AI Hacking Just Got Automated: Is Crypto at Greater Risk?
0
0
Key Insights:
- AI hacking tools can now automate steps that previously took human hackers weeks to complete.
- 2026’s three largest crypto hacks used the same approach demonstrated by OpenAI’s models.
On Tuesday, OpenAI disclosed that its most advanced models, GPT-5.6 Sol and an unnamed, more advanced pre-release model, were tasked with completing a multi-step hacking benchmark widely known as ExploitGym. Their safety restrictions were deliberately lowered for this task. Those models completed the task and also went beyond the planned test environment.
OpenAI called the incident “unprecedented.” The concern for crypto is not that AI attacked a blockchain. It’s that AI hacking can now process complex hacking tasks, highlighted by that incident. That’s a serious risk for crypto because successful hacks cannot be reversed.
What the Models Actually Did
OpenAI posted a blog describing the incident, along with highlighting the same attack patterns in major crypto attacks in 2026. The models were operating in an isolated test environment with limited network access.
To break out of that environment, they found and exploited a zero-day vulnerability. It is a software flaw that was previously unknown. After gaining access, AI models increased their permissions by using additional techniques. Besides, those models moved through the system until they reached a machine with internet access.
Once connected to the open internet, the models identified Hugging Face as a possible source of the benchmark’s answer key. They combined stolen credentials with additional zero-day vulnerabilities to gain a path into Hugging Face’s production servers. Hugging Face’s own security team and AI agents detected the attack and started forensic reconstruction before OpenAI’s teams made contact.

OpenAI wrote, “We are implementing strict controls in infrastructure configuration at the cost of research velocity while the vulnerabilities are patched,”. Hugging Face CEO Clem Delangue called the collaboration that followed “a point we’ve long believed: AI safety won’t be solved by any single company working in secret.”
Crypto AI Hacking and the Attack Playbook
The connection to crypto is not just theoretical; it actually highlights similar attack patterns seen in major hacks. OpenAI’s models independently found weaknesses, gained access, moved across systems, and reached live infrastructure using stolen credentials. This is the same process observed across many crypto attacks.
Drift Protocol lost $285 million in April 2026, as Chainalysis reported. Attackers gained access through a long social engineering campaign, compromised an admin key, manipulated price oracles, and drained assets within minutes.
The LayerZero Labs KelpDAO Incident Report revealed that the liquid restaking protocol suffered a $292 million DeFi exploit. Attackers compromised bridge infrastructure. They created false withdrawal requests to move funds from multiple chains.
The official BONK X handle also revealed that a BONK attacker bought enough tokens to pass a malicious governance proposal and transfer $20 million from the treasury. Each attack relied on identifying system weaknesses rather than directly breaking the rules.

Major crypto hacks often require finding flaws, mapping systems, gaining access, gathering credentials, and lengthy human-intensive social engineering. All these steps mentioned can be automated and completed by AI, highlighted by a recent demonstration of OpenAI.
Security researchers warn that AI does not need to create new attack methods; it can make existing attacks faster, scalable, and easier to execute across multiple targets. While the final step of fund movement still requires human effort, the human-intensive, time-consuming middle steps can now be automated and processed faster.
What Comes Next: The AI Hacking Nobody is Discussing
Crypto developers rely on the same public repositories, cloud infrastructure, and package platforms used by Hugging Face’s environment. A zero-day in that layer doesn’t target a smart contract directly. Instead, it targets the environment in which the smart contract is built, tested, and deployed, before a security audit even takes place. That is the serious risk highlighted by the OpenAI demonstration, which is missing from the current crypto security discussion around AI hacking.
OpenAI stated that they are now working with Hugging Face to further investigate the incident. It has responsibly disclosed the zero-day flaw to the affected vendor.
OpenAI also added Hugging Face to its cyber defense program. The firm also published a separate blog post about improving safety in long-term AI deployments. It will share additional findings as the investigation continues.

It is still unclear whether this incident will change AI regulations, security testing methods, or how DeFi security teams prepare for threats. What’s clear is that AI systems with reduced safeguards demonstrated the ability to independently combine identification of flaws, zero-day exploits, credential theft, privilege escalation, and lateral movement into a successful infrastructure breach. Every major crypto hack in 2026 used at least three of those five steps to reach the stolen funds.
The post AI Hacking Just Got Automated: Is Crypto at Greater Risk? appeared first on The Coin Republic.
0
0
Securely connect the portfolio you’re using to start.
