Blockchain security experts have a warning: your old smart contract audit probably isn’t worth much anymore. AI tooling is helping hackers find vulnerabilities faster than ever.
“Our data argues for continuous review rather than a one-time audit,” TRM Labs head of policy Ari Redbord told Cointelegraph. He said attack techniques are moving faster than any single audit from launch day can account for. An audit built for last year’s attack patterns leaves a protocol exposed to this year’s.
CertiK reported Monday that hackers stole $1.32 billion in the first half of 2026. That’s a 47% drop from last year, but the ecosystem isn’t any safer. Attackers are getting smarter, not stopping. One key strategy: revisiting old codebases with improved automated tooling designed to find latent vulnerabilities at scale.
Recent example: Zcash’s Orchard shielded pool had a bug that went undetected for four years. Shielded Labs engineer Taylor Hornby found it using a custom auditing agent powered by Anthropic’s Claude Opus 4.8. It could have enabled undetectable counterfeiting. Patched now, but the window was wide open for years.
“The window of maximum vulnerability does not close after launch,” CertiK warned. “Projects operating legacy infrastructure should treat reauditing as a recurring operational requirement.”
Anthropic conducted a study in December finding that AI agents found $4.6 million worth of exploitable vulnerabilities in smart contracts. With over $72 billion locked across hundreds of DeFi protocols, the incentive is massive.
Dead protocols are getting hit too. Hackers exploited Aztec Connect for $2.1 million in June, even though it shut down in March 2023. mySwap got drained for $300,000 five days later, months after its UI closed.
The takeaway? One-and-done audits don’t cut it anymore. If your contract’s been sitting untouched for six months, it’s probably worth another look.
