Google’s threat intelligence team said on Sept. 9, 2026 that suspected financially motivated attackers used AI coding tools and agent instructions to plan, build and execute a large-scale credential theft campaign in less than six hours after breaching an organization’s cloud infrastructure. The operation involved thousands of third-party credentials. Google said that time frame did not include the earlier step of obtaining access to the cloud environment.
The case shows AI is already being used in the continuous execution of attack tasks. For crypto companies, that matters because weak points in employee identity checks, developer accounts, vendor systems and transaction approval flows can all become entry points to fund-related permissions.
Google also said some attackers are moving beyond simply asking models questions and are shifting toward agentic workflows and automation tools, cutting down the time spent waiting for human judgment during operations. As attacks move faster, defenders get less time to spot anomalies, confirm risk and act.
Social engineering is getting cheaper to run
Attacks on crypto firms often begin through ordinary business contact. In a warning issued in September 2024, the Federal Bureau of Investigation said North Korea-linked attackers study a target employee’s work history, skills and business interests in advance, then approach them with job offers or investment opportunities. Those conversations can continue for long periods, and the attackers often use fluent or near-fluent English while showing familiarity with crypto industry technology.
These operations were already deceptive before generative AI became widely available. What AI changes is the labor cost of preparing materials, adjusting messages and maintaining multiple lines of contact at the same time.
Anthropic said in August 2025 that North Korean personnel had used Claude to create false professional identities, complete technical hiring tests and deliver real work after obtaining remote roles at U.S. technology companies. Anthropic said AI lowered the English-language and technical training requirements for that activity.
Remote employment fraud and crypto theft are not the same operation. Still, both raise the same question for companies: how to verify the identity of outside personnel and how to assign access rights. A person who can answer technical questions, complete a test or submit code is no longer enough on its own to establish trust.
Based on these cases, AI can help attackers organize target information faster, produce messages that fit a business setting and handle language and technical issues during outreach. For companies, the number of people who require independent verification may rise, while a natural conversation or a polished technical assignment offers less assurance than before.
The window between disclosure and exploitation is narrowing
AI’s effect on cyberattacks also reaches code analysis and exploit development. In an assessment published in May 2025, the UK’s National Cyber Security Centre said AI tools would almost certainly strengthen attackers’ ability to exploit known vulnerabilities by 2027, increase attacks against systems that have not yet been patched, and shorten the time between vulnerability disclosure and exploitation.
The NCSC said AI-assisted vulnerability research and exploit development is likely to become one of the most significant changes in cyber capability during this period. The first impact falls on security problems that already exist. Public vulnerabilities, misconfigurations and outdated software have long served as intrusion paths. If the cost of analysis and exploitation attempts drops, companies also get less time to fix them.
Google’s latest report made a similar point, saying attackers are using models to speed up the conversion of publicly disclosed vulnerabilities into exploit code and to repeatedly refine related components. At the same time, Google said it has not observed attackers deploying a fully autonomous pipeline for zero-day discovery and exploitation against real targets.
That suggests the clearest change right now is the gradual automation of attack stages. Models are taking on more reconnaissance, coding, analysis and debugging work, while skilled operators still handle target selection and key decisions. Tasks that once required larger teams or more time may now be pushed forward faster by smaller groups.
For crypto firms, the highest-risk point is transaction authority
For exchanges, custodians and crypto projects, the severity of a system breach depends on what permissions an attacker can ultimately reach.
In February 2025, Bybit said preliminary forensic findings showed that attackers had obtained the credentials of a Safe developer, entered related infrastructure and induced signers to approve a malicious transaction. Bybit said at the time that the forensic firm it hired found no signs that Bybit’s own infrastructure had been breached.
The incident showed that systems affecting transaction display and approval judgment matter alongside private keys. If multiple signers rely on the same tampered information, adding more signatures may still fail to provide independent verification.
In the Bitget case, Gracy Chen said the preliminary judgment was that a wallet backend system had been compromised and that attackers used it to forge transaction data. She said the incident did not involve private key leakage. Bitget later said the relevant vulnerability had been identified and fixed. Current disclosures do not show that AI was involved in either the Bybit or Bitget attack.
Even so, these cases show the kind of risk AI could amplify. If attackers can study vendors faster, analyze code faster or impersonate business identities more effectively, they may reach permissions with direct impact on funds more often.
Once an unauthorized transfer is confirmed on-chain, an exchange usually cannot reverse it on its own. Restoring servers, resetting employee passwords or fixing a vulnerability does not automatically bring transferred assets back. That is why crypto defense has to cover the full chain from outside contact, devices and code to transaction generation, display and signing.
AI can help defenders too, but automation runs into business limits
AI can also help defenders find problems earlier. In March 2026, Mozilla said its collaboration with Anthropic uncovered 22 security issues that received CVE identifiers, including 14 rated high severity. Mozilla said the issues had been fixed in the latest version of Firefox at the time. The company also said researchers submitted reproducible test cases, allowing engineers to verify the issues quickly and move fixes forward.
This case shows AI-assisted code analysis can produce real defensive gains. Whether those gains are realized depends on whether the findings are accurate, whether they can be reproduced and whether fixes actually enter the engineering process.
Still, defenders face business constraints that attackers often do not. In an article published on Sept. 21, 2026, NCSC Chief Technology Officer for Architecture Dave Chismon said attackers mainly need to overcome technical barriers, while defenders also have to deal with budgets, patch scheduling and change approvals. Even when done for security reasons, an automated block or system change can interrupt normal operations. Companies therefore cannot simply copy the way attackers use autonomous agents.
For exchanges, those constraints are especially concrete. Suspending an account, restricting withdrawals or isolating a system after detecting anomalies can affect users and trading operations. Defense has to move faster, but it also has to limit the damage caused by false positives.
Chismon said companies can start by using AI for information analysis, decision support and tasks with clear scope and easy recovery, then expand automated response step by step. Under that approach, log correlation, anomaly screening and code review can help security teams narrow investigations, while actions involving production systems, fund permissions and transaction execution require clearer authorization and control.
Pressure is building from attack volume and response speed
Public cases already show that AI is lowering the preparation and execution cost of some attacks. That does not mean attackers can now reliably carry out advanced intrusions without human involvement, and it does not prove defenders will necessarily lose their edge.
In its assessment looking toward 2027, the NCSC said a wider gap may open between systems that keep pace with AI-driven threats and the many systems that lag in protection. AI can help attackers find problems, but it can also help system owners fix them. The difference lies in how quickly each side turns those capabilities into action.
For crypto companies, limiting the permissions any single account can reach, separating wallet funds by purpose, independently verifying transaction content and preparing incident response procedures in advance remain basic ways to control losses. AI may improve inspection efficiency, but those controls still determine how far an attacker can move after an employee is deceived or a vendor is compromised.
Based on the cases disclosed so far, the most immediate pressure on companies is that existing vulnerabilities and process flaws may be found faster and tested more often. Better defense has to show up across several stages at once: detecting anomalies, validating risk, completing remediation and limiting the movement of funds.

