The Ethereum Foundation has revealed an experiment that sounds almost ironic: intentionally unleashing a swarm of artificial intelligence agents to attack the Ethereum network itself - before real hackers get the chance.
In an official post by the Protocol Security team, researchers revealed they deployed coordinated AI agents to test the core systems underpinning Ethereum: cryptographic code, protocol code, and smart contracts. “The agents found real bugs,” they wrote.
A Bug That Could Crash Nodes Remotely
Among the most serious findings was a bug capable of remotely triggering crashes in libp2p’s gossipsub - a peer-to-peer networking component used by Ethereum consensus clients to communicate with each other. The flaw has since been patched and registered as CVE-2026-34219.
This practice is known as red teaming: attacking your own systems to uncover weaknesses before malicious actors find them. According to the Ethereum Foundation, their AI agents were divided into specialized roles - reconnaissance, vulnerability hunting, patching missed flaws, and validation - with some identifying attack vectors while others attempted to reproduce failures to ensure the flaws were genuinely exploitable in production code.
The Real Challenge: Distinguishing Real Bugs from Those That Merely Look Real
Interestingly, the hardest part was not finding bugs. “The surprise was how little effort it took to find them, and how much effort to distinguish real bugs from ones that merely looked real,” the team wrote. Every reported bug claim had to be accompanied by reproducible proof - not just a report that “sounded convincing.”
This trend is not the first of its kind. Last April, an early version of Anthropic’s Claude Mythos uncovered 271 security vulnerabilities in Mozilla’s Firefox browser. Last May, security researcher Taylor Hornby used Claude Opus 4.8 during an audit that exposed a critical flaw in Zcash’s Orchard privacy pool - a roughly four-year-old bug that could potentially allow the counterfeiting of ZEC without a clear on-chain trace.
What makes the Ethereum Foundation’s move notable is not just the novel technology, but a fundamental shift in roles: AI is not replacing human security researchers, but shifting their workload. The broader the surface AI can scan, the greater the human responsibility becomes to verify which findings are genuinely real - because that final decision is what is truly at stake.
Reported via Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




