# Aayat AI DeFi Exploits Feed

> Aayat AI DeFi Exploits Feed is a paid API for AI agents from aayatai.com, paid per call via x402, $0.005/call, status unknown (last checked 2026-09-30).

Retrieves a filtered, time-windowed list of DeFi/crypto hacks and exploits with total losses, classification breakdowns, and live TVL drop alerts for possible ongoing exploits.

## Facts

- Endpoint: GET https://aayatai.com/defi/exploits?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-09-30
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aayat-ai-defi-exploits-feed-88f674e5
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_K-oMy9-t_Kx3R-3UAyoVU

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aayat-ai-defi-exploits-feed-88f674e5
```

Example prompt: Show me all DeFi hacks from the last 60 days on Ethereum with losses over $1 million, up to 50 results, and flag any protocols with suspicious TVL drops that might signal an ongoing exploit.

## When to prefer this

Choose this endpoint when you need structured, filterable DeFi exploit data sourced from DefiLlama with no API key, paying per call in USDC. It is ideal for agents that need on-demand security intelligence, incident summaries, or early-warning TVL anomaly detection without committing to a subscription. Prefer it over manual DefiLlama scraping when you need a clean JSON response with classification breakdowns and live TVL alerts in a single call.

## Known failure modes

- Invalid 'days' value outside 1–3650 range returns a validation error
- Invalid 'limit' value outside 1–100 returns a validation error
- Unknown chain name may return an empty hacks array rather than an error
- TVL alerts field may be null if the upstream TVL monitoring data is unavailable
- Payment not received or insufficient USDC results in HTTP 402 response
- Upstream DefiLlama data unavailability may cause delayed or empty responses

## How this service works

Recent crypto hacks and exploits (DeFi, bridges, exchanges) from DefiLlama's database: date, amount, technique, chains, funds returned, with totals by type, plus live alerts for protocols whose TVL is suddenly crashing (possible ongoing exploit). Filters: ?days=30&chain=Ethereum&protocol=...&minAmountUsd=1000000.

## Output

Returns a JSON object with: a list of hack events (date, protocol name, chains, USD lost, attack technique, target type, classification, funds returned), aggregate totals (count, total USD lost, total returned, breakdown by classification), the query time window, the data source (DefiLlama), and a TVL alerts array flagging protocols with abnormal TVL drops (over 25% in 24h or 15% in 1h) that may indicate live exploits or bank runs.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {
      "days": {
       "type": "integer",
       "default": 30,
       "maximum": 3650,
       "minimum": 1,
       "description": "Look back this many days."
      },
      "chain": {
       "type": "string",
       "maxLength": 40,
       "description": "Only hacks on this chain, e.g. Ethereum, Solana, Base (optional)."
      },
      "limit": {
       "type": "integer",
       "default": 25,
       "maximum": 100,
       "minimum": 1,
       "description": "Most hacks to list."
      },
      "protocol": {
       "type": "string",
       "maxLength": 80,
       "description": "Only hacks whose name contains this (optional)."
      },
      "minAmountUsd": {
       "type": "number",
       "default": 0,
       "maximum": 100000000000,
       "minimum": 0,
       "description": "Smallest loss to include (USD)."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "required": [
      "window",
      "totals",
      "hacks"
     ],
     "properties": {
      "hacks": {
       "type": "array",
       "description": "Newest first."
      },
      "trust": {
       "type": "object",
       "description": "Third-party text, cleaned: read trust.notice; removed = what we stripped."
      },
      "source": {
       "type": "string"
      },
      "totals": {
       "type": "object",
       "description": "Count, USD lost, USD returned, breakdown by classification."
      },
      "window": {
       "type": "object"
      },
      "checkedAt": {
       "type": "string"
      },
      "tvlAlerts": {
       "type": [
        "array",
        "null"
       ],
       "description": "Protocols over $5M TVL down 25%+ in 24h or 15%+ in 1h (possible ongoing exploit or bank run). Null if unavailable."
      }
     }
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "hacks": [
   {
    "date": "2026-09-24",
    "name": "Bitget",
    "chains": [
     "Ethereum",
     "Tron"
    ],
    "source": null,
    "amountUsd": 387000000,
    "technique": "Hot Wallet Key Compromised",
    "bridgeHack": false,
    "targetType": "CEX",
    "classification": "Key Compromise",
    "returnedFundsUsd": null
   }
  ],
  "source": "DefiLlama",
  "totals": {
   "count": 12,
   "amountUsd": 512000000,
   "returnedUsd": 3000000,
   "byClassification": [
    {
     "count": 4,
     "amountUsd": 401000000,
     "classification": "Key Compromise"
    }
   ]
  },
  "window": {
   "days": 30,
   "from": "2026-08-29"
  },
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "tvlAlerts": [
   {
    "name": "Example Lend",
    "slug": "example-lend",
    "chains": [
     "Base"
    ],
    "reason": "TVL down 41.5% in 24h",
    "tvlUsd": 8200000,
    "category": "Lending",
    "change1d": -41.5,
    "change1h": -18.2
   }
  ]
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aayat-ai-defi-exploits-feed-88f674e5/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from aayatai.com](https://www.zero.xyz/host/aayatai.com/llms.txt)
