Key Insights
- Vitalik Buterin rejected claims that better AI hacking tools make cybersecurity unwinnable.
- He argues AI-assisted formal verification could help prove whether software meets defined security properties.
- Ethereum researchers already use AI agents for protocol security while requiring machine checks and human review.
Ethereum co-founder Vitalik Buterin pushed back against claims that artificial intelligence could give attackers a permanent advantage in cybersecurity.
In a Sept. 17 discussion, Buterin argued that increasingly capable AI could also strengthen defensive software engineering. His preferred approach centers on formal verification, where mathematical proofs test whether software satisfies clearly defined security properties.
Vitalik Buterin Backs Formal Verification Against AI Attacks
Buterin said stronger AI hacking capabilities do not necessarily make cybersecurity an unwinnable contest.
His argument centers on formal verification rather than simply trying to discover vulnerabilities before attackers do. Formal verification uses mathematical methods to test whether software follows specific rules.
AI systems could help developers construct and check those proofs across increasingly complicated programs.
Buterin has previously described this as part of a more optimistic cybersecurity model. Instead of accepting that critical software will always contain unknown bugs, developers could build smaller highly trusted components and subject them to much stronger verification.
However, the method does not create absolute security.
A mathematical proof only establishes the property written into the specification. If developers fail to include an important threat, software can satisfy the proof while remaining vulnerable in practice.
Defining Security Remains the Difficult Part
Buterin used secure messaging to explain why the specification problem matters.
Preventing outsiders from reading messages represents only one security property. A complete system may also need to prevent message forgery, replay attacks and unauthorized blocking.
Developers must also consider compromised servers, devices and operating systems. A secure application can still fail if another layer exposes private keys or sensitive information.
Metadata creates additional risks. Sender identities, recipient details, timing and message sizes can reveal information even when the message itself remains encrypted.
The same problem extends to databases, software libraries, compilers and hardware.
Buterin’s argument is that formal verification becomes useful only when developers clearly define all the properties they expect the system to protect.
Ethereum Already Runs AI Agents Against Protocol Code
The Ethereum Foundation is already experimenting with AI agents in protocol security work.
Its Protocol Security team said in July that coordinated agents had found real defects in software Ethereum depends on. One publicly disclosed case involved Rust libp2p’s Gossipsub networking implementation.
The agents identified a remotely triggerable panic in the peer-to-peer software. The vulnerability was later fixed and disclosed as CVE-2026-34219.
That result demonstrated that AI agents can find useful security issues in production-relevant code.
However, the Ethereum Foundation also identified a major limitation: AI systems can produce technically convincing reports that do not correspond to exploitable production vulnerabilities.
Ethereum Researchers Still Require Human Review
The Protocol Security team said some agent findings pointed to unreachable code or behavior limited to testing environments.
Others produced formal proofs that technically succeeded but verified a weaker property than researchers actually wanted to establish.
That makes triage central to Ethereum’s current use of AI security tools.
Researchers reproduce reported vulnerabilities, run automated checks and assess whether affected code is reachable in production. Human reviewers then evaluate whether the reported problem has real security impact.
The process therefore does not treat model output as a final security judgment.
Instead, AI provides additional search and analysis capacity while conventional verification remains responsible for deciding whether a finding is valid.
Formal Verification Expands Across Ethereum Roadmap
Ethereum’s longer-term protocol roadmap also gives formal verification a broader role.
The Ethereum Foundation’s Sept. 7 priorities document identified five multi-fork research areas: fast finality, post-quantum security, privacy, state and zkEVM development.
Formal verification is expected to function as shared tooling across several of those areas through 2029.
The push toward an Ethereum L1 zkEVM is expected to improve verification tools, workflows and verified cryptographic components.
Those tools can also support Ethereum’s post-quantum work. The Foundation has set a target of making the network resistant to quantum attacks across execution, consensus and data layers by December 2029.
Privacy research provides another use case because zero-knowledge systems rely heavily on cryptographic correctness.
AI Agents Work With Machine-Checked Proofs
The Ethereum Foundation is also testing AI-assisted mathematical research through better.codes.
The project allows researchers to direct their own AI agents at formalized cryptographic problems written in Lean.
AI agents attempt to improve mathematical proofs and submit them to the system. However, the Lean kernel independently verifies whether each submission actually proves the specified theorem.
That separation is important.
The AI system can propose the proof, but it cannot simply declare its own answer correct. A separate deterministic proof checker decides whether the result satisfies the formal statement.
The model combines machine-generated research with machine-verifiable mathematical guarantees.
Vitalik Buterin Wants Security Beyond Ethereum Code
Buterin’s vision extends beyond blockchain protocols.
In his May discussion of formal verification, he described a future where critical systems form a small highly trusted “secure core.”
Ethereum could be one such core. Parts of an operating-system kernel and critical hardware could become others.
Less trusted software could operate around those components with restricted permissions.
That architecture would reduce the damage caused when ordinary applications contain vulnerabilities. Critical systems would receive substantially stronger verification because failure there carries much greater consequences.
Buterin therefore sees AI as potentially increasing both sides of cybersecurity.
Attackers gain stronger tools for vulnerability discovery, but defenders may also gain cheaper and more scalable methods for proving the correctness of critical software.
AI Offensive Cyber Capabilities Are Already Growing
The threat side of the argument is also becoming more visible.
Anthropic said in its September threat report that malicious actors used Claude across cyber operations between December 2025 and August 2026.
The company documented cases where AI accelerated vulnerability research, exploitation testing and attack workflows. It said some actors built automated systems capable of conducting security research continuously.
Anthropic said AI was reducing the skills and resources previously needed for some sophisticated cyber operations.
Those developments support concerns that offensive capability is improving.
However, Ethereum’s experiments show that defenders are also using AI for vulnerability discovery, testing and formal research.
Ethereum Price Rebounds Toward $2,460
Ethereum price also recovered on Sept. 17 after falling below $2,400 during the previous market decline.
ETH traded around $2,445-$2,460, up roughly 2% over 24 hours at the latest market snapshots.
Analyst Ali Martinez identified a broader four-hour trading range with resistance near $2,570.
His setup places the middle of the range around $2,500, followed by the upper boundary near $2,570.
A confirmed four-hour close above roughly $2,570 could strengthen the recovery setup and bring $2,700 into focus. Martinez also identified $3,000 as a higher conditional target if momentum continues.
Those levels remain technical projections rather than expected outcomes.
Ethereum would first need to confirm a breakout above the existing range before the higher targets become relevant.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments involve risk, and technical targets or security research developments do not guarantee future price performance.





