Security Hub

BIS: AI Cuts the Hacking Window From Weeks to Minutes

Published: Sep 11, 2026By Aleksandar Dukic

Key Analysis

A Bank for International Settlements paper warns AI has shrunk the gap between finding a flaw and exploiting it to minutes, straining bank and crypto defenses.

BIS: AI Cuts the Hacking Window From Weeks to Minutes

Listen To This Article

BIS: AI Cuts the Hacking Window From Weeks to Minutes

4m 42s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

The Bank for International Settlements has warned that artificial intelligence has compressed the time between a security flaw being discovered and being exploited "from weeks to minutes," according to a paper flagged by CoinMarketCap on September 11, 2026. That collapse leaves banks with almost no room to run the routine patching schedules most institutions still rely on.

The finding matters because the patch cycle is the backbone of how large financial institutions defend themselves. A vulnerability gets disclosed, security teams assess it, a fix is scheduled, tested, and rolled out over days or weeks. The BIS argument is that AI has broken the assumption underneath that process: attackers can now find and weaponize a weakness faster than a defender can move a fix through change control.

The defensive math no longer works

Traditional patch management assumes a buffer. Between the moment a flaw becomes known and the moment attackers can reliably use it, defenders historically had a window to react. The BIS paper describes that buffer shrinking to minutes. If an exploit can be generated and deployed at machine speed, a monthly or even weekly patch cadence is structurally too slow.

This is not a claim that any specific bank has been breached. It is a warning about timing. The gap between "we know about this" and "we are protected against this" is where risk lives, and the paper's point is that the gap is widening in attackers' favor. Institutions built for a slower threat model now face one that operates faster than their internal approval chains.

The same logic applies well beyond banks. Crypto exchanges, custodians, and card issuers run the same categories of web-facing infrastructure: authentication systems, APIs, cloud services, and third-party dependencies. A firm holding customer balances is defending the same attack surface a bank defends, often with smaller security teams and faster product cycles that leave less time for hardening.

Counterparty risk gets a new clock

For anyone holding crypto on a platform, the practical read is about counterparty risk. When you leave funds on an exchange or a custodial card account, you are trusting that firm's security operations to keep pace with attackers. The BIS framing suggests the pace required is now measured in minutes, not maintenance windows.

That does not mean custodial platforms are unsafe or that self-custody is automatically the answer. It means the speed of the threat is changing faster than the speed of most defenses, and concentration of funds is the variable a user actually controls. A large balance sitting idle on a platform is exposed to that platform's worst day. A working balance sized to what you actually spend is not.

This is the reasoning behind spending from your own wallet rather than parking large sums with a third party. Self-custody moves the security burden onto you, which is its own set of risks, but it removes the single-point exposure of a custodial breach. For users who prefer a custodial setup, the lighter version of the same idea is keeping only near-term spending money on the platform and holding the rest in cold storage.

Speed asymmetry, not a specific exploit

The BIS paper is a warning about capability, not a disclosure of any active attack. AI lowering the cost and time of finding and exploiting flaws is a structural shift, and structural shifts tend to reward defenders who assume compromise rather than those who assume a comfortable reaction window.

The uncomfortable part is that defenders can use the same AI tools, but the attacker only has to win once, while the defender has to hold every exposed system every minute. That asymmetry is what turns a shorter timeline into a real problem. A monthly patch program that worked in a weeks-long threat window does not automatically work in a minutes-long one, and rebuilding those processes takes far longer than the window the paper describes.

For crypto users, none of this requires panic. It reinforces habits that were already sound: minimize idle balances on any custodial service, treat platform security as a variable outside your control, and size the funds you expose to a platform to what you are willing to lose on that platform's worst day.

Overview

The BIS warned on September 11, 2026 that AI has cut the gap between a vulnerability being found and exploited from weeks to minutes, leaving banks' routine patch schedules too slow. The same exposure applies to crypto exchanges, custodians, and card issuers running comparable infrastructure. The paper describes a capability shift, not a specific breach. For users, the actionable response is reducing concentrated balances on custodial platforms and favoring self-custody or minimal hot balances where practical.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.