A convergence of three events in the past week has forced a reckoning over who — or what — will secure the $100 billion sitting in open-source smart contracts. On February 18, OpenAI and Paradigm released EVMbench, an open-source benchmark that revealed GPT-5.3-Codex can now exploit over 70% of c...
"It's now clear to us that a growing portion of audits in the future will be done by agents." — Alpin Yukseloglu, Partner, Investing & Research at Paradigm
A convergence of three events in the past week has forced a reckoning over who — or what — will secure the $100 billion sitting in open-source smart contracts. On February 18, OpenAI and Paradigm released EVMbench, an open-source benchmark that revealed GPT-5.3-Codex can now exploit over 70% of critical smart contract vulnerabilities — up from less than 20% when the project began. Two days later, AI security firm Cecuro published a parallel benchmark showing its specialized agent detects 92% of real-world DeFi exploits, dwarfing the 34% detection rate of general-purpose AI. And sandwiched between both announcements, the Moonwell lending protocol lost $1.78 million after attackers exploited a bug in code co-authored by Anthropic's Claude Opus 4.6 — the first major "vibe-coding" casualty in DeFi history.
These are not isolated incidents. They represent a structural shift in how value is attacked and defended on-chain. AI exploit capability is doubling roughly every 1.3 months, while the average cost of an AI-powered exploit attempt has collapsed to $1.22 per contract. The traditional audit industry — a $60,000-to-$250,000 engagement model built on human reviewers working over weeks — is being disrupted simultaneously from offense and defense. The question is no longer whether AI will reshape smart contract security, but whether defensive AI can scale fast enough to close the gap.
On February 18, OpenAI and Paradigm jointly released EVMbench, an open-source benchmark that tests AI agents across three critical tasks: detecting vulnerabilities in smart contracts, exploiting them in sandboxed environments, and patching flawed code without breaking functionality. The benchmark draws from 120 real-world vulnerabilities identified across 40 prior smart contract audits, with additional scenarios sourced from Paradigm's Tempo audit process.
The results are striking. GPT-5.3-Codex achieved a 72.2% success rate in exploit mode — meaning it could autonomously drain funds from nearly three-quarters of the vulnerable contracts it was tested against. By comparison, GPT-5, released just six months earlier, managed only 31.9%. That represents a 126% improvement in autonomous exploit capability in half a year.
Detection tells a different story. Anthropic's Claude Opus 4.6 led the detect category with an estimated detect award of $37,824 per vulnerability set, followed by GPT-5.2 at $31,623 and Gemini 3 Pro at $25,112. But even the top performers struggled with exhaustive auditing — agents frequently stopped after identifying a single issue rather than systematically scanning entire codebases.
Patching proved the weakest capability across all models. GPT-5.3-Codex, the top performer, successfully patched only 41.5% of vulnerabilities. As OpenAI acknowledged in the release: "Maintaining full functionality while removing subtle vulnerabilities remains challenging."
The asymmetry is unmistakable: AI is better at breaking smart contracts than fixing them.
Just days before EVMbench's launch, the lending protocol Moonwell provided a real-world demonstration of the risks. On February 16, attackers exploited a bug in a price oracle contract that had been co-authored by Anthropic's Claude Opus 4.6, draining approximately $1.78 million from the protocol.
The root cause was deceptively simple. The AI-generated code failed to multiply the cbETH/ETH exchange rate by the ETH/USD price feed, instead treating the raw exchange ratio as if it were already denominated in dollars. The result: cbETH, trading at approximately $2,200, was valued by the oracle at $1.12 — a 99.9% undervaluation. Attackers borrowed and withdrew assets against this artificially cheap collateral before mitigation measures could be deployed.
What makes the Moonwell incident significant is not the dollar amount — it is the failure mode. The AI-generated code was syntactically perfect. It compiled, it passed basic unit tests, and it cleared review by human developers, GitHub Copilot, and OpenZeppelin Code Inspector. The logic error sat in a category uniquely dangerous in adversarial environments: plausible but wrong. It is precisely the kind of bug that humans skim past and unit tests miss because the code "looks right."
Following the incident, Moonwell's governance submitted proposal MIP-X43 to integrate Chainlink's Oracle Extractable Value (OEV) wrapper contracts — essentially adding a second layer of oracle validation as a failsafe against future pricing errors. The incident has become the first widely cited example of "vibe-coding" — relying on AI to generate production code with minimal human scrutiny — causing material financial losses in DeFi.
Two days after EVMbench dropped, AI security firm Cecuro published its own benchmark with a more optimistic signal for defenders. Cecuro's purpose-built security agent detected vulnerabilities in 92% of 90 real-world exploited smart contracts, covering $228 million in verified losses across contracts exploited between October 2024 and early 2026.
The specialized system flagged vulnerabilities tied to $96.8 million in exploit value — compared with just 34% detection and $7.5 million in coverage from a baseline GPT-5.1-based coding agent. The 13x gap in dollar-value coverage between the specialized and general-purpose approaches underscores a critical finding: raw model intelligence is not enough. The difference, Cecuro argues, "was the application layer: domain-specific methodology, structured review phases and DeFi-focused security heuristics layered on top of the model."
Several contracts in Cecuro's dataset had previously undergone professional human audits before being exploited — a finding that challenges the assumption that manual audits remain the gold standard. To promote transparency, Cecuro open-sourced its dataset and evaluation framework on GitHub, though it withheld its full security agent "due to concerns that similar tooling could be repurposed for offensive use."
Anthropic's own research reinforces the dual-use tension. In a red-team study published via red.anthropic.com, Claude models successfully exploited 207 of 405 real-world vulnerable smart contracts deployed between 2020 and 2025 across Ethereum, BNB Smart Chain, and Base — extracting $550 million in simulated funds. In a smaller, more controlled evaluation, agents stole $4.5 million from 17 of 34 test contracts without any human guidance.
The data from EVMbench, Cecuro, and Anthropic's red-team research reveals a consistent pattern: AI models are significantly better at exploiting smart contracts than detecting or patching vulnerabilities. This asymmetry is structural, not accidental.
Exploiting is objective-driven. As OpenAI noted: "Agents perform best in the exploit setting, where the objective is explicit: continue iterating until funds are drained." The feedback loop is binary and immediate — either you drained the contract or you didn't.
Detection requires exhaustive coverage. Vulnerability scanning demands systematic, comprehensive analysis of every code path — not just the most obvious ones. Models tend to stop after finding one issue, missing compound vulnerabilities that require chaining multiple flaws.
Patching requires deep design understanding. Fixing a vulnerability means preserving correct behavior across edge cases, which requires understanding the developer's original intent and the protocol's broader design assumptions. This is the task least amenable to pattern matching.
The economic implications are stark. At $1.22 per AI-powered exploit attempt, the cost-to-attack is now negligible relative to the potential payoff. Protocols lost over $108 million to hacks and exploits in the first seven weeks of 2026 alone. With 669,500 new smart contracts deployed in a single recent week — down from a peak of 1.7 million weekly deployments in November 2025 — the attack surface continues to expand faster than the security apparatus can cover it.
AnChain.AI, a blockchain forensics firm, summarized the shift bluntly in its analysis of Anthropic's research: "Attack cost is approaching zero."
The traditional smart contract audit industry is built on a pricing model that AI is rapidly disrupting from both ends. A 2026 market reference from Sherlock estimates that a mid-complexity DeFi protocol audit costs $60,000 to $120,000 pre-launch, with simple token contracts at $5,000–$15,000 and enterprise-grade multi-chain systems exceeding $250,000. Rust, Cairo, and ZK-based contracts carry 30–120% premiums over EVM equivalents, and rush engagements add another 20–40%.
These are not trivial sums for early-stage protocols. The average loss per smart contract exploit over the past four years has been approximately $1.9 million — meaning a $60,000 audit pays for itself roughly 30x over if it catches a critical bug. But the Moonwell and Cecuro data suggest that even professionally audited contracts get exploited, calling the return on investment into question.
Three structural models currently compete for audit market share:
The direction of travel is clear. Paradigm's Alpin Yukseloglu stated it directly: "It's now clear to us that a growing portion of audits in the future will be done by agents." The question is whether the industry transitions gradually — with AI augmenting human auditors — or abruptly, as offensive AI capabilities force protocols toward automated, continuous security monitoring simply to keep pace with the threat.
The events of the past week crystallize a fundamental tension in DeFi's security model. The same AI systems that can detect 92% of historical exploits can also autonomously exploit 72% of critical vulnerabilities — and the offensive capability is improving faster. Smart contracts secure over $100 billion in assets with code that, once deployed, is immutable and permissionless. There is no "patch Tuesday" for on-chain code.
The traditional security model — periodic human audits before deployment, followed by bug bounties — was designed for a threat landscape where exploits required specialized human expertise and significant time. That assumption is now obsolete. When attack cost drops to $1.22 per contract and exploit capability doubles every 1.3 months, the only viable defense is continuous, automated, AI-driven monitoring that operates at the same speed and scale as the threat.
The $3.4 billion lost to crypto theft in 2025 was secured by the old model. What happens in 2026 depends on how fast the industry adopts the new one.