Peebles Contact us

AI & Agentic Commerce

AI and Agentic Commerce - The Impact on Security

How AI is reshaping the DeFi attack surface, and how the security industry is fighting back.

Ian Wallis July 2, 2026 7 min read

TL;DR

  1. AI cut the cost of attack, not just defense. Phishing site production is up to 100x versus 2025; hacking tooling is now open-source and unrestricted.
  2. The attack surface moved off-chain. 76% of 2025's losses ($2.2B) came from infrastructure attacks - keys, supply chain, social engineering - versus 24% from smart contract exploits.
  3. Security vendors are going agentic too. Continuous vulnerability mining, zkTLS verification, and AI-assisted-but-human-verified pipelines are the emerging response.
  4. Institutions are pricing in the risk. Blue-chip DeFi is trading fee income for a "hyper secure" posture, with insurance and loss-protection funds emerging as a new layer.

This is the second article covering research across 60 interviews with leaders in the agentic AI, tokenization, and security spaces - read the first, on the rise of the Machine Economy. Download the full Q2 report here.

Peebles brand illustration: a padlock inside a shield, set within a translucent globe with guardrail latitude and longitude lines, captioned 'Secure AI agents for enterprises.'
PeeblesSecure AI agents for enterprises.

DeFi Under Attack

DeFi composability is under attack. AI made hacking infinitely easier and cheaper. Opus 4.6 changed everything when it was released in December 2025, and hackers now have access to unlimited tokens via open-source models where guardrails are bypassed easily. Script kiddies have multiplied their output and are now producing 1,000 phishing sites at a time in 2026, versus 10 phishing sites at a time in 2025.

"Sophisticated phishing and impersonation are on the rise, as AI makes it easy to target individuals with social engineering campaigns. We have seen phishing campaigns increase by 100x in 2026 due to the use of AI tooling. Organizations need to be proactive about identifying and removing impersonators to protect their end users from scams." Nikita Varabei, CEO, ChainPatrol

The attack surface has shifted off-chain, with 76% of 2025 losses ($2.2B) coming from infrastructure attacks - compromised keys, supply chain manipulation, social engineering - and 24% attributed to smart contract exploits. Attackers are leveraging AI to target phishing, pig butchering, admin key management, infiltration of trusted execution environments, malicious transactions, oracle manipulation, smart contract code vulnerabilities, and more.

"Security in web3 is evolving at lightning speed. It seems just like yesterday that we reviewed code manually and that was the gold standard of security. Since then more necessary layers were added like on-chain monitoring, formal verification, and now agentic solutions. Despite the effort, $3.4 billion was stolen in 2025 - much of it from code that had already cleared an audit - and more than $1 billion was gone in the first four months of 2026 alone. The number one source of exploits has shifted from smart contracts to OpSec-related vulnerabilities like bad key management, misconfigurations, and social engineering." Tobias Vogel, CEO, Consensys Diligence

Bug-bounty platforms are cracking under AI-generated submission volume, and many have closed down or are providing significantly reduced payouts, demoralizing the whitehat community. Similar pressures are bearing out in the web2 world, with a recent Instagram attack where malicious actors took over a host of high-profile Instagram profiles using video fakes.

How the Security Industry Is Fighting Back

Developers using AI, and the security providers protecting them, face a triple whammy:

Nevertheless, the industry is responding by utilizing advanced AI techniques in their own services - more advanced phishing and impersonation detection, network and invariant monitoring, transaction simulations, and malicious transaction detection, among others. Vendors are solving for security-at-scale with things like zkTLS-based documentation verification, vulnerability mining marketplaces, expert-triage workflows, and AI-assisted-but-human-verified pipelines.

"Security can't be a snapshot. The next layer is agentic intelligence that mines for vulnerabilities continuously, ingesting security researchers' wisdom and allowing security researchers to analyse previously infeasibly large projects in a matter of days. Consensys Diligence has recently released our agentic vulnerability mining service here." Tobias Vogel, CEO, Consensys Diligence

How Is DeFi Responding?

Participants in our research noted that blue-chip DeFi projects are now prioritising security above everything else. Strategies are evolving to be "hyper secure," with a focus on protection even if it means sacrificing bps or fees. Large institutions cannot price DeFi risk and cannot bear any reputational risk. ETF providers, for example, need to guarantee redemptions and are leaning on insurance products to ensure protection from slashing risks and other risks. The DeFi United crowdfunding of loss protection on Aave is a precursor to having insurance funds set up to protect DeFi users.

"At Blockaid we are seeing AI transform the security industry. Malicious players are utilizing AI to increase their attacks on users, protocols, and organizations. We are also seeing AI drive new security requirements, with agentic wallets requiring sophisticated security layers to protect agentic funds. As an example, MetaMask recently announced they are using Blockaid to secure the MetaMask Agent wallet." Glenn Rachlin, VP Worldwide GTM, Blockaid

The Caveat

This is a reminder that crypto is the most adversarial environment on the internet. It is open source, so attackers can review the code and test out vulnerabilities. It is permissionless, so attackers have access anytime they want. And it is decentralised, so attackers can exit via their chosen routes without fear of funds being returned or transactions reversed. Do your own research.

Methodology & sources

Peebles Q2 2026 Research Report - 60 interviews with agentic AI, tokenization, and security leaders, April–June 2026. Full report at peebles.co.

Nikita Varabei (CEO, ChainPatrol), interview quote, Peebles Q2 2026 research programme.

Tobias Vogel (CEO, Consensys Diligence), interview quotes, Peebles Q2 2026 research programme.

Glenn Rachlin (VP Worldwide GTM, Blockaid), interview quote, Peebles Q2 2026 research programme.

Consensys Diligence, agentic vulnerability mining service announcement, metamask.io.