EVMbench: Evaluating AI Agents on Smart Contract Security

Justin Wang, Andreas Bigger, Xiaohai Xu, Justin W Lin, Andy Applebaum, Tejal Patwardhan, Alpin Yukseloglu, Olivia Watkins
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:125067-125099, 2026.

Abstract

Smart contracts on public blockchains now manage large amounts of value, and vulnerabilities in these systems can lead to substantial losses. As AI agents become more capable at reading, writing, and running code, it is natural to ask how well they can already navigate this landscape, both in ways that improve security and in ways that might increase risk. We introduce EVMbench, an evaluation that measures the ability of agents to detect, patch, and exploit smart contract vulnerabilities. EVMbench draws on 117 curated vulnerabilities from 40 repositories and, in the most realistic setting, uses programmatic grading based on tests and blockchain state under a local Ethereum execution environment. We evaluate a range of frontier agents and find that they are capable of discovering and exploiting vulnerabilities end-to-end against live blockchain instances. We release code, tasks, and tooling to support continued measurement of these capabilities and future work on security.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-wang26k, title = {{EVM}bench: Evaluating {AI} Agents on Smart Contract Security}, author = {Wang, Justin and Bigger, Andreas and Xu, Xiaohai and Lin, Justin W and Applebaum, Andy and Patwardhan, Tejal and Yukseloglu, Alpin and Watkins, Olivia}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {125067--125099}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/wang26k/wang26k.pdf}, url = {https://proceedings.mlr.press/v306/wang26k.html}, abstract = {Smart contracts on public blockchains now manage large amounts of value, and vulnerabilities in these systems can lead to substantial losses. As AI agents become more capable at reading, writing, and running code, it is natural to ask how well they can already navigate this landscape, both in ways that improve security and in ways that might increase risk. We introduce EVMbench, an evaluation that measures the ability of agents to detect, patch, and exploit smart contract vulnerabilities. EVMbench draws on 117 curated vulnerabilities from 40 repositories and, in the most realistic setting, uses programmatic grading based on tests and blockchain state under a local Ethereum execution environment. We evaluate a range of frontier agents and find that they are capable of discovering and exploiting vulnerabilities end-to-end against live blockchain instances. We release code, tasks, and tooling to support continued measurement of these capabilities and future work on security.} }
Endnote
%0 Conference Paper %T EVMbench: Evaluating AI Agents on Smart Contract Security %A Justin Wang %A Andreas Bigger %A Xiaohai Xu %A Justin W Lin %A Andy Applebaum %A Tejal Patwardhan %A Alpin Yukseloglu %A Olivia Watkins %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-wang26k %I PMLR %P 125067--125099 %U https://proceedings.mlr.press/v306/wang26k.html %V 306 %X Smart contracts on public blockchains now manage large amounts of value, and vulnerabilities in these systems can lead to substantial losses. As AI agents become more capable at reading, writing, and running code, it is natural to ask how well they can already navigate this landscape, both in ways that improve security and in ways that might increase risk. We introduce EVMbench, an evaluation that measures the ability of agents to detect, patch, and exploit smart contract vulnerabilities. EVMbench draws on 117 curated vulnerabilities from 40 repositories and, in the most realistic setting, uses programmatic grading based on tests and blockchain state under a local Ethereum execution environment. We evaluate a range of frontier agents and find that they are capable of discovering and exploiting vulnerabilities end-to-end against live blockchain instances. We release code, tasks, and tooling to support continued measurement of these capabilities and future work on security.
APA
Wang, J., Bigger, A., Xu, X., Lin, J.W., Applebaum, A., Patwardhan, T., Yukseloglu, A. & Watkins, O.. (2026). EVMbench: Evaluating AI Agents on Smart Contract Security. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:125067-125099 Available from https://proceedings.mlr.press/v306/wang26k.html.

Related Material