AI-based tools are roughly twice as effective at exploiting smart contract vulnerabilities as they are at identifying them—this is the conclusion of a new Binance Research report, which highlights the growing gap between offensive and defensive capabilities in blockchain security.
According to the report, GPT-5.3-Codex demonstrates a 72.2% success rate in "exploit mode" on the EVMbench benchmark—a tool designed to evaluate AI agents' ability to detect, remediate, and exploit critical smart contract vulnerabilities based on 117 selected vulnerabilities from 40 audits. In "detection mode," the success rate is approximately half that figure.
The Cost of Attacks is Plummeting
The asymmetry is growing as the economics increasingly favor attackers. According to Binance Research, AI hacking tools cost an average of $1.22 per contract, a figure projected to decrease by 22% every two months. Smart contracts hold billions in user funds across decentralized finance protocols, and their open-source nature makes them ideal targets for automated scanning—AI systems can analyze thousands of contracts in minutes at minimal cost.
Data from Chainalysis shows that AI-powered fraud yields 4.5 times more money per case compared to traditional schemes and generates nine times more transactional activity, indicating that fraud has been industrialized. The crypto sector accounts for 88% of all detected deepfake fraud cases worldwide, and the number of impersonation attacks in 2025 grew by 1,400% year-over-year.
A Brutal Year for DeFi Security
These findings come amid severe security challenges for the crypto market. In the first 18 days of April 2026 alone, protocols lost over $606 million to hacks and exploits—nearly four times the total for the entire first quarter. Just two attacks—on Drift Protocol and Kelp DAO—accounted for 95% of the total damage. Cumulative losses from crypto attacks over the last decade have reached $17.1 billion across 518 incidents.
Cecuro, an AI cybersecurity firm, analyzed 90 hacked DeFi smart contracts with total losses of $228 million and found that its specialized AI agent identified vulnerabilities in 92% of these contracts—including those that had previously passed professional human audits. TRM Labs analysts have also begun suggesting that North Korean hackers are integrating AI into reconnaissance and social engineering operations, which may explain sophisticated attacks like the Drift Protocol exploit.
The Defense Dilemma
The imbalance between offense and defense creates a structural problem for an industry investing heavily in security. About 60% of industry representatives cited the growing use of AI by criminals as the top factor increasing risk. Academic research has shown that AI exploitation agents become economically viable at just $6,000 of extractable value, whereas defenders require approximately $60,000 to break even against the same class of attack—a 10-to-1 asymmetry in favor of the attackers.
As one security analyst noted, the most dangerous vulnerability in the crypto industry may no longer be in the code itself—but in the AI layer that interprets and interacts with that code.
month
week
day