DeFiHackLabs, the winning team of SCAN 2024, warned participants against relying blindly on AI during a video interview with Digital Asset on July 3. The blockchain security community emphasized that AI-generated answers must always be verified. The warning comes as AI capabilities have advanced dramatically since SCAN 2024, a digital asset tracing capture-the-flag competition hosted by Dasset in November 2024. DeFiHackLabs stated that while AI can improve problem-solving efficiency, incorrect use can derail the process. The team recommended treating AI as an assistant rather than outsourcing problem understanding to the technology.
DeFiHackLabs is a blockchain security community founded three years ago with approximately 300 members. The members describe themselves as white-hat hackers, security researchers, or security engineers. The community's stated goal is making the blockchain and Web3 ecosystem safer. Members come from professional backgrounds including smart contract security, anti-money laundering investigations, and reverse engineering.
DeFiHackLabs identified the flag submission limit as a standout feature of SCAN 2024. Under this system, participants who exceed the permitted number of attempts can no longer submit a flag for that challenge. The team stated that limiting submissions discourages repeated guessing and encourages careful verification before submission. DeFiHackLabs recommended retaining this rule for the SCAN 2026 finals, noting that AI enables teams to solve CTF challenges much faster than in 2024.
The team provided specific guidance on AI use in CTF competitions. DeFiHackLabs stated: "Do not rely on it completely. Never take an AI-generated answer at face value. Always verify it." The community acknowledged that AI models have become remarkably capable but stressed that AI should remain an assistant or team member. DeFiHackLabs warned that AI can significantly improve problem-solving efficiency but can also derail the entire process when used incorrectly. The team advised participants to use AI engines to support problem-solving without outsourcing the process of understanding the problem to AI.
DeFiHackLabs maintains several open datasets including an incident database containing Web3 hacking proof-of-concept research. The team tracked more than 872 protocol exploit incidents since 2017 through their dashboard, with cumulative losses exceeding $8 billion. The protocol category includes DeFi attacks, bridge hacks, exchange incidents, and smart contract exploits. Last year, approximately 200 protocol hacks resulted in nearly $3 billion in losses.
Wallet compromises including phishing attacks, malware, and private-key leaks caused approximately $800 million in losses last year and affected around 80,000 victims. DeFiHackLabs estimated that scams have caused at least $14 billion in losses. In Taiwan, scam-related losses reached approximately $2.6 billion last year, with around 170,000 cases reported to police.
DeFiHackLabs stated that the flag submission limit has become more important in the age of AI. The team recommended that SCAN 2026 organizers retain this competition design feature. DeFiHackLabs also suggested including challenges involving smart contract security, attack investigations, and asset-recovery scenarios, noting that these cases are becoming increasingly common in real-world blockchain security work. The team encouraged law enforcement agencies, police investigators, Web3 security researchers, and members of the general public to participate in SCAN 2026.
What advice did DeFiHackLabs give about using AI in CTF competitions?
DeFiHackLabs advised participants to never rely completely on AI and to always verify AI-generated answers. The team stated that AI should be treated as an assistant or teammate that provides hints, guidance, and support, rather than taking over the process of understanding the problem itself.
What security data has DeFiHackLabs tracked since 2017?
DeFiHackLabs tracked more than 872 protocol exploit incidents since 2017 with cumulative losses exceeding $8 billion. The team also tracked wallet compromises that caused approximately $800 million in losses and affected around 80,000 victims last year, and estimated that scams have caused at least $14 billion in losses.
Why did DeFiHackLabs recommend retaining flag submission limits for SCAN 2026?
DeFiHackLabs recommended retaining flag submission limits because AI enables teams to solve CTF challenges much faster than in 2024. The team stated that limiting submissions discourages repeated guessing and encourages participants to carefully verify their answers before submitting them.
Related News