The Zero-Day That Cost $3,476
The same models that can patch a vulnerability can find and sell it first, and the study’s own economics show which side the tools favor.
This is Reading the Frontier, a series of close readings of what the frontier labs publish.
In October 2025, an AI agent was pointed at 2,849 blockchain smart contracts that had been deployed recently enough to have no known vulnerabilities. It was not told where to look. It read the code, reasoned about where value could leak, and found two flaws nobody had reported. Then it wrote working exploits for them. The whole run, discovery through weaponization, cost about $3,476 in API calls.
That was a simulation, on forked chains, with no real money touched. It was Anthropic’s Frontier Red Team measuring what was possible, and their word for what they had shown was proof-of-concept: profitable autonomous exploitation is technically feasible today.
Seven months later the concept stopped being a proof. In May 2026, Google’s Threat Intelligence Group reported the first case it had confirmed of a real criminal group using an AI model to discover and weaponize a genuine zero-day, a two-factor-authentication bypass in an open-source administration tool, staged for a mass exploitation campaign. What Anthropic had shown was feasible in a sandbox in October, someone did in the world by May.
There is a detail in the Google case that looks, at first, like reassurance. The attack was stopped. Google’s own AI agent, a vulnerability hunter called Big Sleep, was brought in, isolated the exact flaw the attackers were aiming at, and the vendor patched it before the campaign launched. AI found the hole; AI closed it. The symmetry that the whole field leans on, that every capability handed to attackers is handed equally to defenders, appears to hold in the one case where it was tested against a live threat.
Then, in the second week of July 2026, the reassurance ran out. Security researchers documented what they believe was the first fully autonomous ransomware attack run by an AI agent, tracked as JADEPUFFER. It exploited a vulnerability in an open-source AI workflow tool to get in, and from there the agent executed the entire intrusion on its own: stealing credentials, moving laterally, exfiltrating data, encrypting a production database. No Big Sleep intervened. Nobody caught this one in the staging phase. The whole chain ran end to end at machine speed, and it worked.
That reassurance is thinner than it looks. Read closely, the study that opened with a $3,476 zero-day is an argument against the very balance its authors hope to preserve.



