MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Purpose-built AI Security Agent Detected 92% of DeFi Contracts Vulnerabilities
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$68,955.004.42%
  • ethereumEthereum(ETH)$2,033.653.17%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$642.263.40%
  • rippleXRP(XRP)$1.391.38%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$86.983.37%
  • tronTRON(TRX)$0.2820970.30%
  • dogecoinDogecoin(DOGE)$0.0947952.40%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.64%
DeFi

Purpose-built AI Security Agent Detected 92% of DeFi Contracts Vulnerabilities

Last updated: March 2, 2026 3:20 pm
Published: 8 hours ago
Share

A baseline GPT-5.1-based coding agent may have only detected 34% of vulnerabilities in 90 exploited DeFi contracts, but a purpose-built AI security agent running on the same underlying model bested that by a long shot — detecting 92% of the vulnerabilities.

That, according to Cecuro, which examined 90 exploits occurring after September 30, 2024, into early 2026, amounted to $96.8 million in exploit value.

“These results demonstrate that deep domain expertise and agent optimization can 2-3x vulnerability detection performance over baseline agentic code review on the same underlying model,” according to a Cecuro blog post.

“Separately, frontier agents now execute end-to-end exploits on 72% of known vulnerable contracts, underscoring that offensive capability is advancing in parallel,” the researcher wrote, noting that “the benchmark dataset and the baseline agent are open-sourced; the full Cecuro Security Agent is not, given the risks of making autonomous exploit tooling publicly available.”

Explaining that 2025 crypto theft hit $3.4 billion, “of which $1.5 billion came from a single compromise of Bybit in February,” the researchers point to a massive issue in the security landscape of smart contracts that is not keeping up with the requirements of the financial systems it powers.”

But, they note, protecting smart contracts and Web3 cybersecurity typically proves “very challenging,” particularly because expert knowledge is in short supply. “The vulnerabilities that cause the largest losses are rarely obvious,” they wrote.

Deep expertise in programming languages, as well as governance mechanisms and DeFi protocol economics, is required to identify vulnerabilities. But that latter skillset “is scarce and highly sought after.”

Professional human audits can help, but are costly and time-consuming. Plus, they “only cover the codebase at a sign point in time,” resulting in projects lacking “full audit coverage” or simply skipping the process altogether.

“These findings show that DeFi contract security has now become an ‘attacker AI agents vs defenders AI agents’ regime for smart contracts,” says Mayuresh Dani, Security Research Manager at Qualy Threat Research Unit.

While “threat actors can already use agents to scan thousands of contracts and autonomously weaponize many known bug classes for a marginal cost per attempt,” Dani says, the benchmark “shows us that these need to be based on DeFi-specific heuristics and should contain protocol-aware detections.”

Cecuro’s study found three challenges that researchers say “consistently limited agent performance.” There is no verifiable feedback — discovery is difficult, “knowing where to look before you know what you are looking for.” In addition, there is no systematic coverage.

“Without domain-specific guidance, agents tend to follow shallow paths and spend their budget on surface-level patterns,” the researchers wrote. “In some runs, the basic agent traced a peripheral contract for most of its budget and never reached the vulnerable function.”

And, third, they noted context saturation and output variance. “A pattern we observed across runs is that agents tend to treat the review as complete once a handful of findings are flagged, even when large parts of the codebase remain unexamined,” the researchers said, something that “persists even with explicit planning mechanisms like todo tools and system reminders in place.”

The upshot? Detection is crucial. And AI can improve the odds. “Projects not using AI for defense are exposed in a way that simply was not true a year ago,” the researchers wrote. “AI-powered security review is available today at a fraction of the cost of a single audit, covering the vast majority of real-world exploit classes.”

And defenders must rise to the occasion…quickly. “We’re in the era of machine-speed exploits. Period. General-purpose AI and traditional ‘check-the-box’ security audits are a false comfort when the actual battle is moving in milliseconds,” says Ram Varadarajan, CEO at Acalvio.

Read more on Security Boulevard

This news is powered by Security Boulevard Security Boulevard

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

SEI Nears Golden Cross on 3-Day Chart Could a Bullish Rally Follow?
Solana News Heats Up With Staking ETF Launch — New Coin Projected to Join SOL Among the Top Altcoins
UK orders crypto platforms to log all user transactions starting 2026
Vitalik Buterin Explicitly Urges Prompt into Meaningful L2s Infrastructure – Tekedia
EigenCloud Expands Multi-Chain Capabilities with Enhanced AVS Design

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Bitcoin Resilient as Iran War Threatens Global Markets
Next Article Bitcoin bottom signal tips 130% rally, Morgan Stanley to custody crypto: Hodler’s Digest, Feb. 22 – 28
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d