The story examines a series of repeated exploits against an AI-driven DeFi “agent” protocol used by organizations, documented by rekt.news, and highlights how design choices around autonomous smart agents and permissive access were framed by the protocol’s creator as “expected behavior” rather than a critical vulnerability. According to the post, the protocol—wired directly into organizational treasuries and other on-chain operations—was exploited roughly a dozen times beginning in 2025, with one attacker reportedly using Anthropic’s Claude as a core tool to identify and orchestrate nine separate breaches. The background is the rapid rise of AI-managed DeFi tools and “agentic” protocols that can autonomously manage funds, execute strategies, and plug into multiple chains or protocols via generalized permissioning. In several 2025–2026 incident reviews, security researchers and exchanges noted that a growing share of losses came from logic flaws and integration bugs in these AI or agent-based systems, where the code behaved “as designed” but that design allowed untrusted actors to redirect funds or escalate privileges. In this particular case, the project’s own documentation and responses treated the exploitable behavior as part of the intended architecture, creating a gray zone where attackers could plausibly argue they were just using available features while still draining user and treasury funds. The story matters because it illustrates how AI-assisted attackers and AI-governed protocols are colliding: on one side, cheap, capable models like Claude are making it easier to audit and weaponize smart contract flaws; on the other, protocols are delegating more control to autonomous agents with broad access and weak guardrails. Industry reports for 2025–2026 already show that most DeFi losses now come from protocol logic weaknesses rather than simple bridge or flash-loan exploits, and several analyses warn that a significant fraction of those could be discovered and executed autonomously by AI systems. The rekt.news investigation uses this recurring exploit pattern to argue that calling exploitable behavior “by design” is no longer tenable in an environment where AI tools can repeatedly and systematically abuse those designs across multiple organizations.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on AI

Comments