
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
In 2026, over $600 million was stolen in crypto hacks, with AI systems enabling large-scale attacks. North Korean-linked groups used AI for social engineering, deepfakes, and automated vulnerability scanning, leading to major breaches at Kelp DAO, Drift Protocol, and Zerion. AI's role has amplified the scale and sophistication of these incidents.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions AI being used in social engineering attacks that resulted in theft, AI-powered deepfakes and voice manipulation tools sold for bypassing security, and autonomous AI agents conducting attacks. These uses of AI have directly caused significant financial harm, fulfilling the criteria for an AI Incident. The harms are realized, not just potential, and the AI systems' development and use are pivotal in enabling these attacks. Therefore, this event is classified as an AI Incident.[AI generated]