A year ago, the market was holding its breath in anticipation: artificial intelligence, according to many analysts' forecasts, was expected to trigger an avalanche of attacks on DeFi protocols. However, as practice shows, these fears did not materialize. Hasib Qureshi, managing partner at venture firm Dragonfly, noted that despite a record number of incidents, the median damage from hacks in 2026 fell below the $500,000 mark.

For comparison: a year earlier, this figure was around $2 million. This trend is direct evidence that the threat from AI was overestimated. Attackers armed with machine learning algorithms have indeed become more active, but their targets have shifted.

Where are AI hackers striking?

As Qureshi emphasizes, the main targets for AI-powered attacks have become small or abandoned projects. Large DeFi protocols, on the contrary, have managed to significantly strengthen their defenses. They have implemented automated monitoring systems, improved smart contract audits, and actively use AI for their own protection, making them much less vulnerable.

Essentially, the market has adapted faster than many expected. The median damage of $500,000 is certainly no cause for celebration, but it demonstrates that the wave of large, catastrophic hacks predicted by pessimists never materialized. Instead, we are seeing a rotation of threats: hackers have switched to less protected, but also less liquid, projects.

My comment: The decline in median damage is a positive signal for institutional investors who are still eyeing DeFi. However, it is too early to relax. AI is a double-edged sword: if large protocols have managed to build defenses, it remains a serious challenge for small projects. The market must continue to invest in security, otherwise the next wave of attacks could be far more sophisticated.