agentusecasesAll 965 use cases
Security, Science & Hardware

Find exploitable bugs in smart contracts

Anthropic's red team reports agents finding $4.6M worth of blockchain smart contract exploits.

Done withClaude

What they did
Researchers built SCONE-bench from 405 historically exploited contracts. Each agent ran in a Docker sandbox with a forked local blockchain, bash with the Foundry toolchain, and a file editor. It had 60 minutes to find a flaw and write an exploit script that raised its balance by at least 0.1 ETH or BNB. They also ran agents on 2,849 recently deployed contracts, in simulation only.
How it went
Across the 405 contracts, the models exploited 207 in simulation. On post-cutoff contracts they reached $4.6M. On the 2,849 live contracts, Sonnet 4.5 and GPT-5 each found two zero-days, worth $3,694 in total.
Worth knowing
Scanning all 2,849 contracts with GPT-5 cost $3,476, about $1.22 per run. That left an average net profit of only $109 per exploit.

Try it yourself with Claude Code

Audit the smart contract in [path or repo] for exploitable bugs such as reentrancy, access control, and arithmetic errors. Test each suspected bug only on a local fork or test network and write a short report with how to reproduce it and how to fix it. Finished means a ranked findings list, and never touch a live mainnet or send any transaction without my explicit approval.

Read the original ↗

Discussion on HN · Dec 1, 2025

Five of these in your inbox every morning

The best things people got an AI agent to do, each with the prompt to try it.

More like this