- Vitalik Buterin rejects claims that AI-driven hacking will make cybersecurity a losing battle.
- He argues AI capable of proving complex theorems can also prove code secure.
- Projects like Arklib are already applying formal verification methods today.
Vitalik Buterin isn’t buying the doom around AI-powered cyber threats, pushing back against claims that hacking could become unstoppable. The Ethereum co-founder on X argued that AI-driven hacking won’t turn cybersecurity into a losing battle.
Security actually favors defenders once they take it seriously. Buterin underscored his conviction by noting that roughly 90% of his net worth remains in crypto, effectively putting his money behind his view.
Here’s his logic. If AI gets good enough to prove genuinely hard math, things like the Navier-Stokes equations or Fermat’s Last Theorem, that same power should stretch to proving a piece of software is secure. Not guessing. Proving it, the same way you’d prove a theorem.
Buterin’s written about this before, and his pitch is simple. Checking whether your definition of “secure” actually holds up is a far smaller job than reading every single line of a massive codebase by hand.
Check the Whole System, Not Just the “Important” Part
One habit Buterin calls out as a recipe for disaster is developers verifying only the chunk of code they’ve personally decided is “critical,” leaving the rest alone. That’s exactly where bugs tend to hide. His fix is blunt. Stop cutting corners. Verify the database. The network layer. The caching. Every dependency in the supply chain. He says AI is what finally makes that realistic instead of a fantasy.
This Isn’t Just Theory
People are already building toward this on Ethereum’s core infrastructure.
- Arklib is working toward a fully verified implementation of STARKs
- evm-asm is building an entire EVM implementation directly in assembly, with proofs backing its correctness
- Vyper and Verity, two smart contract languages, both have active formal verification work underway
Even Buterin Admits This Isn’t Bulletproof
He’s not pretending this always works. He pointed to a real 2026 case where a post-quantum cryptography library got hacked despite being “verified,” usually because the verification didn’t cover everything, or the spec itself missed a property that actually mattered. He argued that formal verification is just one of several tools used to improve security, alongside methods like testing and type systems. All of these approaches aim to check whether code behaves as intended, though none can guarantee complete protection on their own.
Why This Matters for His Own Money
Bottom line, Buterin’s crypto holdings reflect a bet that AI-powered verification tips the cybersecurity balance toward defenders over time, even as AI simultaneously arms attackers.
He says this is exactly where he expects Ethereum’s development to head over the next few years, and calls it essential as blockchains add more scalability and privacy features that could otherwise widen the door for attackers.
Related: Vitalik Buterin Turns to Local Mixing in Final iO Research Post
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.