Vitalik Buterin, the founder of Ethereum, has dismissed the notion that AI will spell the end of crypto security. In a Wednesday post on X, he argues that more sophisticated models can make formal verification practical across whole software systems. He insists the balance still tips in favor of the defenders.
“It’s an increasingly common take that AI hacking means cybersecurity is doomed,” Buterin wrote. “I disagree. I think cybersecurity is naturally defense-favoring once people get their shit together.”
Buterin’s Formal Verification Argument
The main argument Buterin makes is that AI can establish the security of complicated software through a mathematical theorem. He cites AI solving famously difficult equations as evidence that the technology can manage abstract reasoning.
“If AI can prove Navier-Stokes and FLT, then AI can prove the statement ‘this program is secure’ as a mathematical theorem,” he wrote. “Even if the program is very complicated.”
Security is not simple, he said, but the real difficulty lies in defining what “secure” means to begin with. After a definition is settled on, the proof falls into place.
The Recent Run of AI-Fueled Breakthroughs
Across crypto, developers are already using AI to guard against attacks by scanning code, testing exploits and checking for bugs before anyone else can take advantage of them. Both Ethereum infrastructure and Bitcoin software have been found to contain vulnerabilities.
In May, security researcher Taylor Hornby used Anthropic’s Claude Opus 4.8 to find a four-year-old flaw in Zcash’s Orchard privacy pool that could have enabled unlimited, undetectable counterfeiting of ZEC. Developers found no evidence it had been exploited before they patched it in June.
Ethereum Foundation researchers reported in July that AI agents had found security weaknesses in key network infrastructure. In the same month, thieves emptied Coldcard wallets via an old firmware flaw that weakened seed generation, taking about $130 million in Bitcoin. The wallet’s maker, Coinkite, suggested AI may have aided in finding the bug.
By mid-August, the danger had spread through the Bitcoin software ecosystem. Boltz put its swap service on hold, citing suspected attackers who were uncovering flaws faster than its developers could correct them. Core Lightning confirmed that several vulnerabilities spotted in AI-generated reports were indeed real. A volunteer group known as the Bitcoin Red Team employed AI-assisted audits to identify 4,962 possible weaknesses across 390 projects.
What Comes Next for Ethereum
Ethereum intends to follow a path over the next several years that involves verifying entire programs with AI, according to Buterin. That contrasts with earlier reliance on AI to check only selected components.
“There is no future for blockchains—especially blockchains with scalability and privacy—without doing this,” he said. “We need to make software actually secure. And we have already made a lot of progress.”
The wager behind Buterin’s position is that artificial intelligence will eventually take over the formal verification of whole crypto software systems, transforming security from a guessing game into something that can be proved. It depends on the builders of software managing to specify their “shit together” well enough that machines can verify them.
There is a lot at risk here. Should AI hacking outpace its defenses, the flaws uncovered by researchers such as Hornby and the Red Team might come to light before they are patched. Buterin contends that the means already exist to stop that from happening, and that those who hold crypto assets are wagering on their successful deployment.
A public contest has begun, and those tasked with protection are now stating their arguments openly.
Key Facts Box
- Taylor Hornby’s May discovery of a four-year-old Zcash Orchard flaw
- Patch applied in June
- Coldcard wallet drain: roughly $130 million in Bitcoin
- Red Team flagged 4,962 potential vulnerabilities across 390 projects
Comparison Table
| Approach | Scope | Current Status |
|---|---|---|
| AI-assisted audits | Spot checks, vulnerability reports | Deployed widely, finding real flaws |
| Formal verification | Prove entire system is secure | Practical, per Buterin, but not yet widespread |
Source material: “Ethereum Founder Vitalik Buterin Says AI Won’t Doom Crypto Security,” Decrypt.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

