TLDR
- Vitalik Buterin rejects claims that stronger AI will make cybersecurity impossible to defend.
- He says AI could make formal verification cheaper and easier for software developers.
- Formal verification uses mathematical proofs to check whether software follows defined security rules.
- Buterin warns that defining what “secure” means remains a major challenge for complex software.
- He expects both attackers and defenders to gain access to more capable AI tools.
Vitalik Buterin has rejected the view that stronger artificial intelligence will make cybersecurity impossible to defend. The Ethereum co-founder argues that AI could also help developers build software with stronger mathematical security guarantees. He said both attackers and defenders will gain access to better AI tools, making software design and verification increasingly important.
Vitalik Buterin Sees AI Helping Cyber Defenders
Buterin said cybersecurity can favor defenders when developers use formal verification more widely. Formal verification uses mathematics to prove that software follows defined rules. He argued that advanced AI could make these proofs cheaper and easier to create, even as AI helps attackers search for weaknesses.
He compared that possibility with AI systems solving mathematical problems, including Fermat’s Last Theorem and the Navier-Stokes equations. His point was that AI may treat software security claims as mathematical statements that require proof.
He also linked the issue to his personal exposure to cryptocurrency. Buterin said about 90% of his net worth remains in crypto. He argued that holding large crypto positions assumes developers can create digital systems that remain secure against increasingly capable attackers.
Formal Verification Still Faces a Definition Problem
Buterin said the hardest task may involve defining what secure software must actually do. He used Signal as an example. Attackers could target message delivery, key discovery, servers, operating systems, libraries, compilers, databases, or hardware while encryption still protects message contents.
That creates a difficult challenge for formal verification. A proof only confirms the rules that developers define. If those rules miss a threat, the proof cannot cover it. Buterin said security definitions can therefore become extremely long and require careful work before AI can prove them mathematically.
Ethereum Security Work Moves Toward Stronger Proofs
Recent Ethereum development also shows continued work on proof-based security. Buterin backed the EIP-8288 proposal, which would use recursive STARK aggregation to combine cryptographic proofs and reduce costs for quantum-safe transactions. The proposal remains in draft form and targets a future Ethereum upgrade.
Ethereum developers are also debating how future transaction systems should balance scale, privacy, and censorship resistance. Recent work on account abstraction standards shows Ethereum Layer 1 and Base pursuing different designs after talks ended. The debate reflects the broader challenge Buterin described: developers must define security goals clearly before tools can verify them.



