AI agents are now capable of exploiting smart contracts on Ethereum and other blockchains, raising urgent questions about the economic risks of autonomous cyber capabilities.AI agents are now capable of exploiting smart contracts on Ethereum and other blockchains, raising urgent questions about the economic risks of autonomous cyber capabilities.

Ethereum smart contracts exploited by AI: GPT-5 and Claude demonstrate million-dollar vulnerabilities

2025/12/03 05:17
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

AI agents are now capable of exploiting smart contracts on Ethereum and other blockchains, raising urgent questions about the economic risks of autonomous cyber capabilities.

Summary
  • Frontier AI models, including GPT-5 and Claude, exploited smart contracts on Ethereum and other blockchains in simulated tests.
  • The AI models discovered previously unknown security flaws—called zero-day vulnerabilities—in software (in this case, smart contracts on Ethereum).
  • Findings highlight the urgent need for proactive AI-powered defense strategies, as AI agents now rival human hackers in identifying profitable blockchain exploits. 

A joint project by Anthropic and MATS Fellows used the newly created Smart CONtracts Exploitation benchmark (SCONE-bench) to test AI models against 405 real-world contracts exploited between 2020 and 2025.

In simulated attacks on contracts exploited after March 2025, Claude Opus 4.5, Claude Sonnet 4.5, and GPT-5 produced exploits collectively worth $4.6 million, demonstrating a concrete lower bound on the potential financial damage AI could cause. Extending the tests to 2,849 recently deployed contracts with no known vulnerabilities, GPT-5 and Sonnet 4.5 uncovered two novel zero-day vulnerabilities, generating simulated profits of nearly $3,700.

SCONE-bench: Quantifying exploits in dollars, not bugs

Traditional cybersecurity benchmarks measure success by detection rates or arbitrary scores, but SCONE-bench evaluates AI exploits in financial terms, providing a more tangible measure of risk. Smart contracts are particularly well-suited for this approach because vulnerabilities can directly translate into stolen funds, and simulations allow researchers to quantify the potential losses.

Over all 405 contracts in SCONE-bench, 10 AI models produced exploits for 207 contracts, totaling $550.1 million in simulated stolen funds. Even accounting for potential data contamination, frontier models consistently demonstrated the ability to exploit contracts beyond their knowledge cutoff dates.

Concrete Examples of AI Exploits

One tested vulnerability involved a token calculator function on an Ethereum-compatible contract that was mistakenly left writable. The AI agent repeatedly called the function to inflate its token balance, generating simulated profits of $2,500 and, under peak liquidity conditions, a potential $19,000. Independent white-hat intervention later recovered the assets.

The research underscores that AI agents are now approaching human-level capability in tasks like control-flow reasoning, boundary analysis, and exploiting software vulnerabilities—a skill set directly applicable to blockchain and traditional software systems alike.

The study emphasizes that AI cyber capabilities are accelerating rapidly, from network intrusions to autonomous exploitation of blockchain applications. SCONE-bench provides a defensive tool, allowing smart contract developers to stress-test systems before deployment.

According to the researchers, the findings are a proof-of-concept that profitable, real-world autonomous exploitation is feasible, highlighting the urgent need for proactive AI-powered defenses to protect financial systems and digital assets.

Market Opportunity
Smart Blockchain Logo
Smart Blockchain Price(SMART)
$0.005725
$0.005725$0.005725
-5.13%
USD
Smart Blockchain (SMART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why Localization Services Matter for Software Companies

Why Localization Services Matter for Software Companies

Rarely does software designed for one market translate smoothly to another. The most obvious obstacle is language, but it’s not the only one. Before a product feels
Share
Techbullion2026/03/25 19:10
₹71L CoinDCX Fraud Case Turns, Court Finds No Link to Founders

₹71L CoinDCX Fraud Case Turns, Court Finds No Link to Founders

Court grants bail to CoinDCX founders after ₹71L scam traced to fake site; no link found, funds recovered, platform secure. The court granted bail to CoinDCX founders
Share
LiveBitcoinNews2026/03/25 19:43
UK crypto holders brace for FCA’s expanded regulatory reach

UK crypto holders brace for FCA’s expanded regulatory reach

The post UK crypto holders brace for FCA’s expanded regulatory reach appeared on BitcoinEthereumNews.com. British crypto holders may soon face a very different landscape as the Financial Conduct Authority (FCA) moves to expand its regulatory reach in the industry. A new consultation paper outlines how the watchdog intends to apply its rulebook to crypto firms, shaping everything from asset safeguarding to trading platform operation. According to the financial regulator, these proposals would translate into clearer protections for retail investors and stricter oversight of crypto firms. UK FCA plans Until now, UK crypto users mostly encountered the FCA through rules on promotions and anti-money laundering checks. The consultation paper goes much further. It proposes direct oversight of stablecoin issuers, custodians, and crypto-asset trading platforms (CATPs). For investors, that means the wallets, exchanges, and coins they rely on could soon be subject to the same governance and resilience standards as traditional financial institutions. The regulator has also clarified that firms need official authorization before serving customers. This condition should, in theory, reduce the risk of sudden platform failures or unclear accountability. David Geale, the FCA’s executive director of payments and digital finance, said the proposals are designed to strike a balance between innovation and protection. He explained: “We want to develop a sustainable and competitive crypto sector – balancing innovation, market integrity and trust.” Geale noted that while the rules will not eliminate investment risks, they will create consistent standards, helping consumers understand what to expect from registered firms. Why does this matter for crypto holders? The UK regulatory framework shift would provide safer custody of assets, better disclosure of risks, and clearer recourse if something goes wrong. However, the regulator was also frank in its submission, arguing that no rulebook can eliminate the volatility or inherent risks of holding digital assets. Instead, the focus is on ensuring that when consumers choose to invest, they do…
Share
BitcoinEthereumNews2025/09/17 23:52