A study by Cecuro compared a baseline GPT-4.1-based coding agent against a purpose-built AI security agent on 90 exploited DeFi contracts representing $96.8 million in exploit value. The baseline agent detected only 34% of vulnerabilities, while the specialized agent detected 92%. The research highlights that general-purpose AI and traditional point-in-time audits are insufficient for smart contract security, as offensive AI agents can already autonomously exploit known bug classes at scale. Key challenges for agents include lack of verifiable feedback, insufficient systematic coverage, and context saturation. Recommendations include integrating AI-assisted security into CI/CD pipelines, combining LLMs with heuristics and static analysis, and adopting continuous rather than point-in-time audits.

4m read timeFrom securityboulevard.com
Post cover image
720 Impressions