Vitalik Buterin said combining AI-generated code with formal verification could improve security across Ethereum’s software stack, with the biggest gains likely in Ethereum infrastructure, zero-knowledge proofs, next-generation consensus systems, and quantum-resistant cryptography. Formal verification uses mathematically checkable proofs to test whether software behaves as intended. The method has existed for decades, but recent advances in AI have made generating both code and those proofs more practical and efficient.
Smart contract failures keep security risks in focus
Buterin pointed to a familiar problem in crypto: smart contract vulnerabilities have repeatedly led to severe failures and losses worth millions of dollars. Attacks on DeFi protocols have shown how weaknesses in software can put large amounts of user funds at risk. He warned that “bugs in computer code are scary,” especially when software controls blockchain-based assets or supports complex cryptographic processes. In that setting, a coding error is not minor. It can become a system-level risk.
Not everyone sees AI as a net security gain. Some researchers argue that AI may weaken overall safety by producing increasingly complex code that is difficult, or impossible, to audit in full. Buterin pushed back on that view. He said AI can help developers get ahead of attackers by spotting and fixing vulnerabilities before they are exploited. Used properly, the combination of AI and mathematical verification could deliver a major advance in cybersecurity.
Mathematical proof does not remove every failure mode
He also drew a clear limit around formal verification. A mathematically proven system can still fail if developers verify the wrong assumptions or overlook hardware-level issues. In real-world systems, exhaustive verification of every component may not be feasible. That matters for large and layered crypto infrastructure, where security depends on more than one piece of code.
Buterin added that AI can generate huge amounts of code quickly, but often at the expense of accuracy. In his words, “formal verification regains the lost reliability… AI is going to produce a lot of messy code, but that also means there’s an optimistic future for cybersecurity.” His argument is not that AI alone solves security. It is that AI, paired with mathematically rigorous verification, can improve how critical software is built and checked. That approach could be especially relevant for DeFi applications and other high-value blockchain systems.
Buterin cautioned that AI and formal verification together should not be treated as a complete security guarantee. Even so, he said the convergence could reshape how software safety is pursued in critical digital infrastructure.

