AIs Exploiting Smart Contracts
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述即可。 首先,我需要理解这篇文章讲的是什么。文章标题是“AI正在利用智能合约”,作者是Bruce Schneier。内容主要讲的是AI在网络安全中的应用,特别是如何自动利用智能合约的漏洞。 文章提到他们建立了一个基准测试SCONE-bench,里面有405个被实际利用过的智能合约。然后用Claude Opus 4.5、Claude Sonnet 4.5和GPT-5这些AI模型来测试这些合约,结果发现这些模型能够找到漏洞并造成经济损失,比如总共赚了460万美元。 此外,他们还测试了2849个新部署的合约,发现了两个零日漏洞,并且GPT-5在API成本上也表现不错。这证明了AI自主攻击的可行性,并强调了防御措施的重要性。 现在我要把这些信息浓缩到100字以内。重点包括:AI自动攻击智能合约的能力、基准测试SCONE-bench、发现漏洞和造成损失、零日漏洞、技术可行性以及防御的重要性。 可能的结构:先说AI自动攻击的能力,然后提到基准测试和结果,接着说发现了零日漏洞和损失情况,最后强调防御的重要性。 比如:“研究表明AI可自动攻击智能合约,在SCONE-bench基准测试中发现漏洞并造成460万美元损失。还能识别新合约中的零日漏洞,证明自主攻击可行,需加强防御。” 这样刚好100字左右。 </think> 研究表明AI可自动攻击智能合约,在SCONE-bench基准测试中发现漏洞并造成460万美元损失。还能识别新合约中的零日漏洞,证明自主攻击可行,需加强防御。 2025-12-11 17:6:5 Author: securityboulevard.com(查看原文) 阅读量:9 收藏

I have long maintained that smart contracts are a dumb idea: that a human process is actually a security feature.

Here’s some interesting research on training AIs to automatically exploit smart contracts:

AI models are increasingly good at cyber tasks, as we’ve written about before. But what is the economic impact of these capabilities? In a recent MATS and Anthropic Fellows project, our scholars investigated this question by evaluating AI agents’ ability to exploit smart contracts on Smart CONtracts Exploitation benchmark (SCONE-bench)a new benchmark they built comprising 405 contracts that were actually exploited between 2020 and 2025. On contracts exploited after the latest knowledge cutoffs (June 2025 for Opus 4.5 and March 2025 for other models), Claude Opus 4.5, Claude Sonnet 4.5, and GPT-5 developed exploits collectively worth $4.6 million, establishing a concrete lower bound for the economic harm these capabilities could enable. Going beyond retrospective analysis, we evaluated both Sonnet 4.5 and GPT-5 in simulation against 2,849 recently deployed contracts without any known vulnerabilities. Both agents uncovered two novel zero-day vulnerabilities and produced exploits worth $3,694, with GPT-5 doing so at an API cost of $3,476. This demonstrates as a proof-of-concept that profitable, real-world autonomous exploitation is technically feasible, a finding that underscores the need for proactive adoption of AI for defense.

*** This is a Security Bloggers Network syndicated blog from Schneier on Security authored by Bruce Schneier. Read the original post at: https://www.schneier.com/blog/archives/2025/12/ais-exploiting-smart-contracts.html


文章来源: https://securityboulevard.com/2025/12/ais-exploiting-smart-contracts/
如有侵权请联系:admin#unsafe.sh