AI company Anthropic revealed on December 2 that advanced AI agents can now identify vulnerabilities in smart contracts and even execute real-world attacks. The findings raise serious concerns about the accelerating risks AI poses to blockchain security.
GM ☀️
Anthropic applied AI models on real hacks and uncovered exploits worth $550M
They created SCONE-bench with 405 exploited contracts from 2020-2025, and 10 models crushed 51% of them
Is AI the new king of security audits? pic.twitter.com/spZWOst3hO
— CryptoLabs (@cryptolabsio) December 2, 2025
The study used Anthropic’s newly developed benchmark “SCONE-bench”, analyzing 405 previously exploited smart contracts. Leading AI models, including Claude Opus 4.5 and GPT-5, were tested across a series of simulations based on data after March 2025.
According to Anthropic, AI agents successfully conducted attacks totaling USD 4.6 million, demonstrating that autonomous AI-driven exploits are no longer hypothetical.
AI Discovers Zero-Day Vulnerabilities and Generates Profit
On October 3, researchers evaluated 2,849 smart contracts with no known vulnerabilities, many operating on Ethereum and related ecosystems.
Both Sonnet 4.5 and GPT-5 identified two previously unknown zero-day vulnerabilities. These flaws were successfully exploited, allowing the AI to extract cryptocurrencies worth approximately USD 3,694.
The cost to operate GPT-5’s API for the attack was USD 3,476, meaning the exploit produced a net-positive return.
Researchers emphasized that this marks a tipping point: AI-driven attacks have become economically viable for malicious actors.
The study focused not only on technical success, but also on the economic feasibility of AI-enabled cyberattacks, underscoring the urgent need for stronger risk controls in AI-crypto infrastructure.
AI Attack Capabilities Doubling Every 1.3 Months
Anthropic found that the profitability of leading AI models in simulated attacks has been doubling roughly every 1.3 months, driven by improvements in:
- autonomous tool use
- error recovery
- sequential reasoning
- complex exploit execution
While researchers noted that this explosive growth may eventually slow, they warned that the current pace represents a severe and rapidly escalating security threat.
Anthropic concluded that autonomous, profit-seeking AI attacks are no longer theoretical and that blockchain ecosystems urgently need AI-powered defensive systems to match accelerating offensive capabilities.
Interest is also growing in AI agents for autonomous defense, including specialized crypto-security AI tools designed to monitor and block attacks in real time.
