AI Agents Demonstrate Autonomous Exploitation of Blockchain Smart Contracts

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Research by Anthropic and collaborators shows advanced AI models, including GPT-5 and Claude variants, can autonomously identify and exploit vulnerabilities in Ethereum and DeFi smart contracts. In controlled simulations, these AI agents executed exploits worth hundreds of millions of dollars, highlighting an urgent risk of AI-driven financial harm to blockchain ecosystems.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly involves AI systems (frontier AI models) used to identify and exploit smart contract vulnerabilities. While the exploits were simulated and no actual harm occurred, the demonstrated capabilities and the discovery of zero-day vulnerabilities indicate a credible risk of future AI-driven cyberattacks causing real financial harm. The AI's role in weaponizing vulnerabilities and the potential for scaling attacks make this a plausible future harm scenario. Since no actual harm has yet occurred, it is classified as an AI Hazard rather than an AI Incident.[AI generated]
AI principles
AccountabilitySafetyRobustness & digital securityDemocracy & human autonomy

Industries
Financial and insurance servicesDigital security

Affected stakeholders
ConsumersBusiness

Harm types
Economic/Property

Business function:
ICT management and information securityResearch and development

AI system task:
Event/anomaly detectionGoal-driven organisationReasoning with knowledge structures/planning


Articles about this incident or hazard