I used to say nothing ever dies in crypto.
The rationale was that since projects had raised absurd amounts of money, if founders wanted to check out, it was legally safer for them to pay for a maintenance team that kept the pretense of progress going.
Founders may have found the perfect cover, though: AI threats.
Harmony Cites AI Threats in Proposed Blockchain Shutdown
— Decrypt (@decrypt.co) September 7, 2026 at 6:18 PM
[image or embed]
The lede in that article was several kinds of crazy rolled into one.
- Ethereum competitor is moving to Ethereum;
- Because the founders are pivoting into AI video now;
- And btw you have three days to pull your money, so hopefully you weren’t on vacation and are paying attention, kthxbai.
Yes, clearly the current advance in AI models is increasing threats for always-on projects. Crypto projects, with their financial, non-repudiable nature, are sweet targets. None of this is new as a category of question — it is the same threat model exercise as always, only with a cheaper, tireless, better-read adversary on the other side of it.
We got into this topic on the Spelunking Pod about four months ago, when I spoke about crypto projects that might be asleep at the wheel, and how I hoped that would put the “fear of god” in those that were too lax about their security.
When I started writing this, my take was frankly negative: we’re going to see a bunch of founders using cyber-capable AI models as an excuse to bolt for the hills, leaving their retail investors and users in the cold (because I’m sure VC investors cashed out a while ago).
Zombie projects looked like a safe bet before, but they are now a legal infection vector. Vague “AI threats” let founders excuse themselves by saying they are doing it to safeguard users, because the world out there has become too dangerous.
But with strange aeons, even death may die: we are going to see a lot of founders and projects that shouldn’t be around in the first place leave the crypto space — and that’s sensational!
The AI threat is going to cut through the veneer of competence and grit. Instead of potentially believable promises about ongoing maintenance, people are going to get a clear sign that they should not be around in the first place.
The space is going to be left with two kinds of projects: the time-bombs where the people running them are shameless or checked out enough that they don’t care if users get hurt; and those who are actively building and working to counter the threats.
They are going to be easy to tell apart.
Those you should avoid will be all bluster about how their stuff is solid and how you should buy the dip, telling you that their team is on it but can’t reveal the secret sauce because that makes them vulnerable to hackers. Avoid them like a Justin Sun-adjacent project.
Those you should pay attention to will not try to cocoon you. They will continue putting out updates that they expect will help address issues (likely after heated community discussion), will work incrementally on their roadmap, and will ideally warn you to remain vigilant about activity both in the base layer and the projects you use (because no base layer improvement can save you from the Drift hack).
There is a second-order effect worth watching: if “we cannot defend this against that class of adversary” is an acceptable reason to shut down a chain or project, then it is an equally acceptable reason to never launch one. The excuse cuts both ways: it raises the bar on what you need to be able to credibly claim before you ask anyone to put their money inside a contract you wrote. Users should get in the habit of picking at the cyber-resilience question.
This will, in the long run, reward competence and grit over swagger. So the question worth asking about anything you are currently holding is not whether the team says they have it handled. It is when they last shipped something that admitted a problem.