AI Agents Uncover Remote Crash Bug in Ethereum Validator Software
An experiment by the Ethereum Foundation used AI agents to test the security of validator software. The result was surprising, as the agents not only uncovered a genuine remote crash bug in GossipSub but also generated numerous false alarms that required human researchers to verify.
The bug, which has since been patched, allowed a remote peer to send a specially crafted message that would cause the validator software to crash. Although this was considered a denial-of-service risk rather than a catastrophic chain failure, it still had consequences for network operators and staking providers.
The experiment demonstrated the value of using AI in cybersecurity, as the agents were able to identify a valid weakness that may have escaped conventional review. However, it also highlighted the challenge of separating genuine bugs from false positives, which required human researchers to investigate each report thoroughly.