In this news:
"Call it what it is: these exploits remain rooted in social engineering and human error. AI didn't create that reality. It made it visible, and accelerated it to machine speed. The only real exit is a hardware root of trust: private keys generated and kept on a certified secure element, with a trusted display and Clear Signing," Guillemet said.
A double-edged blade
The same techniques, however, also work to protect the code itself. Pendle, a DeFi yield protocol, said it has used Anthropic's models defensively since the first version of Claude Opus. The team uses AI to map its codebase and stress-test its contracts, including freshly deployed ones. It says the tools catch bugs early and help it write cleaner code.
Smart contracts are the wrong thing to be concerned about, Pendle's developers said in an interview over Telegram. A smart contract is short and has only about a dozen entry points. Good auditors have long been able to hold a contract's full state in their heads and test every edge case.
"There are really not that many lines of code in a smart contract to audit," the developer team said.
Which means the next major crypto hack may not look new. It will probably look be the same poisoned package, fooled developer or bad signing flow DeFi already knows.