Vitalik Buterin Says AI Could Make Ethereum Security Harder to Break
• September 17, 2026 3:09 pm • CommentsArtificial intelligence is giving attackers better tools, but Vitalik Buterin does not believe that makes the security fight unwinnable. His argument is more ambitious: the same technology can help defenders prove that software behaves the way it is supposed to behave.
In a current report on Buterin’s remarks, Decrypt detailed the Ethereum co-founder’s case for using AI-assisted formal verification across far more than a smart contract. Buterin argued that systems capable of proving difficult mathematical propositions could also help prove that software satisfies explicit security properties.
His target is the whole stack: protocols, servers, networks, databases, caches, compilers, key management, and the layers connecting them. A flaw in any one component can undermine guarantees made elsewhere, which is why checking a single contract or isolated codebase leaves important risk untouched.
Buterin tied that argument directly to Ethereum’s direction over the next several years. Scaling and privacy add complexity, so the network needs stronger methods for showing that each layer behaves as intended instead of relying only on teams to find vulnerabilities before attackers do.
It's an increasingly common take that AI hacking means cybersecurity is doomed.
I disagree. I think cybersecurity is naturally defense-favoring once people get their shit together. And anyone who continues to hold cryptocurrency (including me, ~90% of my net worth) is implicitly…
— vitalik.eth (@VitalikButerin) September 16, 2026
Traditional security work often finds flaws by testing known failure modes, reviewing code, or trying to break a system before an attacker does. Formal verification takes a different route.
Developers define the properties a program must satisfy and use mathematical proofs to test whether the implementation actually satisfies them.
That approach is powerful, but it has historically been expensive and difficult to apply at scale. A proof is only as useful as the assumptions and specifications behind it, and complex systems contain countless moving pieces.
Buterin’s thesis is that increasingly capable AI systems can reduce that burden by helping humans write specifications, generate proofs, and examine a much larger software surface.
AI can introduce bad code as quickly as it can inspect good code. Defenders gain an advantage only if they use automation to test explicit security properties across the whole system.
An attacker needs one exploitable gap; a defense team needs a practical way to reason across an entire stack. AI-assisted proof systems could make that broader review more realistic than it has been.
⚡️ TODAY: Vitalik Buterin pushed back on claims that AI hacking will doom cybersecurity, arguing AI-powered formal verification can make software fundamentally secure.
He added that holding crypto, about 90% of his net worth, is a bet on that. pic.twitter.com/Vn4V62yewp
— Cointelegraph (@Cointelegraph) September 17, 2026
Ethereum’s roadmap keeps asking the network to do more: scale transaction capacity, strengthen privacy, reduce trust assumptions, and remain resilient as cryptography and computing power evolve. Every added layer creates new interactions that must be understood and secured.
That makes Buterin’s argument especially relevant to holders and developers. The future of a programmable blockchain depends on much more than whether its base protocol is sound.
Clients, wallets, bridges, rollups, applications, and the infrastructure connecting them all widen the security surface.
There is an important limit to keep in view. Mathematical verification cannot rescue a bad specification.
If developers prove that software follows incomplete or mistaken rules, the proof can be technically valid while the system remains vulnerable. Humans still have to define the right threat model and make sure real-world operations match it.
The crypto industry has spent years treating audits, bug bounties, monitoring, and incident response as separate defensive layers. AI-assisted formal methods could tie more of that work together earlier, before vulnerable code reaches users and begins holding real money.
For Ethereum, this is an active engineering bet. Better tooling could let an increasingly complex network become more verifiable rather than less.
Attackers will use AI. Buterin’s answer is that defenders should use it to raise the cost of finding anything left to attack.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
