EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

The Ethereum Foundation deploys AI to search for vulnerabilities in the ETH network before hackers d

2026-07-10 06:31:04
Bookmark

The Ethereum Foundation is using a swarm of AI agents to attack Ethereum first-before anyone else does.

Researchers from the Ethereum Foundation\'s protocol security team said in a blog post on Thursday that they have deployed a series of AI agents to target the software systems on which Ethereum relies, looking for vulnerabilities in encryption systems, protocol code and smart contracts.

\"We have been coordinating AI agents to attack various systems on which the network relies, such as system software, cryptographic code and the right contracts that must be ensured,\" the researchers wrote.\"These agents have indeed discovered real vulnerabilities.\"

One of the discovered vulnerabilities involves the remotely-triggered panic in libp2p\'s gossipsub, which is part of the point-to-point layer used by Ethereum consensus clients. The issue has been fixed and publicly disclosed on GitHub as CVE-2026-34219.

This practice is known as red team testing, in which companies deploy security researchers to attack their own systems in an attempt to expose vulnerabilities by penetrating or disrupting the network before malicious hackers discover the vulnerabilities. The red team is responsible for attacking the system, and the blue team is responsible for defense.

Traditionally, human researchers have searched for vulnerabilities by manually reviewing code, while AI agents can scan the entire code base, test potential attack methods, and generate findings for review.

\"It\'s not surprising that agents can find vulnerabilities,\" the team wrote.\"What\'s surprising is that it took so little effort to find vulnerabilities, and what really consumes a lot of energy is how to distinguish real vulnerabilities from issues that look like vulnerabilities.\"

According to the Ethereum Foundation, these agents are organized into specialized functional roles, including reconnaissance, hunting, filling and verification. Some agents search for possible attack paths, while others try to reproduce faults and verify that they can be reproduced in production code.

\"There is a reason for this architectural design,\" they wrote.\"It enforces a concrete, testable claim and clearly defines the criteria for \'completion\'. An agent who has to write observable evidence can no longer prevaricate with \'this looks risky.\'\"

AI\'s growing role in vulnerability research was fully demonstrated in April when Anthropic\'s preview of Claude Mythos found 271 vulnerabilities in Mozilla\'s Firefox browser.

Researchers compare AI agents to fuzzy testing tools-tools used to test software defects. But unlike fuzz testing tools, AI agents can generate vulnerability reports, assess impact, and create proof-of-concept tests.

However, detail does not mean correct. Findings generated by AI can appear convincing, even if they are wrong, forcing researchers to filter out duplications, false positives, and vulnerabilities that are actually unexploitable.

\"There is one rule that is more important than any other: A candidate project is a real discovery only if there is a self-contained reproducible product that reproduces the fault in real code and can be run by non-writers.\" The researchers wrote,\"The reproducible program does not read the description and does not care how confident the model sounds. It either works or it doesn\'t.\"

AI tools have helped security researchers discover vulnerabilities in blockchain networks. In May, security researcher Taylor Hornby discovered a serious vulnerability in Zcash\'s Orchard privacy pool while conducting an AI-assisted audit using Anthropic\'s Claude Opus 4.8. The flaw, which has existed for about four years, could allow attackers to create counterfeit ZECs without leaving visible traces on the chain. Network upgrades are still under way to restore confidence in Zcash supply.

The Ethereum Foundation\'s experiment introduced this technology internally, using AI agents to test its own code to discover vulnerabilities.

\"AI does not replace security researchers, it redistributes work.\" The Ethereum Foundation said,\"Agents allow us to cover much more than manual operations. In exchange, they require us to make more prudent judgments when faced with a large number of confidence-sounding conclusions.\"

\"It\'s a deal worth making,\" they added,\"as long as you can remember, judgment is the real output.\"

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP