Ly Gravity

Agent Hackers at the Gate: Anthropic's 56% and the End of Audit-Based Security Assumptions

BlockBlock Industry
The Thursday links roundup looked like noise. Prediction markets. Agent hackers. Quantum risks. Three bullet points in a digest designed to be skimmed and discarded. But one data point buried in that formatless wall of links deserves to be pulled out and examined under the full weight of its implications. Anthropic researchers deployed an AI agent against a set of vulnerable smart contracts. The agent autonomously discovered and exploited vulnerabilities in 56% of them. Let that number breathe. More than half. Without human intervention. Without a pre-documented exploit path. Without the expensive, scarce labor of a human security researcher. The crowd sees a moon; I see a model. This is not a price signal. It is a security assumption fracturing in real time. For two years, the smart contract security industry has operated on a shared set of assumptions. Audits catch vulnerabilities before deployment. Rule-based scanners encode known attack patterns. The principal threat vector is a human attacker constrained by time, talent, and traceability. Those assumptions can no longer be held in their previous form. The research emerges from Anthropic, the AI safety lab founded by alumni of OpenAI and DeepMind. Institutional context matters here. Anthropic's mission is built around understanding and governing AI systems. When an institution with that mandate publishes empirical data about autonomous vulnerability exploitation, it carries a different weight than a blockchain security startup issuing a speculative whitepaper. This is a lab whose positioning depends on the credibility of its worst-case claims. They do not gain from exaggeration; they gain from being the first to see clearly. The experimental setup deserves attention. The test set consisted of deliberately deployed, known-vulnerable contracts in a sandboxed environment. The 56% figure represents the agent's end-to-end success rate: discovering the vulnerability, crafting an exploit, and executing it autonomously. This is not equivalent to saying the agent could compromise 56% of live DeFi protocols on mainnet. The distance between a controlled sandbox and a production environment with proxy patterns, access controls, monitoring systems, and economic defenses is substantial. But the direction of travel is unmistakable. To understand why this matters, you must understand the history of smart contract security tooling. The current generation of audit tools is fundamentally retrospective. Slither, Mythril, and their descendants operate by matching code against known vulnerability patterns. They encode the past. If a vulnerability has been seen before, the tool will find it. If it is novel, the tool is silent. This is not a criticism. It is the correct design for a world where attackers are humans who reuse successful techniques. The tooling matches the threat model. An AI agent is different. Language models and agent architectures can reason across patterns, compose multi-step attack strategies, and adapt to a contract's specific structure. The 56% success rate implies transferability. The ability to generalize beyond known patterns to unfamiliar contexts. That is the difference between a scanner that finds last year's bugs and an agent that finds tomorrow's. Based on my experience auditing Golem's tokenomics back in 2017, I learned to look for the structural flaw beneath the surface narrative. The structural flaw in the current security paradigm is not any specific vulnerability class. It is the assumption that vulnerability discovery remains expensive enough to be rate-limited by skilled human labor. AI agents are about to make that assumption historical. Let me decompose what the 56% actually means across three dimensions. First, the economics of attack have inverted. The traditional vulnerability exploitation cycle has a cost structure that favors defenders. Finding a high-quality exploit requires skilled researchers. It takes days, sometimes weeks. The labor is expensive, scarce, and increasingly traceable. That scarcity creates a natural defense: attackers can only cause a certain amount of damage because they can only find a certain number of holes. Math does not care about your conviction. But math cares deeply about marginal costs. AI agents collapse the marginal cost of finding and exploiting vulnerabilities toward zero. A tool that compromises 56% of vulnerable contracts at scale does not need to be perfect. It needs to be cheap enough to run against every contract in the ecosystem. The economics shift from find the one valuable target to spray the entire ecosystem and see what breaks. This is the invariant to track: not whether AI agents become better than human attackers, but whether they become cost-effective enough to deploy at ecosystem scale. The 56% figure suggests we are at that threshold. Second, the audit industry faces a structural challenge that it has not yet internalized. Every smart contract audit is, at its core, a probabilistic claim: we have examined this contract according to our methodology and found no exploitable vulnerabilities. The validity of that claim depends on the auditor's ability to find vulnerabilities being at least comparable to the attacker's ability to find them. An AI agent with 56% autonomous exploitation capability breaks that symmetry. If an attacker can deploy an agent that probes for exploitable flaws, the auditor needs an equivalent capability merely to maintain the previous level of assurance. The bar rises for everyone simultaneously. Audit reports function as institutional artifacts. Insurance policies are priced on them. Investment committees check them. Risk teams calibrate exposure based on their conclusions. If the underlying attack technology has advanced but the audit methodology has not, then those artifacts are measuring the wrong threat model. Solitude is the price of clear vision. The industry does not want to hear that the half-million-dollar audit they commissioned may be insufficient in an agent-driven threat landscape. But the data is what it is. I saw the same dynamic in DeFi Summer 2020, when high APYs masked systemic liquidity risk. The market refused to discount what it could not see, until the yield curve itself collapsed. Audits will experience a similar repricing, not in dollars but in confidence. Third, the asymmetry between offense and defense is widening structurally. Offensive AI only needs to find one reliable vulnerability in one contract to achieve its objective. Defensive AI must cover every potential vulnerability across every contract, and the defender can never relax. Attackers iterate in private, testing and refining their agents without scrutiny. Defenders publish their defenses, revealing their assumptions to anyone who cares to look. This asymmetry has a name: the attacker's advantage. AI amplifies it because agents can run thousands of parallel attempts, learn from each failure, and improve. The 56% is a snapshot, not a ceiling. The best agents Anthropic has today will be the weakest agents the ecosystem faces in eighteen months. The informational risk is equally significant. Once research of this kind is published, it cannot be unlearned. The approach, the architecture, and the success metrics are now public knowledge. Researchers will reproduce, modify, and improve upon this work. So will scammers. So will state-sponsored groups. The disclosure is itself an event with consequences. A dynamic familiar in the traditional security community, but largely unexamined in the crypto ecosystem, which has historically relied on obscurity and novelty as informal defenses. The same Thursday links column that surfaced this research also nodded toward prediction markets and quantum risk. The three topics are not unrelated. Prediction markets monetize the probability of future events. Quantum risk threatens the cryptographic foundations of the chain. Agent hackers threaten the application layer that carries actual value. Each represents a different horizon of the same underlying truth: the cryptographic commons has entered an era of machine-speed adversaries. But here is the part of the analysis that most commentary ignores. The same reasoning capability that finds vulnerabilities can be redirected defensively. AI agents can be built to audit contracts continuously, simulate attack paths before deployment, monitor on-chain behavior for anomalies, and respond to threats faster than any human team. The technology has no inherent moral orientation. It takes its shape from the incentives of whoever deploys it. In the chaos, look for the invariant. The invariant here is that security in Web3 has always been a resource game. Protocols with more resources obtain better audits, more monitoring, faster response, and deeper talent. AI agents will amplify this pattern. Adoption will come fastest among well-capitalized protocols and professional security firms. The long tail of DeFi, including small protocols, experimental contracts, and unaudited code, will face the greatest exposure with the fewest defenses. This is where the dominant narrative deceives. When you read that AI agents can exploit smart contracts, the imagination runs to dramatic heists and billion-dollar losses. The more probable scenario is less cinematic but more consequential: a statistical grind against the long tail of poorly defended contracts. The 56% will first express itself not in a single spectacular exploit but in the quiet, compounding loss of small pools, experimental protocols, and community projects that cannot afford AI-grade defense. There is also a subtler institutional dynamic at work in the disclosure itself. Anthropic is a leading AI lab operating in a competitive landscape. Publishing vulnerability research positions them as the responsible actor. The institution that surfaces hard truths, understands emerging threats, and can partner with policymakers and enterprises on AI security. The same publication that warns the ecosystem about autonomous exploitation simultaneously reinforces Anthropic's credibility as the institution best positioned to address it. Narratives are liquid; truth is solid. The extractable truth is that serious actors must now build defensive capability that at least matches what Anthropic has demonstrated offensively. Now the contrarian angle. The most common interpretation of the 56% figure is that all smart contract funds are at imminent risk. That is probably wrong, at least on the immediate horizon. The experiment was conducted against known vulnerable contracts in an isolated environment. Production mainnet environments add layers of complexity: proxy patterns, access controls, multi-signature ownership, operational monitoring, insurance backstops, and the economic cost of failed attempts. The agent did not need to operate stealthily in the lab. It did not need to avoid triggering alarms or optimize gas usage. The chain from exploited a vulnerable contract in a sandbox to stole funds from a live protocol protected by multiple defensive layers is long, uncertain, and full of failure points. The more interesting contrarian observation is that the greatest exposure does not belong to the major protocols. It belongs to the unguarded middle. Protocols with security budgets will adapt. Protocols with none will not. The 56% figure is, in effect, a tax on underinvestment in security intelligence. If it becomes deployable at scale, its first measurable victim will be the sector's weakest links. The same segment that is least visible in market narratives and least represented in governance discussions. There is also a regulatory thread worth pulling. Dual-use technologies attract governance attention. An AI system that autonomously discovers and exploits vulnerabilities sits at exactly the intersection of cyber-defense research and offensive capability that regulators structure export controls around. The Computer Fraud and Abuse Act does not exempt AI agents acting on behalf of researchers. The absence of a clear framework for responsible AI-driven vulnerability research creates a gray zone: too much disclosure risks providing attack tooling; too little disclosure leaves defenders blind. The industry needs to engage with that policy question before an event forces the answer. The takeaway is not panic. It is recalibration. The protocols that survive this transition will be the ones that treat security as a continuous, adversarial process rather than a one-time certification. That means AI-assisted auditing, continuous monitoring, rehearsed incident response, and a healthy paranoia about what autonomous agents can do at scale. Based on my experience across the 2017 ICO era, the DeFi Summer of 2020, and the collapses of 2022, the pattern is consistent: the market prices narrative first and structure later. By the time the narrative stabilizes, the structural damage is already done. Quietly positioned while the world shouts: the signal here is not that AI agents can attack. The signal is that the security assumptions underpinning an entire industry were silently outdated before anyone bothered to test them. Coding the future, one block at a time. But only if we rebuild the defensive layer with the same seriousness as the attack surface.

Agent Hackers at the Gate: Anthropic's 56% and the End of Audit-Based Security Assumptions

Agent Hackers at the Gate: Anthropic's 56% and the End of Audit-Based Security Assumptions

Agent Hackers at the Gate: Anthropic's 56% and the End of Audit-Based Security Assumptions

Market Prices

BTC Bitcoin
$63,944.6 +0.80%
ETH Ethereum
$1,872.76 -0.48%
SOL Solana
$74.01 +0.50%
BNB BNB Chain
$592.4 +0.63%
XRP XRP Ledger
$1.08 +0.05%
DOGE Dogecoin
$0.0705 -0.11%
ADA Cardano
$0.1947 +3.78%
AVAX Avalanche
$6.58 -0.08%
DOT Polkadot
$0.8220 +3.21%
LINK Chainlink
$8.24 -1.27%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,944.6
1
Ethereum ETH
$1,872.76
1
Solana SOL
$74.01
1
BNB Chain BNB
$592.4
1
XRP Ledger XRP
$1.08
1
Dogecoin DOGE
$0.0705
1
Cardano ADA
$0.1947
1
Avalanche AVAX
$6.58
1
Polkadot DOT
$0.8220
1
Chainlink LINK
$8.24

🐋 Whale Tracker

🟢
0xef26...9908
12h ago
In
1,797 ETH
🟢
0xeeaf...cbfd
12m ago
In
4,774.49 BTC
🔵
0x4697...291f
6h ago
Stake
1,493,761 USDT

💡 Smart Money

0xd2b1...9c95
Market Maker
-$4.4M
77%
0xe7f1...2820
Arbitrage Bot
+$3.0M
90%
0xeafc...250b
Institutional Custody
+$4.1M
62%

Tools

All →