EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Ethereum Foundation reveals why AI still cannot detect real vulnerabilities

2026-07-10 06:02:12
Bookmark

摘要

以太坊基金会表示,验证AI漏洞报告比生成它们更困难。

AI代理发现了一个真实的libp2p漏洞,后来被披露为CVE-2026-34219。

基金会表示,人工验证和可复现的证明对于协议安全仍然至关重要。

根据以太坊基金会协议安全团队的说法,最近与协调AI代理进行的实验在以太坊所依赖的系统上发现了真实的软件缺陷,但该组织表示,现在大部分精力都用于区分有效发现和令人信服的误报。

该团队在一篇技术文章中描述了这些结果,解释了如何测试AI代理对系统软件、加密库和高保证智能合约的应用。

协议安全团队一直在将AI代理指向以太坊的协议代码。核心收获不在于发现漏洞,而在于分类。以下是这份工作的现场笔记。

一个已确认的发现涉及libp2p的gossipsub组件中的一个可远程触发的panic,libp2p是以太坊共识客户端使用的点对点网络层的一部分。以太坊基金会表示,该漏洞已被修复,后来被披露为CVE-2026-34219。

The foundation said AI agents should not be viewed as decision-makers, but as tools for generating assumptions that require independent verification. While agents can inspect source code, trace execution paths, and prepare proof-of-concept material, the foundation says they also generate reports based on weak formal verifications that are inaccessible code, duplicate known issues, only debug mode crashes, or fail to prove actual security issues.

The team said that the unexpected discovery was not that the AI was able to identify vulnerabilities, but that the time consuming to verify these reports far exceeded the time it took to generate them.

Multi-agent workflow filters unreliable reports

To reduce unreliable discoveries, the Ethereum Foundation said it deploys multiple AI agents to target the same software warehouse, with each agent handling different stages of the review process. Agents do not rely on a central coordinator, but exchange information through the repository itself, sharing state in version control.

According to the foundation, the workflow starts with reconnaissance, narrowing the broad attack surface to specific testable ideas. The hunting agent then tracks each hypothesis in the code and attempts to build a working renderer. The gap filling agent tracks accepted and rejected reports to avoid duplicating previous work, while the verification agent independently inspects each candidate report, removes duplicates, and determines whether a report is a legitimate vulnerability.

The foundation said each accepted report must identify an achievable goal, clearly define security immutability, explain failure mechanisms, provide observable evidence, contain a self-contained reproducer, and carry a deduplication key. These requirements are designed to ensure that each statement can be tested directly against production code.

Manual verification remains the decisive factor

At the heart of the process, the Ethereum Foundation says there is a principle that overrides everything: unless someone other than the reporting agent can reproduce the vulnerability on the real codebase, the vulnerability does not exist. According to the foundation, this requirement eliminates reports based on impossible attack paths, only debugging pattern failures, or formal verification results (security attributes that appear mathematically correct but have not proven meaningful).

In addition to technical verification, the foundation said that surviving candidate reports will also be evaluated for actual availability. Defects that can be triggered by any network participant have different security implications than defects that require privileged access or non-real computing resources.

The foundation added that AI agents remain inconsistent in determining the reachability of vulnerabilities, attack severity, or vulnerabilities that arise only through long sequences of effective interactions. In these cases, AI agents perform better as an aid to stateful testing frameworks than as a substitute for experienced security researchers.

The latest security update comes only weeks after the Ethereum Foundation completed a major internal reorganization. In a June 23 announcement, the organization said it had laid off about 20% of its staff, and after months of review, 54 employees had left in accordance with its mandate and money management policies. According to the foundation, the reorganization aims to focus staff and resources on responsibilities that only the organization can perform, while continuing the long-term development of Ethereum.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP