AI agents are now capable of exploiting smart contracts on Ethereum and other blockchains, raising urgent questions about the economic risks of autonomous cyber capabilities.AI agents are now capable of exploiting smart contracts on Ethereum and other blockchains, raising urgent questions about the economic risks of autonomous cyber capabilities.

Ethereum smart contracts exploited by AI: GPT-5 and Claude demonstrate million-dollar vulnerabilities

AI agents are now capable of exploiting smart contracts on Ethereum and other blockchains, raising urgent questions about the economic risks of autonomous cyber capabilities.

Summary
  • Frontier AI models, including GPT-5 and Claude, exploited smart contracts on Ethereum and other blockchains in simulated tests.
  • The AI models discovered previously unknown security flaws—called zero-day vulnerabilities—in software (in this case, smart contracts on Ethereum).
  • Findings highlight the urgent need for proactive AI-powered defense strategies, as AI agents now rival human hackers in identifying profitable blockchain exploits. 

A joint project by Anthropic and MATS Fellows used the newly created Smart CONtracts Exploitation benchmark (SCONE-bench) to test AI models against 405 real-world contracts exploited between 2020 and 2025.

In simulated attacks on contracts exploited after March 2025, Claude Opus 4.5, Claude Sonnet 4.5, and GPT-5 produced exploits collectively worth $4.6 million, demonstrating a concrete lower bound on the potential financial damage AI could cause. Extending the tests to 2,849 recently deployed contracts with no known vulnerabilities, GPT-5 and Sonnet 4.5 uncovered two novel zero-day vulnerabilities, generating simulated profits of nearly $3,700.

SCONE-bench: Quantifying exploits in dollars, not bugs

Traditional cybersecurity benchmarks measure success by detection rates or arbitrary scores, but SCONE-bench evaluates AI exploits in financial terms, providing a more tangible measure of risk. Smart contracts are particularly well-suited for this approach because vulnerabilities can directly translate into stolen funds, and simulations allow researchers to quantify the potential losses.

Over all 405 contracts in SCONE-bench, 10 AI models produced exploits for 207 contracts, totaling $550.1 million in simulated stolen funds. Even accounting for potential data contamination, frontier models consistently demonstrated the ability to exploit contracts beyond their knowledge cutoff dates.

Concrete Examples of AI Exploits

One tested vulnerability involved a token calculator function on an Ethereum-compatible contract that was mistakenly left writable. The AI agent repeatedly called the function to inflate its token balance, generating simulated profits of $2,500 and, under peak liquidity conditions, a potential $19,000. Independent white-hat intervention later recovered the assets.

The research underscores that AI agents are now approaching human-level capability in tasks like control-flow reasoning, boundary analysis, and exploiting software vulnerabilities—a skill set directly applicable to blockchain and traditional software systems alike.

The study emphasizes that AI cyber capabilities are accelerating rapidly, from network intrusions to autonomous exploitation of blockchain applications. SCONE-bench provides a defensive tool, allowing smart contract developers to stress-test systems before deployment.

According to the researchers, the findings are a proof-of-concept that profitable, real-world autonomous exploitation is feasible, highlighting the urgent need for proactive AI-powered defenses to protect financial systems and digital assets.

Market Opportunity
Smart Blockchain Logo
Smart Blockchain Price(SMART)
$0.005003
$0.005003$0.005003
+0.70%
USD
Smart Blockchain (SMART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

The post Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny appeared on BitcoinEthereumNews.com. The cryptocurrency world is buzzing with a recent controversy surrounding a bold OpenVPP partnership claim. This week, OpenVPP (OVPP) announced what it presented as a significant collaboration with the U.S. government in the innovative field of energy tokenization. However, this claim quickly drew the sharp eye of on-chain analyst ZachXBT, who highlighted a swift and official rebuttal that has sent ripples through the digital asset community. What Sparked the OpenVPP Partnership Claim Controversy? The core of the issue revolves around OpenVPP’s assertion of a U.S. government partnership. This kind of collaboration would typically be a monumental endorsement for any private cryptocurrency project, especially given the current regulatory climate. Such a partnership could signify a new era of mainstream adoption and legitimacy for energy tokenization initiatives. OpenVPP initially claimed cooperation with the U.S. government. This alleged partnership was said to be in the domain of energy tokenization. The announcement generated considerable interest and discussion online. ZachXBT, known for his diligent on-chain investigations, was quick to flag the development. He brought attention to the fact that U.S. Securities and Exchange Commission (SEC) Commissioner Hester Peirce had directly addressed the OpenVPP partnership claim. Her response, delivered within hours, was unequivocal and starkly contradicted OpenVPP’s narrative. How Did Regulatory Authorities Respond to the OpenVPP Partnership Claim? Commissioner Hester Peirce’s statement was a crucial turning point in this unfolding story. She clearly stated that the SEC, as an agency, does not engage in partnerships with private cryptocurrency projects. This response effectively dismantled the credibility of OpenVPP’s initial announcement regarding their supposed government collaboration. Peirce’s swift clarification underscores a fundamental principle of regulatory bodies: maintaining impartiality and avoiding endorsements of private entities. Her statement serves as a vital reminder to the crypto community about the official stance of government agencies concerning private ventures. Moreover, ZachXBT’s analysis…
Share
BitcoinEthereumNews2025/09/18 02:13
LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group has revealed a multi-year partnership with Ripple to integrate traditional finance with digital asset markets. As part of the agreement, LMAX will introduce
Share
Tronweekly2026/01/16 23:00
Pastor Involved in High-Stakes Crypto Fraud

Pastor Involved in High-Stakes Crypto Fraud

A gripping tale of deception has captured the media’s spotlight, especially in foreign outlets, centering on a cryptocurrency fraud case from Denver, Colorado. Eli Regalado, a pastor, alongside his wife Kaitlyn, was convicted, but what makes this case particularly intriguing is their unconventional defense.Continue Reading:Pastor Involved in High-Stakes Crypto Fraud
Share
Coinstats2025/09/18 00:38