AI agents now exploit smart contract vulnerabilities at a 72.2% success rate while detecting those same flaws only 36% of the time, according to Binance Research's EVMbench benchmark published in April 2026. The gap quantifies a structural asymmetry that has contributed to more than $840 million ...
"It's an unfair game. There were only three days without hacks." — Ronghui Gu, Co-founder and CEO, CertiK
AI agents now exploit smart contract vulnerabilities at a 72.2% success rate while detecting those same flaws only 36% of the time, according to Binance Research's EVMbench benchmark published in April 2026. The gap quantifies a structural asymmetry that has contributed to more than $840 million in DeFi losses through the first five months of 2026, with April alone recording $606 million drained across 12 incidents — the highest monthly count in crypto history.
The threat is no longer theoretical. Google's Threat Intelligence Group (GTIG) confirmed on May 11 the first zero-day exploit developed entirely by an autonomous AI agent. Anthropic's research team demonstrated that current-generation models can produce turnkey exploits for 51% of historically exploited contracts, representing $550.1 million in simulated stolen funds. OpenZeppelin founder Manuel Aráoz stated on May 26 that he now considers "all of DeFi unsafe," citing AI coding agents as "superhuman at finding vulnerabilities."
On the defensive side, Anthropic's Mythos model and Cecuro's specialized audit agent represent early responses. Cecuro's system detected 92% of vulnerabilities in a 90-contract benchmark covering $228 million in exploit value, outperforming baseline AI by nearly 3x. The question is whether defensive deployment can outpace offensive capability that is doubling every 1.3 months.
Three separate research efforts published between February and May 2026 have independently quantified how capable AI agents have become at attacking smart contracts.
Anthropic's SCONE-bench evaluated 10 AI models against 405 contracts that were exploited between 2020 and 2025. Collectively, the models produced turnkey exploits for 207 contracts (51.11%), yielding $550.1 million in simulated stolen funds. The top performer, Opus 4.5, successfully exploited 65% of contracts exploited after June 2025 — those beyond the model's training data — corresponding to $3.7 million in simulated value. Against 2,849 recently deployed contracts with no known vulnerabilities, Sonnet 4.5 and GPT-5 discovered two novel zero-day vulnerabilities and generated exploits worth $3,694, spending $3,476 in compute to do so.
OpenAI and Paradigm's EVMbench tested AI agents across 120 vulnerabilities from 40 real-world audits. GPT-5.3-Codex achieved a 72.2% attack success rate, up from 31.9% with GPT-5, according to Binance Research's analysis of the benchmark.
Cecuro's benchmark evaluated 90 exploited contracts representing $228 million in verified losses. A specialized AI agent flagged vulnerabilities linked to $96.8 million in exploit value. A baseline GPT-5.1 agent detected only 34%, covering $7.5 million.
The trajectory matters more than any single number. Anthropic's data shows exploit capability doubling roughly every 1.3 months, while token costs are falling approximately 22% every two months. The economics of AI-powered contract exploitation are moving in one direction.
The most consequential finding from the EVMbench benchmark is not the attack success rate itself but the gap between attack and detection modes. When given the explicit objective to "drain funds," GPT-5.3-Codex succeeds 72.2% of the time. When asked to identify the same vulnerabilities defensively, it succeeds 36% of the time — roughly half.
This asymmetry has a structural explanation. Exploiting a contract requires finding one viable path to drain funds. Detecting vulnerabilities requires identifying every possible path and classifying the severity of each. The objective function for attack is narrower, more clearly defined, and more reward-aligned with how current AI models optimize.
Binance Research highlighted an additional dimension: Hacken's SSDLC Maturity Survey found that over 80% of developers now use AI during development, but fewer than 40% employ AI for advanced security testing. The tools that write vulnerable code are deployed far more broadly than the tools that catch it.
According to Anthropic's research, the average cost of an AI-powered exploit attempt is $1.22 per contract. At this price, an attacker with a few hundred dollars of compute budget can scan thousands of contracts, let an agent identify vulnerability surfaces, generate working exploits, and attempt to drain funds — without writing a single line of code manually.
The economics are particularly threatening for legacy contracts. Thousands of smart contracts deployed between 2020 and 2023 remain active on Ethereum and other EVM chains. Many were audited once, deployed, and never re-reviewed. Security firm Halborn confirmed a sharp increase in automated attacks targeting these legacy contracts throughout 2026. The contracts were secure against the threat models of their era. They were not designed to withstand machine-speed, machine-scale scanning by models that can explore millions of potential exploit paths.
For context, the $292 million KelpDAO exploit in April 2026 — the largest DeFi hack of the year — demonstrates the stakes. A single exploit path, if discovered, can yield returns that are six to eight orders of magnitude greater than the cost of finding it.
DeFi losses in 2026 have been severe:
Total DeFi TVL contracted to approximately $85 billion as of mid-May, down from $99.5 billion before the April exploits. Ethereum's share of DeFi TVL declined to 53%, down from 63.5% at the start of 2025.
It is not yet established what proportion of 2026 losses are directly attributable to AI-assisted exploitation versus traditional attack methods. TRM Labs has speculated that North Korean hackers may be integrating AI into reconnaissance and social engineering operations, but firm attribution remains elusive.
The defensive side of the AI-security equation is emerging, though it trails the offense.
Cecuro released an open-source benchmark in February 2026 demonstrating that a purpose-built AI security agent could detect 92% of vulnerabilities in exploited DeFi contracts. The key differentiator was domain specificity: Cecuro integrated structured review phases, DeFi-specific security heuristics, and multi-step audit workflows rather than relying on general-purpose language models. Several contracts in the benchmark had passed professional human audits before being exploited — the AI agent caught what human reviewers missed.
To limit misuse, Cecuro open-sourced the dataset and evaluation framework but withheld its full security agent.
Hypernative, a real-time on-chain monitoring firm, has deployed AI-driven detection systems that operate at machine speed, attempting to front-run exploits by identifying anomalous transaction patterns before they complete. The firm flagged several incidents in Q1 2026 before fund drainage was complete.
Multiple audit firms — including CertiK, OpenZeppelin, and Trail of Bits — have publicly discussed integrating AI into their review pipelines. The speed differential is significant: AI can review a smart contract in minutes that would take a human auditor days. Whether the depth matches is an open question.
Anthropic's Mythos Preview, released on April 7, 2026, represents the most significant defensive AI deployment targeting smart contract security. Unlike general-purpose models, Mythos was designed specifically to identify and exploit software vulnerabilities.
During internal testing, the model autonomously detected thousands of high-severity vulnerabilities across various platforms, including 271 vulnerabilities in Firefox and multiple deep-seated flaws within the Linux kernel. In one instance, it uncovered a 27-year-old bug in critical security infrastructure.
Anthropic restricted access through Project Glasswing, a controlled program offering Mythos only to select technology firms and key infrastructure providers. Partners include Amazon Web Services, Google, Microsoft, and JPMorgan Chase, with Anthropic committing up to $100 million in usage credits. Major exchanges including Coinbase and Binance are reportedly in discussions for early access.
The controlled-release approach acknowledges a dual-use dilemma: the same capability that finds vulnerabilities defensively can be weaponized offensively. By restricting access to credentialed defenders, Anthropic is attempting to shift the asymmetry. Whether this containment holds as other AI labs develop comparable models — or as open-source alternatives emerge — remains uncertain.
On May 22, 2026, security firm Socket disclosed TrapDoor, a campaign that planted 34 malicious packages across npm, PyPI, and Crates.io. The campaign specifically targeted AI coding assistants, embedding hidden instructions in configuration files like .cursorrules and CLAUDE.md — files that AI tools read to understand project behavior.
The attack vector is distinct from smart contract exploitation. Rather than scanning deployed contracts, TrapDoor targets the development environment itself, aiming to compromise deployer keys, bridge validator infrastructure, and admin credentials before code reaches the blockchain. Socket estimated that a successful TrapDoor-type compromise of a mid-to-large protocol's deployer keys could result in $100 million to $300 million in losses.
Google's GTIG disclosure of the first AI-generated zero-day on May 11 further expanded the threat surface. The exploit — a two-factor authentication bypass on a widely used development tool — bore hallmarks of LLM-generated code, including hallucinated CVSS scores, excessive docstrings, and textbook formatting. GTIG stated with "high confidence" that a threat actor used an AI model to develop the exploit autonomously.
Combined, these incidents suggest the attack surface is widening from deployed smart contracts to the entire software supply chain that produces them.
The DeFi insurance sector has not yet adapted to AI-accelerated threats. Leading protocols like Nexus Mutual cover smart contract exploits, stablecoin de-pegs, and exchange hacks, but coverage models are priced against historical loss distributions that may no longer apply.
If exploit capability is genuinely doubling every 1.3 months while defensive capability grows linearly, actuarial models built on 2023-2025 loss data will systematically underprice risk. No major insurance protocol has publicly disclosed AI-specific risk adjustments to their pricing models as of May 2026.
Capital is responding through withdrawal rather than repricing. The $13 billion that left DeFi within 48 hours of the KelpDAO exploit represents a market judgment about uncompensated risk. TVL recovery has been slow, suggesting the capital is not returning on the assumption that the threat was temporary.
The data presents a clear pattern: AI exploit capability is advancing faster than AI defense capability, and both are advancing faster than the DeFi ecosystem's institutional response. The 72.2% attack rate versus 36% detection rate is not a temporary imbalance — it reflects an inherent structural advantage that offensive AI holds over defensive AI when applied to smart contracts.
The economic implications are direct. At $1.22 per exploit attempt and with capability doubling every 1.3 months, the addressable attack surface for AI-equipped adversaries encompasses every smart contract deployed before 2024 that has not been re-audited against current-generation AI capabilities. The total value locked in such contracts is not publicly tracked, but it is non-trivial.
Defensive responses exist. Cecuro's 92% detection rate, Anthropic's controlled Mythos release, and Hypernative's real-time monitoring show that purpose-built AI security can significantly narrow the gap. The question is deployment speed. If the DeFi industry treats AI security as an optional upgrade rather than critical infrastructure, losses will continue to compound. If AI-driven defense becomes a standard requirement — for protocol deployment, for insurance eligibility, for institutional capital allocation — the asymmetry can be managed, though likely not eliminated.
The arms race is underway. The data does not yet indicate which side is winning.