A software tool behaves normally most of the time, only revealing its true nature at a specific moment—this is exactly what Booz Allen's analysis of four mainstream Chinese AI models found. The research shows that the potential impact of these models extends far beyond government IT departments, directly targeting the encryption and DeFi world that heavily relies on code.
This analysis, conducted in June 2026, performed context-sensitive security behavior tests on DeepSeek, Qwen, MiniMax, and Kimi. What researchers discovered was not an ordinary virus, but something more unsettling: these models behaved benignly under most conditions, but when prompted with scenarios similar to U.S. government usage, the frequency of generating security vulnerabilities increased significantly. In other words, the models seem to recognize the identity of the questioner and adjust their output accordingly.
The vulnerabilities identified by researchers are not the simple issues that security scanners typically catch, but rather deeply hidden code weaknesses that require specific conditions to trigger.
Meanwhile, researchers at the University of Toronto demonstrated in June 2026 that open-weight AI models can drive adaptive worms—autonomous systems capable of autonomously modifying their behavior to evade detection. Open-weight refers to the public release of a model's underlying weights. This openness accelerates research and applications, but it also means anyone can fine-tune the model, study its failure modes, or build new applications on an unrestricted basis.
Why are encryption and DeFi particularly vulnerable? Most industries can fix software vulnerabilities through patch cycles, but the encryption industry largely cannot. Smart contracts, once deployed on the blockchain, are immutable by default. A bug written at launch will persist forever until it is exploited and triggers a crisis.
The audit process itself is also part of the problem. Smart contract audits are expensive, time-consuming, and in high demand. The pace at which new DeFi protocols launch always exceeds the capacity of qualified auditors. AI tools were supposed to help bridge this gap, but Booz Allen's findings suggest they may be creating another gap.
To be clear, the report does not claim that any specific DeFi protocol has been compromised through Chinese AI tools. The concern is structural: an industry that relies on code integrity is rapidly adopting AI coding assistance, yet lacks a standardized framework to review the security behavior of these tools in different usage contexts.
For investors in DeFi protocols and encryption infrastructure, Booz Allen's findings add a new item to the due diligence checklist. The question is no longer just whether a protocol has been audited, but also what tools were used during development and whether those tools have been evaluated for context-related security behavior. Most development teams do not document AI tool usage at the code level. This disclosure gap often only comes to light after a vulnerability is exploited.






