Ethereum co-founder Vitalik Buterin challenged growing fears that advanced artificial intelligence will make cybersecurity impossible, instead arguing that AI could provide significant advantages to defenders as well as attackers. Buterin, an influential figure in blockchain and cryptography, maintains that new AI tools could lower the cost and complexity of formal verification, allowing developers to better secure critical digital infrastructure.
Buterin: AI can tip the scales in favor of defenders
Buterin outlined his position publicly, stating that he does not agree with the widely held belief that improvements in AI will inherently tip the balance toward cybercriminals. According to Buterin, defenders can use AI systems to rigorously check whether software complies with strict security rules, making exploits harder for attackers to find.
AI has boosted both offensive and defensive capabilities in security, but wider use of formal verification methods — especially with AI-powered tools — could make well-designed software much harder to compromise.
He explained that formal verification, a process where software correctness is demonstrated using mathematical proofs, may become easier with advances in AI. This means it could be less expensive and more scalable for developers to apply mathematically robust security techniques across complex codebases.
Buterin, whose personal fortune is heavily invested in digital assets, noted that a majority of his net worth remains in cryptocurrencies. His continued stake in these technologies, he said, reflects his fundamental belief that secure cryptocurrency systems are possible, especially if defenders embrace improved tools.
Mini dictionary: Formal verification, a technique in computer science, involves using mathematical logic to prove that a given program strictly adheres to its specification, reducing the risk of software bugs and vulnerabilities.
Defining ‘secure’ remains a hurdle
Buterin identified a persistent problem that even the best AI cannot fully solve: the challenge of precisely defining what “secure” means in the context of complex software. He pointed out that programs like Signal — an encrypted messaging application — must consider not only encryption algorithms but also threats to servers, operating systems, libraries, compilers, and even hardware.
A formal proof can only guarantee the rules it is designed to check; if developers overlook certain threats, those vulnerabilities remain outside the scope of formal verification.
He emphasized that as software tends to grow in complexity, the definitions of security also expand, sometimes requiring extensive documentation and precise language. Unless developers clearly identify and formalize their security goals, even the most advanced AI-driven proofs cannot account for overlooked threats.
Ethereum developments target enhanced proof standards
Continued work within the Ethereum ecosystem highlights ongoing progress in proof-based security. Buterin has recently shown support for the proposed EIP-8288 upgrade, which focuses on using recursive STARK aggregation. This approach is designed to batch cryptographic proofs, reducing the operational costs of quantum-resistant transactions in future Ethereum versions.
Mini dictionary: STARKs (Scalable Transparent ARguments of Knowledge) are cryptographic proofs that provide scalable and transparent ways to verify the validity of computations without revealing any underlying data, often used in blockchain for privacy and scalability.
Meanwhile, Ethereum developers continue to debate how upcoming transaction systems, including account abstraction standards, should balance priorities such as scalability, privacy, and censorship resistance. Teams working on different Ethereum layers are considering divergent approaches, highlighting the challenges of aligning technical innovation with robust, clearly defined security standards.
Buterin’s recent statements suggest that while attackers and defenders will likely both benefit from stronger AI, the underlying challenge will always be a careful definition of what constitutes system security — and building proofs that rigorously protect those definitions.




