AI-Driven Attacks Fuel Major Crypto Thefts in 2026

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

In 2026, over $600 million was stolen in crypto hacks, with AI systems enabling large-scale attacks. North Korean-linked groups used AI for social engineering, deepfakes, and automated vulnerability scanning, leading to major breaches at Kelp DAO, Drift Protocol, and Zerion. AI's role has amplified the scale and sophistication of these incidents.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions AI being used in social engineering attacks that resulted in theft, AI-powered deepfakes and voice manipulation tools sold for bypassing security, and autonomous AI agents conducting attacks. These uses of AI have directly caused significant financial harm, fulfilling the criteria for an AI Incident. The harms are realized, not just potential, and the AI systems' development and use are pivotal in enabling these attacks. Therefore, this event is classified as an AI Incident.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital securityFinancial and insurance services

Affected stakeholders
ConsumersBusiness

Harm types
Economic/PropertyReputational

Business function:
ICT management and information security

AI system task:
Content generationEvent/anomaly detection


Articles about this incident or hazard