Artificial intelligence is proving to be a formidable force in cybersecurity, with Anthropic's AI systems recently demonstrating the ability to identify and exploit smart contract vulnerabilities, potentially worth millions. In simulated tests, these AI agents successfully uncovered flaws in blockchain applications, highlighting both the power of AI and the ongoing security challenges within the decentralized finance (DeFi) sector.
Key Takeaways
-
AI models, including Anthropic's Claude Opus 4.5 and GPT-5, can successfully exploit smart contracts.
-
Simulated exploits identified vulnerabilities totaling $4.6 million in value.
-
Testing focused on simulated environments to assess potential real-world impact without risking actual funds.
-
The study suggests AI can be a double-edged sword, useful for both finding and fixing security flaws.
AI's Exploit Capabilities Revealed
Anthropic, in collaboration with MATS and Anthropic Fellows, conducted tests using a benchmark called SCONE-bench. This benchmark comprises 405 smart contracts that were previously exploited in real-world scenarios between 2020 and 2025. When ten leading AI models were run in a simulated blockchain environment, they managed to exploit just over half of these contracts, with the simulated value of the stolen funds reaching approximately $550.1 million.
To ensure the AI models were not simply recalling past incidents, the researchers refined their focus to 34 contracts exploited after March 1, 2025, the knowledge cutoff date for the AI systems. On this more recent set of vulnerabilities, advanced models like Claude Opus 4.5, Claude Sonnet 4.5, and GPT-5 successfully generated working exploits for 19 contracts, collectively valued at $4.6 million in simulated assets. Notably, Claude Opus 4.5 alone accounted for approximately $4.5 million of this simulated value.
Uncovering Novel Threats
Further testing explored the AI agents' ability to discover entirely new vulnerabilities, not just replicate known ones. In a simulation on October 3, 2025, Sonnet 4.5 and GPT-5 were tasked with analyzing 2,849 recently deployed Binance Smart Chain contracts that had no previously identified vulnerabilities. Both agents successfully identified two zero-day bugs, generating attacks with a simulated value of $3,694. GPT-5 achieved this at an API cost of around $3,476.
Simulated Environments and Security Implications
It is crucial to note that all testing was performed on forked blockchains and local simulators, with no real funds at risk. Anthropic emphasized that the objective was to gauge the current technical capabilities of AI in identifying exploits, not to interfere with live systems. Smart contracts, due to their direct handling of value and on-chain execution, serve as ideal test cases for such research.
The study also observed that the potential exploit revenue from newly identified vulnerabilities has been doubling approximately every 1.3 months over the past year. Concurrently, the cost of generating a working exploit has significantly decreased across different AI model generations. This trend suggests that attackers could potentially achieve more successful exploits with the same computational budget as AI technology advances.
While the research primarily focuses on DeFi, Anthropic posits that the AI skills demonstrated are transferable to traditional software security, including public APIs and internal services. The company's core message to developers is that AI tools are dual-purpose: they can be leveraged to identify and exploit vulnerabilities, but also to audit and fortify smart contracts and other software before deployment.
Sources
-
AI Can Hack Smart Contracts After Finding $4.6M, Cryptonews.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.