DeFi platforms have lost $20 billion in total value locked since the start of the year, according to DeFiLlama. Part of that decline tracks the broader market downturn, but repeated protocol breaches and rising concern over security flaws have also weighed on user confidence.
Over the past 12 months, more than $1.1 billion in assets has been lost across DeFi security incidents. The losses are large, and the trust damage is hard to ignore. In April 2024, the Kelp DAO hack led to a $292 million loss and highlighted major weaknesses in cross-chain infrastructure. Earlier in 2024, Solana-based Step Finance suffered a $27 million hack and later shut down.
Cross-chain weaknesses remain a major pressure point
The disclosed cases point to a familiar problem: cross-chain systems continue to carry elevated risk. The Kelp DAO incident was tied to a cross-chain vulnerability, an area where multiple contracts and asset routes can widen the attack surface. Step Finance showed a different side of the same issue. A single major exploit was enough to end the platform’s operations.
For DeFi, the issue goes beyond the size of any one hack. Public smart contract code has long been part of the sector’s transparency model, yet users are now warning that the same openness can be turned against protocols when attackers can scan and act faster than human teams.
AI is entering the exploit pipeline
A risk highlighted by Araoz is that attacks are no longer driven only by humans. Advanced AI agents are starting to enter the field. The report points to Anthropic’s Claude Mythos, a model described as being able to locate software vulnerabilities on its own and instantly produce working exploit code. Anthropic says the model performs far beyond current automated security tools in this area.
That changes the pace of attacks. Vulnerability discovery, exploit creation, and launch can be compressed into a much shorter window. For DeFi projects that still rely heavily on human review, manual response, and patching after exposure, that creates a much harder defense environment.
Existing defense models were built for human attackers
Experts cited in the report argue that DeFi’s current security foundations were designed to deal with human adversaries, not ultra-fast AI systems. The threat model has shifted. Risk assessment and defense mechanisms now face pressure to adapt, because human-led response teams can struggle to keep up when machine-driven systems move at much higher speed.
The latest figures show that this is not only a story about direct asset losses. It is also a challenge to the way DeFi security is structured, tested, and maintained as the sector deals with falling locked value and growing concern over protocol resilience.

