Cecuro, an AI-based smart contract audit platform, reports a 91.45% vulnerability detection rate on the EVMBench test, highlighting the growing role of automated security tools as blockchain threats evolve
As blockchain adoption accelerates, the security of smart contracts has become a central concern for developers, investors, and users. Cecuro, a security audit platform that uses artificial intelligence agents, recently reported a 91.45% vulnerability detection rate on the EVMBench benchmark-a test suite developed by OpenAI and Paradigm to evaluate the effectiveness of AI systems in identifying and addressing smart contract vulnerabilities. This result, according to Cecuro, surpasses previous benchmarks and underscores the increasing sophistication of AI-driven security tools in the Web3 ecosystem.
AI in Smart Contract Auditing
Smart contracts, which automate transactions and logic on blockchains, are foundational to decentralized finance (DeFi), tokenization, and many consumer-facing crypto applications. However, flaws in smart contract code can lead to significant asset losses, as seen in numerous high-profile exploits. Traditional audits rely on manual code review by security experts, but the growing complexity and volume of contracts have driven demand for automated solutions. Cecuro's platform deploys multiple specialized AI agents in parallel, each analyzing smart contract code from a different perspective. The company says that every identified vulnerability is further validated using proof-of-concept (PoC) exploits and symbolic execution before being included in the final audit report.
Understanding the EVMBench Benchmark
EVMBench is a standardized benchmark designed to measure how well AI systems can detect, fix, and exploit vulnerabilities in Ethereum Virtual Machine (EVM)-compatible smart contracts. Developed by OpenAI and Paradigm, EVMBench includes 117 real-world vulnerability examples drawn from 40 professional security reviews, public bug bounty programs, and stablecoin projects. The benchmark evaluates AI tools on three criteria: identifying vulnerabilities, proposing fixes that preserve contract functionality, and generating working exploits to confirm the presence of flaws. This approach allows for objective comparison between different automated security solutions.
Performance and Market Context
Cecuro's reported 91.45% detection rate on EVMBench represents an improvement over its previous 87.17% result and, according to the company, maintains its lead among specialized AI audit platforms. For context, general-purpose large language models tested on EVMBench have achieved a maximum detection rate of 45.6%. Cecuro attributes its gains not to larger AI models, but to improved coordination among its AI agents, which the company claims increases both efficiency and accuracy. The platform supports a wide range of blockchain networks and smart contract programming languages, aiming to serve diverse developer teams.
According to Cecuro, a standard smart contract audit on its platform takes about eight hours, with roughly 180 AI agents running in parallel. Only vulnerabilities confirmed by both PoC and symbolic execution are included in the final report, which the company says helps reduce false positives. Audit reports start at $799, and Cecuro offers free trial options for new users. The platform's automated approach is positioned as a way to reduce the time and cost associated with traditional manual audits, though the company does not claim to eliminate the need for human review in all cases.
Security Risks and Industry Trends
The rise of AI-powered security tools comes as attackers themselves increasingly leverage advanced AI for cyberattacks. According to the UK AI Security Institute, the capabilities of AI-driven attacks are growing rapidly, and Anthropic has reported that the share of malicious actors using AI rose from 33% to 56% in a single year. Chainalysis forecasts that crypto theft could reach $3.4 billion in 2025, citing incidents such as the Bybit exchange hack in February. These trends highlight the escalating arms race between attackers and defenders in the blockchain space, and the need for more scalable, automated security solutions.
Recent data from Chainalysis shows that in 2024, smart contract exploits accounted for a significant share of total crypto losses, with DeFi protocols remaining a primary target. The increasing use of AI in both attack and defense underscores the importance of continuous improvement in security tooling. While platforms like Cecuro offer promising advances, users and developers should remain aware that no audit-manual or automated-can guarantee complete protection against evolving threats.
Smart contract security audits are a critical step for projects seeking to reduce risk before launch, but the effectiveness of any audit depends on the quality of the tools, the expertise of reviewers, and the evolving tactics of attackers. Automated platforms can help scale security analysis, but they should be seen as part of a broader risk management strategy that includes ongoing monitoring, bug bounties, and incident response planning.
For U.S. developers and companies, the adoption of AI-driven audit tools like Cecuro may help address resource constraints and accelerate time-to-market, but regulatory expectations around security, disclosure, and consumer protection remain high. As the technology matures, the interplay between automated and manual review will likely shape best practices for smart contract security in the years ahead.
Automated smart contract auditing platforms such as Cecuro are part of a broader trend toward using artificial intelligence to address blockchain security challenges. While these tools can rapidly analyze large volumes of code and identify many common vulnerabilities, they are not a substitute for comprehensive security practices. Developers should combine automated audits with manual review, continuous monitoring, and robust incident response to manage risk in an environment where both threats and defenses are evolving rapidly.