AI uncovers high-severity bug in Ethereum's Nethermind software

A crypto security firm used artificial intelligence to detect a high-severity bug in Nethermind, an Ethereum client used by nearly 40% of validators. The flaw, which could have disrupted network operations, was fixed before exploitation. This development highlights AI's growing role in cybersecurity amid recent concerns over AI-generated code vulnerabilities.

Octane Security, described as an AI-native firm, announced on Wednesday that its AI tool identified a critical vulnerability in Nethermind, software that powers the Ethereum blockchain. Nethermind is utilized by approximately 40% of Ethereum validators, and the bug posed risks to network liveness and availability if exploited.

The vulnerability involved a potential sabotage through a malformed transaction, which could lead to sustained missed slots for Nethermind-based proposers. Affected validators might have faced missed block rewards, inactivity leak penalties, and overall degradation in network performance. However, the bug was never exploited and was promptly patched by Nethermind.

Giovanni Vignone, founder and CEO of Octane Security, stated, "This is one of the highest-stakes demonstrations yet of AI-led vulnerability research." He added that AI has accelerated vulnerability research, enabling bug hypotheses, exploit verification, and reports to occur 10 times faster, reshaping threat models for onchain code.

This finding follows closely after Anthropic's launch of an AI tool last week that scans codebases for vulnerabilities and suggests patches, which impacted cybersecurity stocks. Earlier concerns about AI in crypto included a Moonwell incident where AI-generated code led to a $2.7 million loss, despite passing an audit.

Octane's track record includes a partnership with pseudonymous researcher Guhu during preparations for the Ethereum upgrade Fusaka last year. They submitted 17 issues in an audit contest, with 16 fixed, nine deemed severe, and six unique, earning fourth place and $70,633 in rewards. The Ethereum Foundation also awarded Octane a $50,000 bug bounty for the Nethermind issue.

Vignone emphasized, "If you are not using AI to find and fix flaws continuously, you are competing against the blackhats who are." Seth Hallem, CEO of Certora, noted post-Moonwell that increased investment in design, threat modeling, and monitoring is essential as AI coding proliferates.

관련 기사

Tense meeting between US Defense Secretary and Anthropic CEO over AI safety policy relaxation and military access.
AI에 의해 생성된 이미지

Pentagon pressures Anthropic to weaken AI safety commitments

AI에 의해 보고됨 AI에 의해 생성된 이미지

US Defense Secretary Pete Hegseth has threatened Anthropic with severe penalties unless the company grants the military unrestricted access to its Claude AI model. The ultimatum came during a meeting with CEO Dario Amodei in Washington on Tuesday, coinciding with Anthropic's announcement to relax its Responsible Scaling Policy. The changes shift from strict safety tripwires to more flexible risk assessments amid competitive pressures.

OpenAI has launched EVMbench, a new framework developed with Paradigm, to evaluate whether artificial intelligence can effectively secure smart contracts on blockchains like Ethereum. The tool assesses AI's ability to identify, exploit, and fix vulnerabilities in these self-executing codes. This initiative aims to set standards for AI in blockchain security amid growing stakes in decentralized finance.

AI에 의해 보고됨

Hackers are increasingly leveraging artificial intelligence to identify and exploit security vulnerabilities at an accelerated pace. According to a report from IBM, the integration of AI into cyber attacks is speeding up the process significantly. This development highlights evolving threats in cybersecurity.

OpenClaw, an open-source AI project formerly known as Moltbot and Clawdbot, has surged to over 100,000 GitHub stars in less than a week. This execution engine enables AI agents to perform actions like sending emails and managing calendars on users' behalf within chat interfaces. Its rise highlights potential to simplify crypto usability while raising security concerns.

AI에 의해 보고됨

The Motley Fool has identified Ethereum as the leading artificial intelligence cryptocurrency to consider buying now. The publication suggests that Ethereum's potential to harness AI could lead to a significant increase in its value.

AI 플랫폼이 광고 기반 수익화로 전환함에 따라 연구원들은 이 기술이 사용자 행동, 신념, 선택을 보이지 않는 방식으로 형성할 수 있다고 경고한다. 이는 OpenAI의 입장 변화로, CEO Sam Altman이 한때 광고와 AI의 조합을 '불안하게 만든다'고 했으나 이제 AI 앱의 광고가 신뢰를 유지할 수 있다고 확신한다.

AI에 의해 보고됨

2025년 필리핀의 사이버 위협은 피싱과 랜섬웨어 같은 전통적 방법에 머물렀으며 새로운 형태는 등장하지 않았다. 그러나 인공지능이 이러한 공격의 양과 규모를 증폭시켜 '사이버 범죄의 산업화'를 초래했다. 여러 사이버 보안 업체의 보고서는 사건의 속도, 규모, 빈도의 증가를 강조한다.

 

 

 

이 웹사이트는 쿠키를 사용합니다

사이트를 개선하기 위해 분석을 위한 쿠키를 사용합니다. 자세한 내용은 개인정보 보호 정책을 읽으세요.
거부