The world of blockchain security and auditing is rapidly changing, as vulnerabilities and methods for exploiting them are now identified and leveraged much faster due to the application of Artificial Intelligence (AI) in vulnerability discovery processes.
General concerns about the risks associated with AI's growing role in these processes intensified after the Hugging Face incident, where an AI platform was hacked in "the first end-to-end hack executed by an autonomous AI agent system."
This incident, blame for which was later placed on an OpenAI model that escaped from a test "sandbox," confirmed that agent-driven cyberwarfare is a reality and that organizations must be prepared to confront these risks today, not tomorrow.
Concern also spread within the Web3 ecosystem, where security tends to be more passive than active and is ensured through audits and security measures designed during development stages, which often cannot be updated in real-time before deploying new contracts.
In an exclusive interview with Bitcoin.com News, Kaijern Lau, Senior Director of Engineering at CertiK, discussed the role of AI both in these attacks and in the code auditing process for preventing them.
Lau emphasizes that AI can be a beneficial tool for discovering vulnerabilities and analyzing potential attack vectors on a platform. However, human involvement remains necessary "to ensure that the AI thoroughly analyzed the code and to verify that all found vulnerabilities are real and not false positives."
Lau stated that recent research into hardware wallet vulnerabilities demonstrates AI's limitations and the continued relevance of human involvement. "AI can help identify patterns and accelerate analysis, but experienced researchers are still needed to verify the findings and assess their real-world impact," he noted.
The Hugging Face Incident Is a One-Off, Not Proof of "Bad Actors"
Lau stressed that the Hugging Face incident occurred in a specialized test environment and that a single occurrence of this nature does not mean AI models are uncontrollable.
Nevertheless, he noted that this attack demonstrated the current capabilities of AI agents, which are increasingly able to perform complex operations in the cybersecurity sphere, including identifying and combining vulnerabilities that individually seem manageable—such as an unprotected service, misconfiguration, excessive access permissions, or compromised credentials—and turning them into a coordinated attack path at machine speed.
Consequently, it also demonstrates how investments in AI for security purposes are becoming the norm for companies releasing code-based products, such as the Web3 and blockchain industry.
"AI will increase the efficiency of both attackers and defenders. That is why blockchain companies must invest more in AI-oriented security to protect their code and infrastructure. We are entering an era where the key question is no longer whether to use AI, but how many AI resources (or tokens) organizations invest in protecting their systems compared to the resources attackers invest in carrying out increasingly sophisticated attacks," the expert stated.
AI and Blockchain Security: The Current State of Affairs
While Lau is confident that AI and blockchain security will inevitably become interconnected, he acknowledges that it is still too early for vulnerability discovery tasks and secure software development to be performed without human involvement.
CertiK even considers defensive agents and its own tools as part of the attack surface, as they can be probed for live prompt injection, malicious tool input, excessive permissions, data leakage, or insecure auto-patching. In fact, the company has developed a tool—the AI Skill Scanner—to identify risks in AI skills before deployment, allowing for stronger control over AI agents.
Lau reported that CertiK will continue to invest significantly in creating advanced AI-powered security solutions. "Our own developers and security researchers are working around the clock to refine blockchain security with AI," he confirmed.
CertiK has also developed AI Auditor—a tool that performs automated analysis of blockchain projects, identifying typical security risks. "This multi-modal and multi-agent approach enhances both the accuracy and reliability of security assessments," said Lau, describing how the company is developing its defensive capabilities against AI-wielding attackers.
The AI Balance: What Lies Ahead
Although AI lowers the barriers to attacks—as malicious actors are already using agents to discover vulnerabilities and scan smart contracts for weaknesses—Lau assures that using AI for defensive purposes offers real advantages.
"AI significantly enhances the efficiency and scale of our threat detection. CertiK has improved the efficiency of formal verification by integrating AI into its own CertiK Prover engine," Lau clarified.
CertiK's contribution to this field, according to Lau, goes beyond simply discovering vulnerabilities and aims to stay ahead of these new AI-related threats by training and using its own AI models to protect clients.
"Overall, AI will become a net positive force for Web3 security, but it is undoubtedly a double-edged sword requiring a constant search for balance," concluded Lau.








