The EF team has launched a fleet of coordinated AI agents against Ethereum code – artificial intelligence analyzes system software, cryptographic code, and contracts.
They have already found real bugs, one of which is in gossipsub – an important part of the libp2p network protocol through which nodes exchange messages. The vulnerability allowed a remote crash of a node – an attacker could send a special message and "take down" a node. This issue was assigned the identifier CVE-2026-34219 and has been fixed.
AI agents are very good at generating hypotheses and attack scenarios. However, most of what they find are false positives, duplicates, or things that cannot be reproduced in real-world conditions. Therefore, the main work now is verifying and filtering the results.
📰 @Cryptoz
