Weekly Brief | 06.11.26
 
 
Chainalysis Research and Analysis
 
 

Smart contract security has long relied on a community-driven ecosystem of white hat researchers, competitive audits, and public code review. But a growing class of protocols is operating outside this safety net entirely, deploying unverified contracts whose source code is never made public. New on-chain data reveal that attackers are increasingly targeting these opaque protocols, likely accelerated by AI-assisted exploit development that can identify vulnerability patterns at scale.

  • Over the last six months, at least $36.7 million has been stolen from protocols whose source code was never publicly verified, forcing attackers to decompile raw bytecode to identify exploitable vulnerabilities.
  • The rise of large language models (LLMs) is likely accelerating this trend, enabling attackers to systematically identify vulnerability patterns in decompiled bytecode at a scale that was previously impractical.
  • Unverified contracts represent a distinct and growing attack surface: they receive less public scrutiny, generate fewer community-driven bug reports, and are typically excluded from bug bounty programs, yet still hold millions in user funds.
  • Real-time on-chain monitoring is especially critical for protocols deploying unverified contracts, as the traditional security ecosystem cannot function without readable source code to review.

Read our full analysis here.

 
 

Recent Insights

 
 
 
 
 
 
Who are we?
 
 

Chainalysis is the blockchain data platform, making it easy to connect the movement of digital assets to real-world services. Powered by deep blockchain data and AI, organizations can investigate illicit activity, manage risk exposure, and develop innovative market solutions built on the industry's most trusted blockchain intelligence. Our mission is to build trust in blockchains, blending safety and security with an unwavering commitment to growth and innovation. For more information, visit chainalysis.com.