Bankless
Bankless

AI Finds 70% of Smart Contract Exploits | Alpin Yukseloglu

AI is getting dangerously good at smart contract security. Faster than crypto is ready for. Alpin Yukseloglu joins Bankless to break down EVMBench (built with OpenAI), a benchmark testing whether AI agents can detect, patch, and exploit real fund-draining bugs and why the jump from ~12–13% exploit-f

Featured Speakers

Alpin Uxololu Guest

Topics Discussed

Episode Summary

Executive Summary: The conversation argues that AI will rapidly reshape crypto security, first as a short-term threat to smart contracts and later as a major force for hardening the ecosystem. Alpin Uxololu says verifiable crypto environments make AI especially effective, so white hats and black hats will both accelerate, but the industry can shape outcomes through agency, faster adaptation, and better benchmarks like EVM Bench.

Main Topics: AI as a short-term security threat and long-term booster (Priority: 5/5): The discussion centers on AI’s growing ability to detect, patch, and exploit smart contract bugs. In the near term, this raises exploit risk; in the long term, it should increase crypto’s carrying capacity by making systems more secure. EVM Bench and measurable smart contract security (Priority: 5/5): Alpin explains the benchmark’s design: a verifiable environment using historical critical bugs, with detection, patching, and exploit tasks. The benchmark lowers false positives by requiring proof-of-concept exploitation in a production-like EVM. Verifiability as crypto’s strategic advantage (Priority: 5/5): Crypto is unusually suited to AI improvement because outcomes can be objectively tested. The transcript repeatedly contrasts verifiable tasks with unverifiable ones, arguing this makes crypto a natural training ground for frontier models. Agency, speed, and staying sane near the singularity (Priority: 4/5): A long philosophical section argues that doomers and accelerationists both surrender agency. The right response is to build, experiment, and move fast rather than freeze in abstract speculation about superintelligence. Which contracts and protocols are most exposed (Priority: 4/5): Small-cap, low-TVL, long-tail protocols on EVM/Solidity are seen as most at risk first, while battle-tested OG contracts are safer but still vulnerable. The first major AI-driven exploit could serve as a canary for the whole sector. Crypto labs, benchmarks, and industry adoption (Priority: 4/5): The team hopes EVM Bench pushes AI labs to treat crypto as a serious evaluation target. The speaker says stigma, reputational volatility, and liability have slowed adoption despite the richness and verifiability of crypto data. Crypto’s future role in an AI-driven world (Priority: 4/5): The conversation closes by arguing that AI and crypto are mutually reinforcing. As intelligence and goods become commoditized and geopolitical instability rises, extra-sovereign, verifiable financial rails should become more valuable.

Key Arguments: AI security capabilities are improving extremely fast; benchmark performance reportedly rose from roughly 12-13% to over 50%, then over 70% during the project. Crypto is unusually verifiable, so AI systems can improve faster here than in subjective domains like poetry or humor. Short-term AI risk depends on who gets access first, but the industry is already used to adversarial pressure and can harden faster than expected. Small, obscure protocols are likely to be exploited first because AI lowers the cost of finding and executing attacks. Benchmarking matters because labs optimize what they can measure; crypto needs credible evaluations to become a priority inside model labs. Agency is the practical response to uncertainty: experiment, ship, and work with frontier labs instead of speculating in the abstract. Formal verification and AI-assisted verification could become increasingly important as software volume outpaces human review capacity. AI and crypto are structurally aligned: agents need fast, reliable, verifiable rails, which points them toward blockchains and smart contracts.

Data Points: Initial bug-finding rate: 12-13% - Early EVM Bench results showed frontier models finding less than 20% of critical smart contract bugs. Mid-project bug-finding rate: Over 50% - Model performance improved substantially while the benchmark was being developed. Latest bug-finding rate: Over 70% - By the time of launch, the newest model version reportedly exceeded 70% on exploit detection. Time horizon to superhuman auditor: 6-8 months / by end of year - Alpin says he is confident a superhuman AI auditor may arrive within this timeframe. Assets referenced in crypto contracts: Nearly $100 billion - Mentioned as the value of assets housed in contracts that may need hardened defenses. Emerging market annual yield: Over $115 billion - Used in a sponsor segment to illustrate on-chain access to real-world yield opportunities. Emerging market yield range: 10-40% - Sponsor segment describing the yields currently available in emerging market money markets. Galaxy assets on platform: Over $12 billion - Sponsor ad describing Galaxy’s institutional digital asset platform. Galaxy loan book: $1.8 billion average in late 2025 - Sponsor ad highlighting Galaxy’s lending activity. Galaxy Helios power capacity: More than 1.6 gigawatts - Sponsor ad describing Galaxy’s AI/HPC data center campus. Bitget tokenized stock trading volume: Over $18 billion - Sponsor ad for tokenized equities trading volume. Bitget market share: Close to 90% - Sponsor ad claiming dominance in an Ando tokenized stock spot market.

Pivotal Quotes: "In the long term, I think it massively increases the carrying capacity of crypto." — Alpin Uxololu: He argues AI-driven security improvements will let the industry safely support more value and complexity. "I think the core point is that agency, right?" — Alpin Uxololu: He uses agency as the antidote to fear, doom, and paralysis when thinking about AI and the singularity. "The best path forward is through there. Like, if you are intimidated by everyone else having agency because of these tools, you can have agency yourself." — Alpin Uxololu: He urges listeners to build, experiment, and participate rather than become passive observers.

Implications: Crypto teams should treat AI security as an imminent operational risk and a major opportunity. Expect faster exploits, better defenses, more formal verification, and stronger pressure to harden long-tail contracts and protocol layers.

🔓 Sign Up for Unlimited Episode Search

About Bankless

View all episodes from Bankless