Vitalik Buterin Says AI Won’t Doom Security as Crypto Faces New Threats

By Hassan Shittu

Key highlights:

  • Vitalik Buterin argued AI-assisted formal verification could shift cybersecurity in favor of defenders rather than attackers
  • Buterin also dismissed predictions that AI could break Bitcoin’s cryptography or proof-of-work, calling the risk “very low”

Ethereum co-founder Vitalik Buterin has pushed back against concerns that artificial intelligence could give cyber attackers a lasting advantage, arguing that the technology could also help developers build more secure software.

Vitalik pushed back against concerns that artificial intelligence will give hackers a lasting advantage, arguing that cybersecurity could become more defense-favoring as developers adopt AI-assisted formal verification.

His comments come as blockchain developers increasingly use AI to review code, detect security flaws and test critical infrastructure. 

The growing use of AI has also raised concerns that attackers could use the same capabilities to find vulnerabilities faster.

Can AI make crypto software secure before hackers find the flaws?

“I disagree,” Buterin wrote in an X post, adding that he believes cybersecurity will naturally favor defenders once developers “get their shit together.” 

He also noted that about 90% of his net worth remains in cryptocurrency, suggesting he continues to have significant exposure to the security of blockchain systems.

Buterin argues that the answer is not simply having defenders race attackers to identify vulnerabilities. 

Instead, he sees AI-assisted formal verification as a way to make software more secure before vulnerabilities emerge.

Formal verification uses mathematical specifications and computer-checkable proofs to establish whether software behaves according to defined requirements. 

Unlike conventional testing, which examines how a system performs under selected conditions, formal verification attempts to prove that specific properties hold more broadly.

Buterin has argued that developers could eventually use AI to formally verify much larger portions of software, rather than focusing only on components considered security-critical.

The approach could be particularly relevant to blockchain networks, where vulnerabilities in smart contracts, cryptographic systems and core infrastructure can result in irreversible losses.

Buterin sees AI as a defense against crypto’s next security threat

In a blog post published in May, Buterin previously highlighted formal verification efforts involving Ethereum, including verified EVM implementations, STARKs, consensus systems and smart contract programming languages. 

He has also proposed using AI to generate optimized code while relying on formal proofs to confirm that it maintains the properties of a verified reference implementation.

However, formal verification does not eliminate security risks. A proof can only establish what the underlying specification requires. If developers fail to account for an important vulnerability, the software can pass verification while remaining exposed.

Security gaps can also emerge when only part of a system is verified, when assumptions in the proof are incorrect, or at the boundaries between software and hardware.

Buterin’s argument therefore centers not on eliminating cyber threats, but on using AI and mathematical verification to shift more of the security burden toward prevention.

Earlier this month, Vitalik pushed back against AI-risk commentator Liron Shapira’s prediction that Bitcoin could lose at least 50% of its value within two years as AI weakens its security.

Buterin said he was optimistic about long-term cybersecurity and viewed the risk of AI breaking Bitcoin’s cryptography or proof-of-work as very low. Shapira later lowered his confidence in the forecast to 40% following comments from Buterin and AI researcher Eliezer Yudkowsky.

Crypto’s AI security race is heating up as new vulnerabilities emerge

Those concerns have become more relevant as AI-assisted security research expands across the crypto industry.

In May, security researcher Taylor Hornby reportedly used Anthropic’s Claude Opus 4.8 to uncover a four-year-old vulnerability in Zcash’s Orchard privacy pool. 

The flaw could have enabled the undetectable creation of unlimited ZEC, although developers found no evidence it had been exploited before patching it in June.

Also, Ethereum researchers reported in July that AI agents had also identified vulnerabilities in critical network infrastructure, highlighting the growing role of automated tools in blockchain security.

Around the same time, attackers exploited an old firmware vulnerability affecting Coldcard wallets, with losses estimated at about $130 million in Bitcoin. 

Coinkite, the company behind Coldcard, said AI may have helped attackers identify the flaw.

By August, concerns had spread across Bitcoin’s wider software ecosystem. 

Boltz bridge shut down its Bitcoin swap service over fears that attackers were finding vulnerabilities faster than developers could fix them, while Core Lightning disclosed several vulnerabilities identified through AI-generated reports.

The Bitcoin Red Team later used AI-assisted auditing to identify 4,962 potential vulnerabilities across 390 projects, showing the scale of weaknesses automated tools can uncover.

The developments have also fueled debate over whether AI could eventually threaten Bitcoin itself.

Source:: Vitalik Buterin Says AI Won’t Doom Security as Crypto Faces New Threats