The Kerberus 2026 Threat Report, released this week, has sounded the alarm on two converging threats facing Web3 developers and users: AI-enabled attack campaigns and sophisticated state-sponsored hacking operations targeting cryptocurrency wallets and private key infrastructure. The report arrives as market sentiment sits at a cautious 2/10 bullish rating, suggesting builders are already operating in defensive mode.
AI-Enabled Attacks Take Center Stage
According to the threat intelligence analysis, malicious actors are increasingly deploying machine learning systems to automate vulnerability discovery, phishing campaigns, and wallet draining operations. These AI-augmented attack vectors reduce the barrier for entry for crypto theft significantly, enabling even low-skill attackers to execute sophisticated heists at scale.
State-Sponsored Actors Expand Web3 Targets
Perhaps more alarming is the report's documentation of nation-state hacking groups adding cryptocurrency infrastructure to their target portfolios. These well-funded operations bring advanced persistent threat capabilities—including zero-day exploits and supply chain compromises—to bear against exchanges, wallet providers, and DeFi protocols.
Emerging Projects Under the Microscope
The Kerberus team flagged several rising crypto projects for security monitoring, including iotex-core and Maskbook, both of which are actively gaining GitHub stars. While growth doesn't indicate vulnerability, rapid adoption often outpaces security audits—a pattern the threat intelligence community watches closely.
Key Infrastructure Concerns
Private key management emerges as the primary attack surface in the report. Hardware security modules, multi-signature schemes, and MPC (multi-party computation) wallets are recommended as baseline mitigations. The report also emphasizes the need for automated threat detection in CI/CD pipelines handling sensitive cryptographic operations.
Key Takeaways
- AI-powered attacks on Web3 infrastructure are scaling faster than defensive tools can adapt
- State-sponsored groups now actively target cryptocurrency exchanges and wallet providers
- Private key security remains the single highest-priority attack surface for 2026
- Emerging projects like iotex-core warrant close security monitoring as adoption grows
The Bottom Line
If you're shipping Web3 infrastructure in this environment, your threat model is outdated before you ship. AI-assisted attacks aren't theoretical anymore—they're the baseline. Budget accordingly.