Immunefi CEO Mitchell Amador said at WAIB Summit that a new generation of AI models, including Claude Opus 4.8 and ChatGPT 5.5, is changing the balance between cyber attackers and defenders. According to Amador, these models have tilted the cybersecurity landscape toward attackers and contributed to a rebound in crypto hacking activity in 2026.
April thefts reached the highest monthly total since the Bybit hack
Data from DefiLlama shows that illicit actors stole more than $634 million from crypto platforms in April 2026. That figure marked the highest monthly total since February 2025, when the Bybit hacking incident drove losses to about $1.4 billion. Amador linked the rise in pressure on crypto security teams to the capabilities of newer AI models, describing the industry as entering a period in which defensive systems must be rebuilt for a faster attack environment.
Amador said the crypto industry is facing a critical survival period over the next three to four years, until security teams can use the same class of AI models to build codebases that attackers cannot break. He added that if the industry adopts more crowdsourced security solutions, that timeline could be shortened to under two years. Immunefi operates as a bug bounty platform, placing it directly within the field of crowdsourced vulnerability reporting and security review.
Anthropic safeguards and the Kelp DAO bridge incident
AI company Anthropic’s latest Claude Mythos model, Fable 5, previously raised concerns over its ability to accelerate the exploitation of crypto vulnerabilities. Anthropic said Fable 5 includes safeguards and will redirect topics such as cybersecurity to Claude Opus 4.8. The company’s response shows that restrictions have been built around how its AI models handle security-related subjects.
One major incident cited in the broader context of April’s losses occurred on April 19, when an attacker transferred about 116,500 restaked Ether tokens, rsETH, out of Kelp DAO’s LayerZero-based rsETH bridge. The assets were valued at about $290 million to $293 million at the time. Cross-chain protocol LayerZero said Kelp DAO’s 1/1 decentralized verifier network configuration relied on a single verification path to process cross-chain messages, creating a single point of failure.

