Newsroom

Vitalik Buterin Says AI Will Not Doom Cybersecurity, Backs Formal Verification

17 September, 2026   /   News   /  AI   /   Tags:  buterin, defenders, security, properties, verification

Vitalik Buterin Says AI Will Not Doom Cybersecurity, Backs Formal Verification

Ethereum co-founder argues advanced AI can help prove software security mathematically, giving defenders an edge over attackers once proper methods are adopted

Ethereum co-founder Vitalik Buterin has rejected the growing view that increasingly capable artificial intelligence will render cybersecurity unwinnable for defenders. In a detailed post on X, Buterin stated that cybersecurity is naturally defense-favoring once developers fully apply formal verification techniques.

Buterin acknowledged that powerful AI systems could help malicious actors identify vulnerabilities more quickly and craft more effective attacks. At the same time, he maintained that the same technology can equip defenders with stronger tools for building and verifying security-critical software.

It's an increasingly common take that AI hacking means cybersecurity is doomed. I disagree. I think cybersecurity is naturally defense-favoring once people get their shit together. And anyone who continues to hold cryptocurrency (including me, ~90% of my net worth) is implicitly…
Vitalik Buterin

Buterin linked his position directly to his personal holdings, noting that roughly 90 percent of his net worth remains in cryptocurrency. He argued that continued ownership of substantial crypto assets amounts to an implicit bet that sufficiently secure digital systems can be constructed even as attackers grow more sophisticated.

Formal Verification as the Core Defense

Central to Buterin’s case is formal verification, a method that uses mathematical specifications and proofs to determine whether software satisfies defined properties. He compared the process to proving complex mathematical theorems, stating that if AI can prove results such as the Navier-Stokes equations or Fermat’s Last Theorem, it can also prove the statement that a given program is secure.

Developers would define the required security properties and then use automated tools to establish that the implementation obeys them. AI, in Buterin’s view, could sharply reduce the time, expertise, and resources needed to complete difficult mathematical security proofs for complex systems.

He has previously described AI-assisted formal verification as a potentially transformative approach for security-critical software, including areas such as consensus mechanisms, zero-knowledge systems, and quantum-resistant cryptography.

The Difficulty of Defining Security

Buterin identified a key obstacle: developers must clearly and completely define every security property the software is expected to maintain. He illustrated the challenge with the encrypted messaging application Signal.

An attacker might forge messages, block deliveries, replay old communications, compromise supporting servers, manipulate public-key discovery, or exploit vulnerabilities in a user’s operating system. Further risks could arise from corrupted databases, malicious libraries, compromised compilers, or hardware-level information leaks. Even when message contents remain encrypted, attackers might still determine who is communicating and observe patterns.

As a result, protecting content alone does not constitute a complete security standard. Definitions must also address identity verification, metadata protection, message delivery, device integrity, and the broader supporting infrastructure. Buterin noted that thorough security definitions can exceed one thousand lines and require careful analysis to formulate correctly.

Mathematical proofs only confirm the properties that have been included. Any risks left outside the verified model remain unaddressed. AI could assist by reviewing specifications, identifying missing assumptions, and helping strengthen those definitions before deployment.

Both Sides Will Use AI

Buterin’s argument does not treat the situation as a simple race in which defenders must find bugs faster than attackers. Instead, he describes a model in which carefully constructed specifications, combined with automated proof tools, can establish stronger guarantees for the properties that are defined.

More capable AI will make vulnerability discovery easier for attackers. The same advances in machine reasoning can also lower the cost of formally proving that software behaves according to security specifications. Both sides will have access to AI.

Ethereum’s Protocol Security team has already begun using coordinated AI agents to inspect protocol code and independently reproduce vulnerabilities. In one case, the agents identified a remotely reachable crash in the Rust libp2p Gossipsub networking implementation, later tracked as CVE-2026-34219 and fixed in version 0.49.4.

The team reported that generating candidate findings was not the hardest part of the workflow. Many reports involved unreachable paths, debug-only failures, or proofs that technically succeeded while establishing weaker properties than intended. Independent reproduction and human review remained necessary before accepting results.

Formal verification has also been incorporated into Ethereum’s longer-term protocol research priorities. It is treated as cross-cutting tooling across work on privacy, state management, zkEVM development, post-quantum security, and related areas. Projects combining large language models with formal methods are already under way, including efforts to check client implementations against specifications and to formalize cryptographic soundness problems.

Buterin’s comments continue an existing research direction rather than announcing a new protocol upgrade or mandatory verification requirement for all Ethereum software.

Parallel Evidence of Offensive AI Use

Separate research indicates that AI is also expanding the capabilities of attackers. Anthropic has reported observing malicious actors using AI to automate vulnerability research, exploit development, and multi-target campaigns. Some operators maintained continuous automated workflows for vulnerability discovery.

By late August, Anthropic said it had disclosed 2,300 AI-discovered vulnerabilities across 392 open-source projects, with hundreds already patched upstream. The company has also described using frontier models with security firms and software vendors to locate high- and critical-severity flaws before they can be exploited.

Buterin’s position remains that once developers define security properties carefully and apply formal verification at scale, the balance can favor defenders. The ultimate effect of AI on cybersecurity, in his assessment, depends on how effectively those definitions and proofs are constructed and applied across technology systems.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.