AI Attack Accelerates: On-Chain Asset Security Raises Red Flags

CN
9 hours ago

AI is no longer just a tool for increasing productivity; it is accelerating the pace at which network attacks are evolving, spreading from traditional internet companies to the world of on-chain assets. Recently, around 100 companies, including OpenAI, Anthropic, Google, Microsoft, AWS, Cloudflare, CrowdStrike, Cisco, Visa, and Oracle, jointly signed an open letter, raising the cybersecurity threats posed by AI to a cross-industry collective alarm, calling for a reshaping of defensive capabilities in the new technological environment. Almost simultaneously, CrowdStrike CEO George Kurtz publicly warned on August 28, 2026, that the rapid development of AI is making attacks faster and more complex, revealing weak defenses even in companies with substantial security budgets. He specifically mentioned that Anthropic's Mythos model has significantly increased attack efficiency and security demands. Just as the traditional internet world was starting to realize that defenses were being generally elevated, the CCC token on BSC rang a more immediate alarm in the on-chain world—attackers exploited the sell() function in contracts to destroy tokens from the LP liquidity pool, resulting in approximately $117,000 in losses, highlighting that the design of smart contracts itself is a high-risk exposure in the context of new technologies. Three clues, unfolding one after another: cross-industry signing, industry-level warnings from leading security companies, and specific on-chain attack cases are converging to turn "AI amplifying attack risks" from an abstract topic into a real scenario, thus entering a high-pressure period where the security of encrypted assets must be re-examined.

Joint Open Letter from Hundreds of Companies: AI Security Becomes a Cross-Industry Alarm

At the upstream of this wave of security anxiety is an open letter signed by about 100 companies. According to existing materials, the initiators of this letter span multiple technological and business fronts: on one end are labs like OpenAI and Anthropic that directly shape model capabilities, and on the other are giants like Google, Microsoft, and AWS that control computing power and cloud infrastructure. Surrounding these are companies in cybersecurity and cloud protection like Cloudflare, CrowdStrike, and Cisco, as well as participants deeply embedded in global payment and enterprise systems, such as Visa and Oracle. The open letter clearly identifies "the amplification of network attack threats by AI technology" as a common concern, calling for strengthened network defenses under this premise, although the specific release time and complete signature list have yet to be disclosed, leaving only the outline of this singular source of information to understand the level of pressure it releases.

What is truly alarming is not the number of technical terms repeated in the letter, but its elevation of AI security from an internal issue within a particular industry to a cross-industry systemic risk alert. When model developers and cloud vendors acknowledge that attack methods will be accelerated by AI, when security companies admit defensive lines are being compressed, and when participants in finance, payment, and enterprise services are willing to include themselves in the same risk statement, the traditional defensive framework's "slow iteration and localized reinforcement" approach appears particularly out of place. Past security efforts assumed the evolution of attack methods was gradual; today, large models can generate more complex social engineering scripts, exploit paths, and attack scripts in a short time, turning the evolution of attack and defense into a race between "model version vs defense version." The key signal conveyed by this joint open letter is that, in the face of AI-driven attack speeds, the defensive pace of individual companies and single industries is already difficult to match, and security problems are being rewritten into a long-term offensive and defensive war across industries and infrastructures.

CrowdStrike Warns: AI Attack Speeds Up

After the joint open letter elevated AI risks to a cross-industry height, specific warnings from front-line security vendors provided a clearer outline for this offensive and defensive race. On August 28, 2026, according to media reports, CrowdStrike CEO George Kurtz stated in an interview that the rapid rise of AI is exposing weak links in enterprise network security, “even companies that invest heavily in security may be pierced by AI-driven attacks.” In his description, attackers leverage model-generated scripts and optimized utilization paths to make attacks faster and more complex, while traditional defense methods focused on piling up security products and expanding security teams are being forced to fail.

Even more impactful is his specific mention of Anthropic's Mythos model, believing that such tools are further accelerating the speed and complexity of network attacks and driving up market demand for cybersecurity solutions. Security vendors are starting to publicly view specific large models as "accelerators" of attacks, indicating that the defensive side is no longer just worried about the general AI capabilities being widespread, but is incorporating specific models into the threat landscape. However, current publicly available materials do not disclose the technical details of Mythos, nor is there direct evidence attributing any specific attacks to this model; such judgments mainly remain at the level of risk assessment and market expectations. Nevertheless, for boards and security teams, such directional statements can sufficiently change the starting point for budget and strategic discussions: security investments may shift from one-off projects to long-term operations centered around AI offense and defense, while defensive thinking must transition from "preventing every intrusion" to "continuously improving detection, response, and recovery capabilities in the new normal of AI-accelerated offense and defense."

AI Offense and Defense Increase Costs: On-Chain Projects Are Involved

As boards begin to allocate long-term budgets for AI offense and defense, the risk landscape is no longer confined to corporate intranets. The signatories of this open letter span AI developers, cloud and security infrastructure giants, and payment institutions, meaning that both offense and defense are layering stronger technology stacks, and the same set of technological logic necessarily extends to the on-chain world, which holds substantial assets. On BSC, the CCC token encountered a smart contract attack; attackers exploited the sell() function in the contract to destroy tokens from the LP liquidity pool, with AiCoin data showing losses of approximately $117,000. This incident does not point to a specific AI tool's involvement, but during the same period that models like Anthropic's Mythos were mentioned as "making attacks faster and more complex," practical cases like CCC objectively expand security anxieties of the AI era from server rooms to DeFi pools and smart contract addresses.

On-chain protocols inherently expose authority rules and functions embedded in code. If there is a design flaw in role assignment, key function call conditions, or parameter validation, it can be exploited by attackers, a consensus background frequently mentioned in public security research. In the face of more complex attack tools, such "errors written into the chain" will only be more quickly scanned, combined, and amplified, while traditional auditing processes and rule-based security tools are mostly designed for relatively slow human attack and defense rhythms, making it difficult to prepare for scenarios where "attackers have large models behind them." For on-chain project teams, security assessments must incorporate the AI perspective in advance, treating the assumption that "attackers can quickly enumerate contract function relationships, simulate LP behaviors, and generate multiple payloads" as a basic premise. Although there is currently a lack of sufficient on-chain quantitative data to prove that "AI attacks are systematically sweeping the crypto industry," the way cases like CCC are being discussed indicates that on-chain attacks are transitioning from isolated incidents into windows viewed as trend signals, leading the security narrative in the crypto industry to shift from "fixing every contract vulnerability" to "ensuring the overall resilience of protocols in an environment of AI-accelerated offense and defense."

Exploitation of CCC on BSC: Sell Function Breach

Returning to the CCC attack on BSC itself, the contract details are actually very "simple"—the problem lies in a seemingly ordinary sell() function. The open path shows that attackers locked onto the sell() entry in the CCC related contract and directly affected the LP liquidity pool through this function, destroying pool tokens without obstruction, leading to approximately $117,000 in losses. In other words, the LP pool became the passive party "bleeding," and ordinary token holders had little reaction time during the sudden collapse of price and depth, only to face the results of asset shrinkage and impaired exit pathways afterward.

From the existing information, this is not a failure of any specific chain's underlying infrastructure but a typical case of design oversight at the smart contract level being precisely exploited: a function was granted too much power but lacked sufficient security boundaries. The materials do not disclose the attacker's identity, specific timing, or whether the project team has made any effective subsequent repairs, nor is there evidence indicating that this attack was directly prompted by any specific AI model or tool. However, in the context of AI-accelerated offense and defense, such events of "sell() function breaches" are essentially tangible examples of security vulnerabilities being concentrated and amplified—once the weakest link is exposed in the public contract, the asset security of the entire protocol will become immediately unreliable.

AI Gray Rhino Approaches: Crypto Security Enters a Tense Period

From the joint open letter signed by about 100 cross-industry companies, which raised AI risks to a common alert, to CrowdStrike CEO George Kurtz specifically mentioning that the Anthropic Mythos model "makes attacks faster and more complex," and then to the CCC token on BSC suffering losses of about $117,000 due to the design of the sell() function, these three signals from different industries and scenarios are resonating in the same direction: AI is pushing existing offense and defense structures toward a new imbalance point. It forms a slow but continuously approaching "gray rhino" between the world of traditional enterprise IT and crypto contracts, not a fictional hacker legend, but a risk profile that has gradually materialized through open letters, industry leaders' voices, and on-chain empirical cases. For the crypto industry, the direction of response is already relatively clear: contract audits should no longer focus solely on syntactical and logical checks but should actively introduce the perspective of "can AI automate the discovery and exploitation of vulnerabilities"; permission designs must anticipate AI-driven large-scale scanning and automated exploitation, setting more refined defenses for key functions, LP resources, and governance entries; monitoring and warning systems need to assume that attack paths are more complex, speeds are faster, and to lay the groundwork for identifying behavioral patterns and anomalous function calls on-chain in advance. Meanwhile, variables that are worth continuous tracking have already emerged: whether there will be more complex attack cases targeting smart contracts, whether traditional security vendors will start forming stable collaboration mechanisms with on-chain projects, and whether the industry will institutionalize responses to AI security threats in audit standards, compliance requirements, and protocol governance—evolutions in these dimensions will determine whether the "AI gray rhino" is merely a controllable risk identified in time or evolves into a long-term structural pressure that shapes the security landscape of crypto assets.

Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink