Frontier AI Models Demonstrate Human-Level Capability in Smart Contract Exploits

In brief

  • Anthropic tested ten AI models on 405 historical smart contract exploits and reproduced 207 of them.
  • Three models generated $4.6 million in simulated exploits on contracts created after their training cutoff.
  • Agents also discovered two new zero-day vulnerabilities in recent Binance Smart Chain contracts.

AI agents matched the performance of skilled human attackers in more than half of the smart contract exploits recorded on major blockchains over the last five years, according to new data released Monday by Anthropic.

Anthropic evaluated ten frontier models, including Llama 3, Sonnet 3.7, Opus 4, GPT-5, and DeepSeek V3, on a dataset of 405 historical smart contract exploits. The agents produced working attacks against 207 of them, totaling $550 million in simulated stolen funds.

The findings showed how quickly automated systems can weaponize vulnerabilities and identify new ones that developers have not addressed.

The new disclosure is the latest from the developer of Claude AI. Last month, Anthropic detailed how Chinese hackers used Claude Code to launch what it called the first AI-driven cyberattack.

Security experts said the results confirmed how accessible many of these flaws already are.

“AI is already being used in ASPM tools like Wiz Code and Apiiro, and in standard SAST and DAST scanners,” David Schwed, COO of SovereignAI, told Decrypt. “That means bad actors will use the same technology to identify vulnerabilities.”

Schwed said the model-driven attacks described in the report would be straightforward to scale because many vulnerabilities are already publicly disclosed through Common Vulnerabilities and Exposures or audit reports, making them learnable by AI systems and easy to attempt against existing smart contracts.

“Even easier would be to find a disclosed vulnerability, find projects that forked that project, and just attempt that vulnerability, which may not have been patched,” he said. “This can all be done now 24/7, against all projects. Even those now with smaller TVLs are targets because why not? It’s agentic.”

To measure current capabilities, Anthropic plotted each model’s total exploit revenue against its release date using only the 34 contracts exploited after March 2025.

“Although total exploit revenue is an imperfect metric—since a few outlier exploits dominate the total revenue—we highlight it over attack success rate because attackers care about how much money AI agents can extract, not the number or difficulty of the bugs they find,” the company wrote.

Anthropic did not immediately respond to requests for comment by Decrypt.

Anthropic said it tested the agents on a zero-day dataset of 2,849 contracts drawn from more than 9.4 million on Binance Smart Chain.

The company said Claude Sonnet 4.5 and GPT-5 each uncovered two undisclosed flaws that produced $3,694 in simulated value, with GPT-5 achieving its result at an API cost of $3,476. Anthropic noted that all tests ran in sandboxed environments that replicated blockchains and not real networks.

Its strongest model, Claude Opus 4.5, exploited 17 of the post-March 2025 vulnerabilities and accounted for $4.5 million of the total simulated value.

The company linked improvements across models to advances in tool use, error recovery, and long-horizon task execution. Across four generations of Claude models, token costs fell by 70.2%.

One of the newly discovered flaws involved a token contract with a public calculator function that lacked a view modifier, which allowed the agent to repeatedly alter internal state variables and sell inflated balances on decentralized exchanges. The simulated exploit generated about $2,500.

Schwed said the issues highlighted in the experiment were “really just business logic flaws,” adding that AI systems can identify these weaknesses when given structure and context.

“AI can also discover them given an understanding of how a smart contract should function and with detailed prompts on how to attempt to circumvent logic checks in the process,” he said.

Anthropic said the capabilities that enabled agents to exploit smart contracts also apply to other types of software, and that falling costs will shrink the window between deployment and exploitation. The company urged developers to adopt automated tools in their security workflows so defensive use advances as quickly as offensive use.

Despite Anthropic’s warning, Schwed said the outlook is not solely negative.

“I always push back on the doom and gloom and say with proper controls, rigorous internal testing, along with real-time monitoring and circuit breakers, most of these are avoidable,” he said. “The Good actors have the same access to the same agents. So if the bad actors can find it, so can the good actors. We have to think and act differently.”

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.

Source link

Jason Nelson

https://decrypt.co/350575/ai-models-human-level-capability-smart-contract-exploits

2025-12-02 02:48:00

bitcoin
Bitcoin (BTC) $ 86,708.00 0.13%
ethereum
Ethereum (ETH) $ 2,809.99 1.02%
tether
Tether (USDT) $ 0.99998 0.02%
xrp
XRP (XRP) $ 2.03 1.69%
bnb
BNB (BNB) $ 831.70 0.55%
usd-coin
USDC (USDC) $ 0.999804 0.00%
tron
TRON (TRX) $ 0.277355 0.24%
staked-ether
Lido Staked Ether (STETH) $ 2,809.67 1.44%
dogecoin
Dogecoin (DOGE) $ 0.13616 1.84%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 1.21%
cardano
Cardano (ADA) $ 0.389491 0.66%
whitebit
WhiteBIT Coin (WBT) $ 57.84 3.77%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,429.53 1.02%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,623.00 0.31%
bitcoin-cash
Bitcoin Cash (BCH) $ 532.50 0.81%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,046.59 0.96%
usds
USDS (USDS) $ 0.999821 0.01%
leo-token
LEO Token (LEO) $ 9.84 0.59%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999697 0.01%
chainlink
Chainlink (LINK) $ 12.08 1.88%
hyperliquid
Hyperliquid (HYPE) $ 30.73 2.04%
weth
WETH (WETH) $ 2,811.50 1.01%
stellar
Stellar (XLM) $ 0.233713 1.26%
monero
Monero (XMR) $ 396.61 6.91%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,041.90 1.53%
ethena-usde
Ethena USDe (USDE) $ 0.999305 0.14%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 86,778.00 0.06%
litecoin
Litecoin (LTC) $ 77.79 1.22%
hedera-hashgraph
Hedera (HBAR) $ 0.133069 1.83%
avalanche-2
Avalanche (AVAX) $ 12.92 1.85%
zcash
Zcash (ZEC) $ 333.76 13.75%
sui
Sui (SUI) $ 1.35 3.01%
shiba-inu
Shiba Inu (SHIB) $ 0.000008 0.79%
dai
Dai (DAI) $ 0.999121 0.05%
susds
sUSDS (SUSDS) $ 1.08 0.30%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.152504 3.41%
paypal-usd
PayPal USD (PYUSD) $ 0.999915 0.02%
crypto-com-chain
Cronos (CRO) $ 0.102605 0.91%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21 0.04%
usdt0
USDT0 (USDT0) $ 0.99999 0.02%
the-open-network
Toncoin (TON) $ 1.50 0.57%
uniswap
Uniswap (UNI) $ 5.53 1.98%
polkadot
Polkadot (DOT) $ 2.05 1.42%
mantle
Mantle (MNT) $ 0.977967 3.69%
canton-network
Canton (CC) $ 0.077418 8.64%
usd1-wlfi
USD1 (USD1) $ 0.999454 0.02%
aave
Aave (AAVE) $ 169.53 0.87%
bittensor
Bittensor (TAO) $ 265.29 3.22%
bitget-token
Bitget Token (BGB) $ 3.46 0.38%
memecore
MemeCore (M) $ 1.40 1.32%