Ethereum Foundation: AI finds bugs, but humans confirm

Ethereum Foundation uses AI to find bugs, but most reports are false positives. Human validation is crucial, as AI serves mainly as a search tool, not a decision-maker.

The Ethereum Foundation has deployed coordinated AI agents to audit critical components of the Ethereum network, including systems software, cryptographic code, and smart contracts. These AI agents have uncovered real vulnerabilities, such as a remotely-triggerable panic in the libp2p gossipsub component, which was fixed and disclosed as CVE-2026-34219. However, the Foundation notes that the main challenge lies not in finding potential bugs, but in verifying which findings are genuine. Most AI-generated bug reports are false positives, duplicates, or irrelevant, requiring significant human effort to triage and validate. The Foundation emphasizes that AI agents should be seen as powerful search tools that generate hypotheses, not as decision-makers. Human validation and reproducible proof remain essential for protocol security. While AI accelerates discovery, efficiently distinguishing real vulnerabilities from incorrect reports is now the primary focus.

Related Tokens

Related News