Skip to content
AI Agents Demonstrate Alarming Ability to Exploit Smart Contracts, Potentially Draining Millions

AI Agents Demonstrate Alarming Ability to Exploit Smart Contracts, Potentially Draining Millions

Quasa December 3, 2025

In a sobering new study from AI safety leader Anthropic , autonomous AI agents have proven capable of identifying and exploiting vulnerabilities in blockchain smart contracts at a scale that could enable multimillion-dollar thefts.

Researchers developed a novel benchmark called SCONE-bench, comprising 405 real-world smart contracts that were successfully exploited between 2020 and 2025 across major chains like Ethereum, BNB Smart Chain, and Base. Ten frontier AI models - including Anthropic's Claude Opus 4.5 and Claude Sonnet 4.5 , OpenAI's GPT-5, and others such as DeepSeek V3 - were tasked with autonomously analyzing the code, crafting exploit scripts, and executing attacks in a simulated environment using tools like Python, Foundry, and forked blockchains.

Even here, leading models like Opus 4.5, Sonnet 4.5, and GPT-5 succeeded on 19 cases (55.8%), with simulated damages reaching $4.6 million. Opus 4.5 alone accounted for $4.5 million, demonstrating superior reasoning in high-value scenarios.

Performance varied notably between models, underscoring their differing approaches to problem-solving. In one instance, GPT-5 extracted $1.12 million from a vulnerable contract, while Opus 4.5 maximized the same flaw to drain $3.5 million by optimizing transaction sequencing and liquidity routing.

Both independently discovered two previously unknown zero-day vulnerabilities, yielding $3,694 in simulated profits at a total inference cost of just $3,476 for GPT-5 (roughly $1.22 per contract scanned).

Anthropic observed explosive progress in AI exploitation capabilities: over the past year, simulated exploit revenue on post-March 2025 contracts roughly doubled every 1.3 months, while compute costs plummeted - dropping 70% in six months for some generations. This Moore's Law-like acceleration means more than half of 2025's real-world DeFi hacks, traditionally executed by elite human teams, could now be automated by off-the-shelf AI agents.

The implications extend far beyond crypto. Smart contracts' public, immutable nature makes them an ideal proving ground, but the underlying skills - reading complex code, tracing execution paths, and chaining transactions - apply equally to traditional software vulnerabilities, APIs, and infrastructure.

Yet the report strikes a balanced tone: the same autonomous agents that uncover exploits can serve as powerful defensive tools. Anthropic plans to open-source the SCONE-bench dataset, enabling developers to stress-test contracts pre-deployment and integrate AI-driven auditing into standard practices.

As one researcher noted, the race is on - those who deploy AI for proactive security first will hold a decisive edge in an era where attackers never sleep, tire, or forget. For the DeFi industry, already reeling from billions in cumulative losses, this study serves as a urgent wake-up call to embrace AI not just as a threat, but as the frontier in blockchain resilience.

Extracted Entities

Attack Types (1)

Companies (2)

Platforms (1)

Tools (2)