Zhixiong Pan|Dec 02, 2025 14:48
Models that compete with each other in business have tacitly stood in the same trench in terms of security assessment. Everyone is eager to figure out the economic consequences of letting go of the current strongest model and doing bad things.
To verify this, Anthropic also introduced its competitor OpenAI's GPT-5 as the core test object in its latest SCONE bench report. By reviewing real smart contract attack cases from the past five years, Anthropic directly quantified AI's malicious ability using "stolen funds".
one ️⃣ Competition collusion: GPT-5 becomes the industry wide 'attack benchmark'
The most interesting detail of this report is that Anthropic has also introduced its competitor OpenAI's GPT-5 into the core testing phase and deployed it as the main "vulnerability hunter" in actual combat.
This cross model tool application not only confirms that GPT-5 has become a de facto first-line benchmark in the industry, but also implies that a "adversarial symbiosis" relationship is forming among top-level models to verify security boundaries through mutual confrontation.
two ️⃣ Economic Singularity: AI Attacks Formally Achieve 'Positive ROI'
The most milestone data point in the report is the "net profit of $109" in the simulation calculation, which is the true positive benefit achieved by GPT-5 through fully automated mining of unknown vulnerabilities after deducting all API computing power costs.
This seemingly tiny number is actually the "singularity" of AI agent economics, marking the official implementation of fully automated network attacks in business logic, meaning that AI no longer needs human funding and can achieve infinite loops in the digital world solely through algorithms.
three ️⃣ Qualitative change in ability: evolving from "code generation" to "financial strategist"
Claude Opus 4.5 demonstrated astonishing high-order reasoning capabilities in attack testing, not only detecting code logic vulnerabilities, but also systematically sweeping all relevant liquidity pools to maximize the benefits of a single attack.
This proves that the current SOTA models already possess the Agent attribute of "maximizing the objective function". They are no longer just Copilots that assist in writing code, but independent decision-makers who can understand the Lego attributes of complex financial systems and formulate optimal arbitrage strategies.
four ️⃣ Moore's Law Reappearance: Exponential Collapse of Attack and Defense Time Windows
Experimental data shows that AI's attack capabilities are reproducing Moore's Law, with the amount of funds that models can steal doubling every 1.3 months over the past year, while the cost of mining a single vulnerability's token has decreased by 23% every two months.
The trend of "doubling capabilities and halving costs" means that in the field of cybersecurity, under a human centric defense mode, the pressure will become increasingly out of control.
The time window left for human developers to fix code is being filled by exponential growth in computing power.
five ️⃣ Zero day crisis: Generalized reasoning ability breaks through 'unknown domains'
Unlike the "post hoc analysis" that relied on historical data fine-tuning in the past, Sonnet 4.5 and GPT-5 successfully identified two previously unexplored zero day vulnerabilities in unopened contracts without any historical attack samples.
This proves to the AI community that universal logical reasoning and long-range planning capabilities can be significantly transferred to the field of network security, and any software code containing logical judgments, whether it is blockchain or traditional SaaS, is now a potential hunting ground for strong artificial intelligence.
six ️⃣ The ultimate defense line: the inevitable choice of using AI to control AI
The true revelation left by Anthropic at the end of the article is that as the cost of attacks approaches zero, the era of relying solely on human audit of code has completely come to an end.
The only way out is to use the same automation capabilities for defensive stress testing, because in the era of AI attack and defense, code that has not undergone AI adversarial testing is essentially a naked asset.
Share To
HotFlash
APP
X
Telegram
CopyLink