The $3 exploit
A verified exploit costs a median of $2.83, end to end. 90% cost under $5, and the priciest in the whole dataset was $14.63. The economic filter between “a vulnerability exists” and “a working exploit exists” is gone.
Evidence-based research on how artificial intelligence is changing the economics of exploitation, across open-source ecosystems, known-exploited catalogs, and the long tail of vulnerabilities no human has weaponized.
AI-native cyber offense just got incredibly cheap.
The only thing that changes with AI is the speed of response.
Nearly three-quarters of CVEs analyzed could be exploited by Quantro’s Exploit Harness. The numbers will only climb from here.
A complete end-to-end exploit fits inside the context window, with room for two more to spare in a 1M-token model.
It’s not all bad. What AI breaks, AI can also fix, just as fast.
One story, in three parts: what collapsed, why every warning system missed it, and the one signal that keeps pace.
What AI-native cyber offense now costs to weaponize a known CVE.
Part I →Why every signal we use to prioritize defense misses it.
Part II →A measure that isn’t blind, and a defense that keeps pace.
Part III →For decades, the implicit defense of most vulnerabilities was cost. Writing a reliable exploit took a skilled human days or weeks. We measured what it costs an autonomous agent instead. The unanswerable became a dataset.
A verified exploit costs a median of $2.83, end to end. 90% cost under $5, and the priciest in the whole dataset was $14.63. The economic filter between “a vulnerability exists” and “a working exploit exists” is gone.
Median time from a known CVE to a verified exploit is 11 minutes, with 90% landing inside half an hour. The gap between disclosure and weaponization has effectively closed.
The harness drove 72% of the dataset, 2,183 CVEs out of 3,029, to a verified working exploit. Treat that as a floor rather than a ceiling.
Of 998 human-reviewed exploits, 77% needed no correction at all and verified exactly as generated. That number falls with every version of the harness.
If offense has collapsed, the signals we use to prioritize defense should have caught it. One by one, the catalog, the probability, the severity, the “no public PoC” comfort, they turn out blind to AI-driven exploitation.
89% of AI-exploitable CVEs, 1,933 of them, aren’t in CISA KEV. Past exploitation predicts nothing about what an agent can weaponize next.
73% of AI-exploitable CVEs carry an EPSS below 0.25, squarely in the deprioritize band. The vulnerabilities the harness couldn’t exploit score statistically the same, so EPSS can’t tell them apart.
Nearly a quarter of exploited CVEs, 500 in all, score below “High” on CVSS. Rated low, exploited anyway.
For 450 CVEs no public PoC existed. The harness wrote one from scratch for a median of $3.00 and 11 minutes, barely more than it spent adapting an existing one.
So don’t rank by them. See what an AI attacker sees on your domain, or score a CVE you care about — both free, in minutes.
Every instrument on the dashboard is blind. So we built one that isn’t, and found that the same machine speed that broke offense open can be turned to defense.
The AI Exploitability Index (AI-XI) scores each vulnerability 1–5 by how hard the agent had to work. Cost and time rise cleanly with it, and even the hardest solved tier costs under $4.
The harness generates a remediation in a median of 14 minutes, about as fast as it builds the exploit. To fight AI-native cyber offense, you need AI-native cyber defense.
Two free tools from the VRL research team. Scan your domain for AI-exploitable exposure, or score any CVE by whether AI can exploit it.
Is this CVE exploitable by AI, and how hard? Paste a CVE and an autonomous agent builds and verifies a working exploit, then returns an index from 1 (easy) to 5 (hard) with time and cost to exploit — median 11 minutes, $2.83. Never the exploit code.
See what's exploitable on your domain — free. Point the agent at a domain, org, or repository and it enumerates exposed services, packages, and versions, then flags where our dataset of verified exploits already has a working PoC for what you're running.