Ethereum Taps AI Agents to Bolster Security Ahead of Major Protocol Shift
The Ethereum Foundation has been testing AI agents to identify vulnerabilities in its code ahead of major protocol changes. The agents successfully found real software bugs, including a remotely triggered consensus-client failure.
The foundation divided the workflow into reconnaissance, hunting, gap-filling and validation roles, drawing on earlier research from Anthropic and Cloudflare. AI agents performed well when linking specifications to code and proposing possible root causes.
However, human security experts remain essential for validating findings and judging their severity. The systems sometimes treated unreachable call chains as exploitable and overstated a flaw's severity.