Report: Unverified smart contracts become a new target for attackers, with $36.7 million stolen in six months
According to a report by Chainalysis, over the past six months, at least $36.7 million has been stolen from protocols with unverified source code, involving protocols such as Truebit, Trusted Volumes, Aperture Finance, and Ekubo. Attackers are searching for vulnerabilities by decompiling the original bytecode. AI-assisted vulnerability exploitation development is accelerating this trend, as large language models can scale the identification of vulnerability patterns.
Chainalysis points out that unverified contracts lack community review and are often excluded from bug bounty programs. The barrier to AI decompilation and vulnerability analysis is rapidly decreasing, allowing attackers to systematically scan thousands of unverified contracts. Protocols should verify all contract code, audit the contracts actually deployed, expand the coverage of bug bounties, and implement real-time on-chain monitoring. Each unverified contract is a potential target for automated scanning, and relying solely on obfuscation as a security measure is no longer effective.
You may also like
BIS Report Compliance Observation: The Real Risks of Stablecoins, Not Just "Depegging"
When American giants collectively "defect" from Chinese AI models
A pre-announced harvesting case: After the cryptocurrency price dropped by 99%, the public chain Saga exited to transform into AI
Ethereum Foundation Report: A Basic Guide to Ethereum for Governments and Financial Institutions
Portugal 2-1 Croatia: Ronaldo's 20-Year Knockout-Stage Drought Ends With a Debt Finally Collected
Portugal beat Croatia 2-1 in the 2026 global football championship's knockout rounds as Ronaldo scored his first-ever knockout-stage goal, Gonçalo Ramos struck a stoppage-time winner, and VAR ruled out a late equalizer for offside.
Bitcoin Price Prediction July 2026: Will BTC Recover to $70K or Drop Below $55K?
A South Korean company that learned the strategy of hoarding coins, from a bull market to delisting?
Where is Zhao Changpeng's billion-dollar investment going? YZi Labs' investment landscape fully revealed
Semiconductor stocks plummet, yet Anthropic wants to create a 2nm chip
WEEX API Broker Program: Turn Your Trading Platform Into a Revenue Engine
How to choose between buying discounted ETH, Bitmine, and SharpLink?
Do you want to buy CRCL?
Wosh: Inflation has cooled in recent weeks, AI is reshaping the economy, and forward guidance has lost its necessity
The most secretive AI winner
Looking at Stripe's ambitions and the future of stablecoins from OUSD
From Pump.fun to Collector Crypt: Has Solana's income throne changed hands?
Dan Bin's latest speech: Don't miss out on a great era
Robinhood launches its own blockchain, no longer wanting to be a tenant on others' chains
BIS Report Compliance Observation: The Real Risks of Stablecoins, Not Just "Depegging"
When American giants collectively "defect" from Chinese AI models
A pre-announced harvesting case: After the cryptocurrency price dropped by 99%, the public chain Saga exited to transform into AI
Ethereum Foundation Report: A Basic Guide to Ethereum for Governments and Financial Institutions
Portugal 2-1 Croatia: Ronaldo's 20-Year Knockout-Stage Drought Ends With a Debt Finally Collected
Portugal beat Croatia 2-1 in the 2026 global football championship's knockout rounds as Ronaldo scored his first-ever knockout-stage goal, Gonçalo Ramos struck a stoppage-time winner, and VAR ruled out a late equalizer for offside.



