Last month, Anthropic published research that should concern every smart contract developer and security researcher in this space: AI agents can now autonomously exploit more than half of real-world smart contract vulnerabilities without any human guidance.
The Numbers Are Staggering
In just one year, AI agents went from exploiting 2% of vulnerabilities to 55.88%—a leap from $5,000 to $4.6 million in total autonomous exploit revenue. Claude Opus 4.5, Claude Sonnet 4.5, and GPT-5 collectively developed exploits worth $4.6M against the SCONE-bench dataset (405 real contracts exploited between 2020-2025).
More concerning: both Sonnet 4.5 and GPT-5 uncovered two novel zero-day vulnerabilities and produced exploits worth $3,694—with GPT-5 doing this at an API cost of just $3,476. This means profitable, autonomous exploitation is now technically and economically viable.
The research found that more than half of blockchain exploits carried out in 2025 (presumably by skilled human attackers) could have been executed autonomously by current AI agents.
This Isn’t Theoretical Anymore
We already have real-world examples. North Korea’s Konni hacking group launched Operation Poseidon using AI-generated PowerShell malware to target blockchain developers in Japan, Australia, and India. The malware had “unusually polished structure” with professional documentation—hallmarks of AI-generated code.
These attacks impersonated financial institutions and human rights organizations, delivering backdoors through compromised WordPress sites. The targets? Blockchain developers with access to production systems and private keys.
The Attack Economics Are Brutal
Here’s the asymmetry that keeps me up at night: At 0.1% vulnerability rates, attackers achieve profitability at $6,000 exploit value, while defenders require $60,000 to justify AI-powered security scanning at the same scale.
And the trend is accelerating:
- Potential exploit revenue doubling every 1.3 months
- Token costs falling ~22% every 2 months
- AI agents moving from “interesting research” to “actively deployed” by adversaries
The Legal Liability Black Hole
When an autonomous AI agent finds and exploits a smart contract vulnerability, who is legally liable?
- The AI developer (Anthropic, OpenAI, etc.) who built the model?
- The person who deployed the agent and pointed it at contracts?
- The smart contract developer whose code had the vulnerability?
- Nobody—because it’s just “code is law” and permissionless systems?
Traditional liability frameworks don’t map cleanly to autonomous agents. Is this a crime, or is it automated arbitrage? If the blockchain is permissionless and smart contracts are “code is law,” did the AI agent just follow the rules we designed?
What Happens Next?
If 55% of exploits can be automated by 2026, what happens when we hit 95% automation in 2027? Do we:
- Ban AI agents from interacting with smart contracts? (Violates censorship resistance and is technically unenforceable)
- Require AI developers to implement exploit prevention filters? (Arms race, easily circumvented)
- Hold deployers strictly liable? (Might prevent legitimate security research)
- Accept that “code is law” means autonomous exploitation is just the new reality? (DeFi becomes uninvestable)
The asymmetry favoring attackers suggests that without intervention, AI agents will systematically exploit vulnerable contracts faster than humans can patch them.
We Need AI-Specific Legal Frameworks
Autonomous systems break conventional liability models. We need:
- Legal definitions for AI agents in crypto contexts
- Algorithmic governance models with built-in accountability
- International coordination (good luck enforcing against North Korean AI malware)
- Technical standards for AI-resistant smart contract patterns
The alternative is a DeFi ecosystem where deployment means immediate AI scanning and exploitation of any vulnerability, no matter how small.
Trust but verify, then verify again—except now, verification happens at machine speed by adversaries with infinite patience.
What’s your take? Are we overreacting to research, or is this an extinction-level event for unaudited DeFi protocols?
Sources: