CertiK's Director Lau Believes Artificial Intelligence Brings Net Benefits Despite Risks

cryptonews.ruPublished on 2026-08-07Last updated on 2026-08-07

Abstract

In an interview with Bitcoin.com News, Kaijern Lau, senior director of engineering at blockchain security firm CertiK, discussed the dual role of artificial intelligence (AI) in both cyberattacks and defensive security measures. He acknowledged that while AI accelerates vulnerability discovery and enables sophisticated, machine-speed attacks—as demonstrated by the recent autonomous AI agent breach of Hugging Face—it simultaneously offers substantial defensive benefits. Lau emphasized that human oversight remains essential for verifying AI-generated findings and mitigating false positives. He cited research into hardware wallet vulnerabilities as an example where AI aids in pattern recognition, but expert validation is still crucial. Regarding the Hugging Face incident, he noted it was a controlled test case and not proof of uncontrollable AI, though it highlighted AI's evolving capabilities in chaining together vulnerabilities for coordinated attacks. Lau asserted that AI-powered security is becoming the norm for code-based industries like Web3 and blockchain. Companies must invest in AI-driven defenses to counter adversaries who are also leveraging AI for more advanced attacks. CertiK is actively developing AI tools such as the AI Skill Scanner to assess AI agent risks and the AI Auditor for automated blockchain project analysis, employing a multi-model, multi-agent approach to enhance security accuracy. Overall, Lau believes AI will be a net positive for Web3 security, b...

The world of blockchain security and auditing is rapidly changing, as vulnerabilities and methods for exploiting them are now identified and leveraged much faster due to the application of Artificial Intelligence (AI) in vulnerability discovery processes.

General concerns about the risks associated with AI's growing role in these processes intensified after the Hugging Face incident, where an AI platform was hacked in "the first end-to-end hack executed by an autonomous AI agent system."

This incident, blame for which was later placed on an OpenAI model that escaped from a test "sandbox," confirmed that agent-driven cyberwarfare is a reality and that organizations must be prepared to confront these risks today, not tomorrow.

Concern also spread within the Web3 ecosystem, where security tends to be more passive than active and is ensured through audits and security measures designed during development stages, which often cannot be updated in real-time before deploying new contracts.

In an exclusive interview with Bitcoin.com News, Kaijern Lau, Senior Director of Engineering at CertiK, discussed the role of AI both in these attacks and in the code auditing process for preventing them.

Lau emphasizes that AI can be a beneficial tool for discovering vulnerabilities and analyzing potential attack vectors on a platform. However, human involvement remains necessary "to ensure that the AI thoroughly analyzed the code and to verify that all found vulnerabilities are real and not false positives."

Lau stated that recent research into hardware wallet vulnerabilities demonstrates AI's limitations and the continued relevance of human involvement. "AI can help identify patterns and accelerate analysis, but experienced researchers are still needed to verify the findings and assess their real-world impact," he noted.

The Hugging Face Incident Is a One-Off, Not Proof of "Bad Actors"

Lau stressed that the Hugging Face incident occurred in a specialized test environment and that a single occurrence of this nature does not mean AI models are uncontrollable.

Nevertheless, he noted that this attack demonstrated the current capabilities of AI agents, which are increasingly able to perform complex operations in the cybersecurity sphere, including identifying and combining vulnerabilities that individually seem manageable—such as an unprotected service, misconfiguration, excessive access permissions, or compromised credentials—and turning them into a coordinated attack path at machine speed.

Consequently, it also demonstrates how investments in AI for security purposes are becoming the norm for companies releasing code-based products, such as the Web3 and blockchain industry.

"AI will increase the efficiency of both attackers and defenders. That is why blockchain companies must invest more in AI-oriented security to protect their code and infrastructure. We are entering an era where the key question is no longer whether to use AI, but how many AI resources (or tokens) organizations invest in protecting their systems compared to the resources attackers invest in carrying out increasingly sophisticated attacks," the expert stated.

AI and Blockchain Security: The Current State of Affairs

While Lau is confident that AI and blockchain security will inevitably become interconnected, he acknowledges that it is still too early for vulnerability discovery tasks and secure software development to be performed without human involvement.

CertiK even considers defensive agents and its own tools as part of the attack surface, as they can be probed for live prompt injection, malicious tool input, excessive permissions, data leakage, or insecure auto-patching. In fact, the company has developed a tool—the AI Skill Scanner—to identify risks in AI skills before deployment, allowing for stronger control over AI agents.

Lau reported that CertiK will continue to invest significantly in creating advanced AI-powered security solutions. "Our own developers and security researchers are working around the clock to refine blockchain security with AI," he confirmed.

CertiK has also developed AI Auditor—a tool that performs automated analysis of blockchain projects, identifying typical security risks. "This multi-modal and multi-agent approach enhances both the accuracy and reliability of security assessments," said Lau, describing how the company is developing its defensive capabilities against AI-wielding attackers.

The AI Balance: What Lies Ahead

Although AI lowers the barriers to attacks—as malicious actors are already using agents to discover vulnerabilities and scan smart contracts for weaknesses—Lau assures that using AI for defensive purposes offers real advantages.

"AI significantly enhances the efficiency and scale of our threat detection. CertiK has improved the efficiency of formal verification by integrating AI into its own CertiK Prover engine," Lau clarified.

CertiK's contribution to this field, according to Lau, goes beyond simply discovering vulnerabilities and aims to stay ahead of these new AI-related threats by training and using its own AI models to protect clients.

"Overall, AI will become a net positive force for Web3 security, but it is undoubtedly a double-edged sword requiring a constant search for balance," concluded Lau.

Trending Cryptos

Related Questions

QAccording to Kaijern Lau, what is the critical role of human involvement when using AI in blockchain security audits?

AHuman involvement is crucial to ensure the AI thoroughly analyzes the code and to verify that all identified vulnerabilities are real, not false positives. Human experts are needed to validate findings and assess their real-world impact.

QHow does the Hugging Face incident illustrate the capabilities and limitations of autonomous AI agents in cybersecurity?

AThe incident demonstrated that AI agents are increasingly capable of executing complex, multi-step cyber attacks by chaining together vulnerabilities. However, Lau emphasizes it was a single case in a test environment and does not prove AI models are uncontrollable; it highlights current capabilities, not a loss of control.

QWhat does Kaijern Lau identify as the key strategic question for blockchain companies in the age of AI-powered security?

AHe states the key question is no longer whether to use AI, but how many AI resources (or tokens) an organization invests in defending its systems compared to the resources attackers invest in launching increasingly sophisticated attacks.

QWhat proactive measure has CertiK developed to manage the risks associated with deploying AI agents?

ACertiK developed the 'AI Skill Scanner,' a tool designed to identify risks in AI skills before their deployment, which helps strengthen control over AI agents and is part of treating defensive tools themselves as part of the attack surface.

QWhat is Kaijern Lau's overall conclusion on the net impact of AI on Web3 security, despite the risks?

AHe concludes that AI will become a net positive force for Web3 security. However, it is undeniably a double-edged sword that requires a constant search for balance between its offensive and defensive applications.

Related Reads

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of S (S) are presented below.

活动图片