0x5fb1b39a5fb1…5fb1b397

ConfirmedSecurity609 vB140 sat/vB3 min decode

Anthropic AI Agents Exploit 56% of Vulnerable Smart Contracts

Anthropic researchers reported AI agents built on the company's models exploited 56% of vulnerable smart contracts in a controlled study, raising questions about automated security testing in DeFi.

Thursday links: Prediction markets, agent hackers, quantum risks
WitnessThursday links: Prediction markets, agent hackers, quantum risksAI-generated

Outputs

  1. Anthropic researchers reported AI agents exploited 56% of vulnerable smart contracts in a controlled study

  2. The 56% figure measures successful exploitation, not detection, on a pre-vetted sample

  3. The finding was disclosed in a weekly research roundup; model versions, corpus, and researcher names were not specified

  4. If replicated, the result implies cheaper continuous adversarial testing and tighter bug-bounty pricing for DeFi protocols

  5. Independent replication on public corpora is required before 56% can be treated as a reproducible benchmark

Anthropic researchers reported that AI agents built on the company's models successfully exploited 56% of vulnerable smart contracts in a controlled study, according to a weekly research roundup cited by industry observers.

The finding, attributed to Anthropic's own research team, frames the company's models as capable of identifying and weaponizing flaws in smart contracts with limited human supervision. The agents were tested against a sample of contracts previously identified as vulnerable, and the 56% figure refers to the share they were able to compromise end-to-end.

For DeFi protocols and security teams, the result raises operational questions on two fronts. Automated discovery could compress the window between deployment and patch, reducing the value of latent vulnerabilities. The same capability, however, lowers the technical cost for adversaries scanning unaudited deployments.

What did the agents actually do?

The 56% success rate measures exploitation, not detection. The agents worked from a pre-vetted sample of contracts known to carry bugs, then attempted to weaponize those bugs. That distinction matters: a high success rate against confirmed-vulnerable contracts is a different signal than a wide-net scan over a large unfiltered corpus.

The research, as described in the roundup, did not specify the model versions, the contract corpus, or the names of the researchers. Independent replication with public datasets will determine whether 56% is a structural feature of how agents approach known-vulnerable code, or a function of the particular sample Anthropic selected.

What does this change for protocol teams?

The dual-use character of the finding is the operative point. Anthropic has previously published on the offensive potential of its own systems, arguing that capabilities used to find flaws can equally be turned against production deployments. The smart-contract benchmark extends that pattern into a domain with direct financial stakes and active adversaries already operating on-chain.

Three operational consequences follow if the 56% figure holds in independent testing:

  • Continuous adversarial testing of in-house code becomes cheaper to run.
  • Bug bounty programs need to price against AI-assisted adversaries, not only human researchers.
  • Disclosure timelines tighten, since automated discovery compresses the period during which a flaw remains unknown to defenders.

What does the market signal?

Security researchers and audit firms have warned for two years that the pace of new deployments across major smart-contract platforms outstrips the supply of senior reviewers. If agent-driven testing replicates a mid-level auditor's workflow, the marginal cost per audit falls. The bottleneck shifts from finding flaws to triaging them and producing fixes on deadline.

Protocols that rely on obscurity — or on the assumption that attackers lack tooling — will need to recalibrate. The on-chain exploit economy has historically rewarded speed; the Anthropic data point suggests the floor on attacker capability is moving upward.

What is not yet known

The roundup did not specify the contract languages tested, the exploit categories attempted, or whether the agents used retrieval over public audit reports. Without those details, the 56% figure is a headline number rather than a reproducible benchmark.

Anthropic did not respond to immediate requests for clarification on methodology. The full research output, if published, will set the reference standard for follow-up work.

The forward signal

The next test is whether competing labs publish comparable figures on the same or overlapping corpora. Standardization of the benchmark matters more than any single percentage, because auditors and insurance underwriters need a shared reference to price risk on smart-contract exposure.

Until comparable data arrives, the working assumption for protocol teams is straightforward: the cost of finding a flaw has dropped, and the cost of leaving a flaw in production has not.

via Blockworks (Source)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles