what appears to be a “hijacking of the implementation contract,” the attacker was able to borrow assets “without posting any collateral.”

Read more: LLM crypto trading contest finds LLMs can’t trade crypto

Following hacks in 2021 and 2022 (for $15 million and $80 million, respectively), Rari Capital ceased operations. According to DeFiLlama data, Rari contracts still contain around $2.7 million of funds.

The team later settled with the SEC in September 2024 over “misleading investors and engaging in unregistered broker activity” as well as unregistered securities offerings.

Yearn Finance: third time’s the charm

On Tuesday, a five-year old iEarn Finance (precursor to Yearn) contract was attacked for approximately $250,000.

Pseudonymous Yearn developer Banteg described how a “misconfigured adapter” caused “a cascading failure across multiple DeFi protocols.”

Read more: DeFi yield aggregator Yearn discloses September incident in yUSND vault

The hack exploited the same vulnerability as a 2023 attack, which saw $11 million lost. Yearn had previously been hacked in 2021, also for $11 million.

In addition to the hacks, Yearn suffered an operational mishap in 2023 in which $1.4 million was lost to “significant slippage.”

Last month, the team also disclosed a malfunction in one of its vaults, with Yearn covering the shortfall.

An AI-supported hacking spree?

Given a generally decreasing rate of smart contract hacks on DeFi protocols, the recent concentration has raised eyebrows.

A security researcher (and former Yearn developer) who goes by storm0x suspects that someone may be “specifically targeting legacy contracts, maybe even using new tools and LLMs?”

They advise withdrawing from 2021-era contracts that are “deprecated, sunsetted or abandoned.”

Another observer shares storm0x’s suspicion. They see the boom in AI support for already sophisticated attackers posing a threat which could be “extremely painful” for DeFi developers in the coming years.

“The bar to build, sample, test, exploit strategies has never been lower,” they said.

As well as AI-supported hackers covering more ground, autonomous AI hacks may also pose a threat in the future.

A recent study from Anthropic pitted AI agents against a library of 405 smart contracts exploited between 2020 and 2025.

The AI models autonomously achieved $4.5 million worth of exploits on contracts deployed after their knowledge cutoff. They also “uncovered two novel zero-day vulnerabilities” in 2,849 new contracts with no known vulnerabilities.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/is-an-ai-hacker-targeting-old-defi-projects-in-5m-spree/

Market Opportunity
null Logo
null Price(null)
--
----
USD
null (null) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
SHIB Price Analysis for February 8

SHIB Price Analysis for February 8

The post SHIB Price Analysis for February 8 appeared on BitcoinEthereumNews.com. Original U.Today article Can traders expect SHIB to test the $0.0000070 range soon
Share
BitcoinEthereumNews2026/02/09 00:26
Solana’s Long-Term Upside Tied to Upgrades, Short-Term Structure Still Weak

Solana’s Long-Term Upside Tied to Upgrades, Short-Term Structure Still Weak

Solana remains caught between strong long-term fundamentals and a fragile short-term technical structure. While the network’s upgrade roadmap points to meaningful
Share
Coinstats2026/02/09 00:28