A new arms race is unfolding across decentralized finance, and both sides are wielding the same weapon: artificial intelligence. In February 2026, OpenAI and Paradigm released EVMbench, a benchmark showing that GPT-5.3-Codex can now exploit 72.2% of known vulnerable smart contracts — up from 31.9...
"More than half of the blockchain exploits carried out in 2025 — presumably by skilled human attackers — could have been executed autonomously by current AI agents." — Anthropic Red Team, Smart Contract Security Research
A new arms race is unfolding across decentralized finance, and both sides are wielding the same weapon: artificial intelligence. In February 2026, OpenAI and Paradigm released EVMbench, a benchmark showing that GPT-5.3-Codex can now exploit 72.2% of known vulnerable smart contracts — up from 31.9% just six months earlier. Weeks later, a purpose-built defensive AI agent demonstrated it could detect vulnerabilities in 92% of historically exploited contracts, covering $96.8 million in exploit value. The capability gap between attack and defense is narrowing at a pace the industry has never seen.
The economic stakes are staggering. Crypto theft totaled $3.41 billion in 2025, with a single Bybit exchange hack accounting for $1.5 billion. The $128 million Balancer V2 exploit in November 2025 evaded 11 prior security audits. And in February 2026, the Moonwell lending protocol lost $1.78 million after AI-assisted "vibe coding" introduced an oracle misconfiguration that no human reviewer caught before deployment. These are not theoretical risks — they are the current operating environment for every protocol managing user deposits.
This report examines how AI is reshaping DeFi security from both the offensive and defensive sides, analyzes the economic incentives driving the arms race, and evaluates what protocols, auditors, and investors must do to survive a world where a $1.22 API call can break a smart contract.
Anthropic's red team published the most comprehensive study to date on AI-driven smart contract exploitation. Using SCONE-bench — a dataset of 405 contracts that were actually exploited between 2020 and 2025 — they demonstrated that Claude Opus 4.5, Claude Sonnet 4.5, and GPT-5 collectively developed exploits worth $4.6 million on contracts exploited after each model's training data cutoff. This is not pattern recognition on known bugs. These are novel attack constructions against vulnerabilities the models had never seen.
The economics make the threat existential. The average cost of an AI-powered exploit attempt is approximately $1.22 per contract. At that price, an attacker can systematically scan thousands of deployed contracts for pennies, identifying targets where the exploit value dwarfs the cost of discovery by orders of magnitude. The barrier to entry for smart contract exploitation has collapsed from "elite security researcher" to "anyone with an API key and a script."
When evaluated against 2,849 recently deployed contracts with no known vulnerabilities, both Sonnet 4.5 and GPT-5 uncovered two novel zero-day vulnerabilities and produced working exploits worth $3,694. The API cost for GPT-5 to find those zero-days was $3,476 — barely break-even, but this represents frontier capability that is improving at a rate of roughly 2x every 1.3 months.
The implication is clear: within 12 to 18 months, AI-driven exploitation will be profitable at scale against contracts that have passed traditional security audits.
In February 2026, OpenAI and Paradigm released EVMbench, the first standardized benchmark for evaluating AI agents on practical smart contract security tasks. Built from 120 curated vulnerabilities across 40 audits, EVMbench tests three distinct capabilities:
The results were sobering. In exploit mode, GPT-5.3-Codex achieved a 72.2% success rate, compared with 31.9% for GPT-5 released just six months prior. That represents a 126% improvement in exploit capability in half a year. Detection and patching scores were lower, revealing an asymmetry that favors attackers: AI models are currently better at breaking contracts than fixing them.
This asymmetry maps directly to the Balancer V2 exploit from November 2025. Despite 11 security audits from firms including OpenZeppelin, Trail of Bits, and Certora, a precision rounding error in the vault's swap calculations went undetected. The attacker chained multiple swaps using the batchSwap function, compounding microscopic rounding losses into massive price distortions, and drained over $128 million across Ethereum, Base, Polygon, and Arbitrum. At least 27 Balancer forks were also affected.
This is the type of vulnerability — subtle, multi-step, requiring compositional reasoning across contract interactions — where AI excels. Rounding errors that a human auditor might dismiss as negligible become exploitable goldmines when an AI can simulate thousands of chained transactions to amplify them.
On February 15, 2026, DeFi lending protocol Moonwell lost $1.78 million in a single exploit triggered by an oracle misconfiguration. Post-mortem analysis revealed that multiple commits in the governance proposal's pull requests were co-authored by Anthropic's Claude Opus 4.6. Security auditor Pashov publicly flagged the incident as a case study in AI-assisted Solidity development gone wrong.
The technical failure was deceptively simple. Instead of calculating the cbETH price in USD by multiplying the cbETH/ETH exchange rate by the ETH/USD price feed, the deployed code obtained only the cbETH/ETH exchange rate and treated that ratio as if it were already denominated in dollars. With cbETH's price artificially deflated in Moonwell's system, liquidators could repay approximately $1 of debt and seize collateral worth thousands in return.
Moonwell's risk manager contained further damage by reducing the cbETH borrow cap to 0.01 within hours, but the liquidations had already executed. The incident crystallized a growing industry concern: "vibe coding" — the practice of using AI to write production smart contract code with minimal human review — is creating a new class of vulnerabilities.
The debate is not about whether AI can write Solidity. It clearly can. The question is whether the humans reviewing AI-generated code possess sufficient expertise to catch the subtle logical errors that AI models introduce. As one security researcher noted: "Behind the AI is a person who checks the finished work, and possibly a security auditor. For this reason, blaming the neural network alone is incorrect — but the incident raises questions."
The same AI capabilities that enable exploitation are being weaponized for defense. A purpose-built security agent — layering domain-specific security methodology on top of frontier AI models — detected vulnerabilities in 92% of 90 historically exploited DeFi contracts, covering $96.8 million in exploit value. By comparison, a baseline GPT-5.1-based coding agent detected only 34%, covering $7.5 million.
The performance gap is instructive. Raw AI capability (the base model) is necessary but insufficient. The decisive factor is the security-specific methodology and tooling layered on top: structured vulnerability taxonomies, compositional reasoning frameworks for multi-contract interactions, and economic simulation of attack profitability. The lesson for the industry is that general-purpose AI tools are dangerously inadequate for security — but specialized systems represent a genuine step-change in defensive capability.
AI agents are particularly effective at two tasks that human auditors find time-consuming: tracing price dependency chains across multiple protocols and modeling the economic impact of flash loan-amplified manipulation. These are exactly the attack vectors that produced the largest losses in 2025 — the Balancer exploit's multi-step rounding amplification, the cross-protocol oracle dependencies that enabled the Moonwell drain.
The audit industry is responding. Major firms including Sherlock, OpenZeppelin, and CertiK are integrating AI-augmented audit workflows. OpenZeppelin reports that its new AI tools cut auditing time by 50%. Sherlock has launched a lifecycle security platform combining traditional audits with bug bounties and AI-powered continuous monitoring.
Traditional smart contract audits operate on a point-in-time model: a protocol pays $100,000 to $500,000 for an audit before deployment, receives a report, patches the identified issues, and proceeds. The Balancer exploit — which evaded 11 such audits — demonstrates the fundamental limitation of this approach. Contracts evolve through governance proposals, composability introduces new interaction surfaces, and market conditions create exploitation opportunities that did not exist at audit time.
AI enables a shift from point-in-time to continuous monitoring at economically viable price points. A DeFi protocol with $5 million in total value locked cannot justify a $200,000 audit. But $3,000 per month for continuous AI monitoring — which catches an estimated 80% or more of what a full audit would find — fundamentally changes the security economics of the long tail of DeFi.
The insurance implications are already materializing. Industry forecasts indicate that DeFi insurance protocols will begin requiring AI monitoring as a coverage prerequisite in 2026. Bug bounty platforms like Immunefi are integrating AI agents as first-pass reviewers. And regulatory bodies are beginning to recognize AI audits within compliance frameworks — a development that could standardize continuous security monitoring as a licensing requirement for protocols seeking institutional capital.
For protocols managing significant TVL, the calculus is straightforward. The expected loss from exploitation (probability of exploit multiplied by TVL at risk) now exceeds the cost of continuous AI monitoring by an order of magnitude. Security is no longer an expense — it is the single highest-ROI investment a protocol can make.
The AI security arms race has three direct implications for how capital should flow in DeFi:
1. Security infrastructure is undervalued. Protocols spend an average of 1-3% of treasury on security. Given that AI-driven exploitation is becoming systematically cheaper and more effective, this allocation should increase to 5-10%. Protocols that do not will face higher insurance premiums, lower institutional participation, and eventual catastrophic loss.
2. Composability is a liability until proven otherwise. The multi-protocol attack vectors that AI excels at exploiting — oracle dependencies, cross-protocol liquidation chains, flash loan amplification — are all products of DeFi's composability. Protocols must invest in formal verification of their composability surfaces, not just their internal logic.
3. Audit firms become AI companies or die. The traditional model of 3-5 security researchers spending 4-8 weeks on a manual audit cannot compete with AI agents that scan contracts in minutes. Firms that fail to integrate AI tooling will find themselves unable to deliver audits at the speed and depth the market demands. The winners in this space will be hybrid operations — deep human expertise directing and validating AI-generated analysis.
AI exploit capability is doubling roughly every 1.3 months. GPT-5.3-Codex's 72.2% exploit rate on EVMbench is up from 31.9% for GPT-5 six months earlier. The window for protocols to upgrade their security posture is measured in quarters, not years.
The cost of attack has collapsed. At $1.22 per contract for an AI-powered exploit attempt, systematic scanning of thousands of deployed contracts is economically trivial. DeFi's security model cannot rely on attacker friction as a defense.
Purpose-built defensive AI dramatically outperforms general tools. A specialized security agent detected 92% of historically exploited vulnerabilities ($96.8M in value) versus 34% ($7.5M) for a baseline model. Domain-specific methodology is the decisive factor.
"Vibe coding" is a systemic risk. The $1.78 million Moonwell exploit demonstrated that AI-generated smart contract code, deployed without rigorous human review, introduces subtle vulnerabilities that can evade standard governance processes.
Continuous monitoring replaces point-in-time audits. The Balancer V2 exploit, which evaded 11 security audits, proves that static audits alone are insufficient. AI-powered continuous monitoring at $3,000/month offers better coverage than $200,000 point-in-time audits for the majority of protocols.
Insurance and regulation will enforce AI monitoring. DeFi insurance protocols and regulatory bodies are moving toward requiring continuous AI monitoring as a prerequisite for coverage and compliance.
The AI-DeFi security arms race is not a future threat — it is the current reality. Every week that passes, AI models become better at both finding and exploiting smart contract vulnerabilities. The protocols that survive will be those that recognize security as their most critical infrastructure investment and adopt continuous AI monitoring before the next $128 million exploit, not after.
The economic logic is unforgiving. When the cost of attacking a contract drops below $2 and the potential payoff is measured in millions, the only viable defense is a system that operates at the same speed and scale as the attacker. Human auditors remain essential for complex architectural review and threat modeling, but they must be augmented — and in many cases led — by AI systems designed specifically for blockchain security.
DeFi's value proposition has always been permissionless, composable financial infrastructure. That proposition means nothing if the infrastructure can be broken by an API call. The industry's response to the AI security arms race will determine whether DeFi becomes institutional-grade infrastructure or remains a frontier market where catastrophic loss is an accepted cost of participation.