AI Agent Automates the Exploitation of Smart Contract Vulnerabilities
2025-07-10

Researchers from University College London and the University of Sydney have developed an AI agent, A1, capable of autonomously discovering and exploiting vulnerabilities in smart contracts. A1 uses AI models from OpenAI, Google, DeepSeek, and Alibaba to generate exploitable Solidity contracts. Tested on 36 real-world vulnerable contracts, A1 achieved a 62.96% success rate on the VERITE benchmark and discovered additional vulnerabilities. The researchers highlight a 10x reward asymmetry between attack and defense, emphasizing the need for proactive security. While A1 shows significant profit potential, its open-source release is currently on hold due to concerns about its powerful capabilities.
Tech
exploit generation