Vitalik Buterin Says Perfect Crypto Security Remains Impossible

TheNewsCrypto2026-02-23 tarihinde yayınlandı2026-02-23 tarihinde güncellendi

Özet

Vitalik Buterin, the founder of Ethereum, argues that perfect security in the cryptocurrency sector is unattainable due to the complexity of human intent. He explains that blockchain networks cannot perfectly interpret user intentions and hard-code them into inflexible code. Buterin defines security as an alignment problem, where the goal is to ensure the protocol's actions match user expectations. Even basic transactions involve assumptions about identity, network, and interface accuracy that cannot be fully programmed. Instead of pursuing perfect security, Buterin advocates for layered security mechanisms. These include redundancy through multiple independent checks, transaction simulations, spending limits, and address verification. He also suggests that AI could complement, but not replace, cryptographic security by modeling human judgment patterns. However, no technological system can fully emulate human reasoning. Buterin concludes that crypto security is a continuous alignment process rather than a final endpoint, requiring ongoing improvements as technology evolves.

Vitalik Buterin has clarified the reasons why the cryptocurrency sector will never be able to provide perfect security, citing the complexity of human intent. In a recent X post, the Ethereum founder went on to say that blockchain networks will never be able to perfectly interpret the complex intentions of users and hard-code them into an inflexible line of code.

Buterin defined security not as a standalone technological aspect, but rather as a larger problem of bringing system security in line with user expectations. He went on to say that usability and security have the same goal in mind: ensuring that what the user wants is what the protocol does.

Security as an Alignment Problem

Buterin explained that even basic blockchain transactions involve some assumptions. When people send digital assets, they assume certain things about the recipient’s identity, the correct network, and the interface’s accuracy. Programmers cannot program all these assumptions into code.

Buterin highlighted that these gaps make it impossible to achieve absolute security. Even with highly advanced code, systems cannot accurately determine the users’ actual intentions. Therefore, the community should move away from the promise of achieving perfect security and instead aim for alignment between intentions and results.

Buterin further added that security models can decouple user experience and security. He said that both aspects need to be combined to avoid unintended consequences. If systems are not able to represent user intent correctly, then vulnerabilities arise.

Layered Security Mechanisms and Redundancy

Instead of aiming for perfection, Buterin encouraged the use of layered security mechanisms. Redundancy was one of the principles he encouraged, where multiple independent checks are done to ensure the user’s intentions are verified before any transaction is carried out. Transaction simulations enable users to see the results of their actions before they are carried out. Spending limits and address verification can also be used to minimize risks when carrying out high-value transactions.

Buterin also spoke about the possible use of large language models in the interpretation of user instructions. He explained that artificial intelligence should be used to complement, not replace, basic cryptographic security. General-purpose AI can model general human judgment patterns, and fine-tuned models can model individual human behavior patterns. Buterin, however, was of the opinion that no technological system can fully emulate human reasoning.

Market analysts have noted that recent high-profile exploits underscore the importance of improving protective frameworks. Investors are increasingly drawn to platforms that implement transparent redundancy and structured safeguards. Buterin summed up the state of crypto security as an alignment process rather than an endpoint. There is always a need for improvement in protective systems as blockchain technology advances.

Highlighted Crypto News:

U.S. Bitcoin ETF Holdings Contract With $1.6B Monthly Outflows

Tagscrypto securityCryptocurrencyETHEREUMEthereum (ETH)securityVitalikvitalik ButerinVitalikButerin

İlgili Sorular

QAccording to Vitalik Buterin, why is perfect security impossible in the cryptocurrency sector?

ABecause blockchain networks cannot perfectly interpret the complex intentions of users and hard-code them into an inflexible line of code. Security is an alignment problem between system security and user expectations.

QHow did Buterin define security in the context of blockchain technology?

AHe defined it not as a standalone technological aspect, but as a larger problem of aligning system security with user expectations, ensuring that what the user wants is what the protocol does.

QWhat are some of the layered security mechanisms Buterin encouraged instead of aiming for perfection?

AHe encouraged the use of redundancy with multiple independent checks, transaction simulations, spending limits, and address verification to minimize risks, especially for high-value transactions.

QWhat role did Buterin suggest artificial intelligence could play in crypto security?

AHe suggested that AI, specifically large language models, could be used to complement basic cryptographic security by modeling general human judgment patterns and individual behavior patterns, but it cannot fully replace human reasoning.

QWhat is the current state of crypto security, as summarized by Buterin?

AHe summarized it as an alignment process rather than an endpoint, emphasizing that there is always a need for improvement in protective systems as blockchain technology advances.

İlgili Okumalar

GPT-5.6 Countdown: Abandon the Illusion of a Single API, Computational Iteration Can't Outpace a Single Page of Compliance

In mid-June, three seemingly independent industry events—the compliance-driven throttling of Fable 5, the open-sourcing of GLM-5.2, and the leaked release timeline for GPT-5.6—are pushing the global AI industry toward a watershed moment. These shifts signal a fundamental restructuring of the industry's underlying logic. First, **"usability" has substantially overtaken "advanced capabilities"** as the primary weight, pushing the global large language model (LLM) supply chain into a "dual-track" phase of controlled closed-source and local open-source coexistence. Second, **the competitive moats of closed-source giants are shifting**. Their technical focus is moving from "language intelligence" toward "spatial intelligence (world models)"—a domain heavily reliant on computing power. Third, faced with常态化 transnational compliance risks, **a "model-agnostic" decoupled design has become a survival necessity for application-layer developers to maintain business continuity.** The article details how Anthropic's Fable 5, despite its advanced engineering feats, was restricted for non-U.S. citizens within 72 hours of launch, highlighting how geopolitical compliance can instantly limit even the most advanced models. In response, the open-source camp, exemplified by Zhipu AI's MIT-licensed GLM-5.2, is gaining market share by offering stable performance improvements and significant cost advantages (up to 70% savings for enterprises), while achieving full adaptation with domestic semiconductor platforms. Meanwhile, closed-source leaders like OpenAI are pivoting. The anticipated GPT-5.6 reportedly shifts focus from language to spatial intelligence and world models, aiming to rebuild a generational gap in areas like 3D understanding, simulation, and industrial design that demand immense compute. The core conclusion is that the LLM supply chain's logic has changed. Enterprises must now evaluate infrastructure based on a composite of technical performance and policy compliance. For developers, complete reliance on a single closed-source API poses unacceptable risk. Implementing a truly model-agnostic architecture—enabling swift switches to compliant, locally deployable open-source alternatives—is no longer just good practice but a fundamental baseline for business continuity.

marsbit1 saat önce

GPT-5.6 Countdown: Abandon the Illusion of a Single API, Computational Iteration Can't Outpace a Single Page of Compliance

marsbit1 saat önce

Is the 'Token Subsidy War' Among AI Giants Almost Over?

The article discusses the ongoing "token subsidy war" among AI giants like OpenAI and Anthropic, questioning whether it's nearing its end. It reveals that current AI subscription prices are heavily subsidized, with some plans offering tokens at up to 70 times the actual cost to attract and retain heavy users, especially developers and enterprises. This strategy mirrors past internet-era subsidy battles, but with a key difference: AI tokens lack "lock-in" effects. Unlike ride-hailing or food delivery apps, users can easily switch between AI providers as APIs become standardized, making it difficult for companies to raise prices post-subsidy. The piece highlights a structural asymmetry in the competition. Giants like Google, with massive advertising revenue, can afford to subsidize tokens indefinitely, akin to using "tokens as a weapon." In contrast, venture-backed companies like OpenAI and Anthropic face pressure to become profitable, especially as they approach IPO. The article cites Google Ventures founder Bill Maris, who suggests Google could slash token prices by 80%, putting immense pressure on competitors. Two potential endgames are presented: the "internet service" model (subsidize, monopolize, then raise prices) and the "utility" model (tokens become a standardized, low-margin commodity like electricity). Given the low switching costs, the latter seems more likely. The competition may not have a single winner but could instead accelerate AI's evolution into a foundational, infrastructure-level technology, akin to a public utility. For now, users continue to benefit from heavily subsidized token costs.

marsbit1 saat önce

Is the 'Token Subsidy War' Among AI Giants Almost Over?

marsbit1 saat önce

Beyond the Stadium: The Profitable Games Surrounding the World Cup

"Beyond the Pitch: The Profit Game Around the World Cup" The FIFA World Cup transcends being a sporting spectacle, evolving into a massive global arena for speculation and profit-seeking. The 2026 tournament has amplified this dynamic, creating a multi-layered ecosystem of financial opportunism alongside the football. **Prediction markets** have surged into the mainstream. Platforms like Polymarket and Kalshi saw trading volumes for World Cup contracts soar, attracting new users with their financial trading model and high-profile, chain-based wealth stories that overshadow traditional sports betting in terms of growth and narrative. However, **traditional sportsbooks** remain the dominant force, leveraging established user habits, legal markets, and comprehensive product offerings to handle the vast majority of speculative wagers, with projections suggesting record-breaking betting volumes. Capital markets also react. **"Concept stocks"** in countries like South Korea and Japan experience volatile price swings based on team performance and anticipated fan spending on items like chicken, beer, and viewing parties, effectively becoming a stock market reflecting fan sentiment. The **ticket resale market** has become a sophisticated arena for arbitrage. Prices fluctuate wildly based on team draws and star power, with sellers sometimes listing tickets they don't yet own in a practice akin to short-selling, while FIFA's own "Right to Buy" tokens add another layer of speculative trading. **Collectibles and merchandise** offer another avenue. Panini sticker albums, with their inherent scarcity and nostalgic value, can become high-value collectibles. Limited-edition or locally themed jerseys command significant premiums on secondary markets, and even counterfeit vendors profit from fans' desire for affordable match-day identity. The **cryptocurrency** space has seen a frenzy of speculative, unauthorized World Cup-themed meme coins on chains like Solana. These tokens, often exploiting team names and player imagery, experience extreme pump-and-dump cycles, creating stories of massive gains for a few early entrants and steep losses for many others. Finally, an entire industry thrives on **providing information and tools** to other speculators. Developers create platforms like SeatSidekick to track ticket inventory and prices, while paid Telegram groups and subscriptions sell betting tips and predictions, monetizing the widespread desire for an informational edge. In essence, the World Cup has become a compressed, global laboratory for speculation. While the games determine champions on the field, a parallel, complex network of financial transactions—spanning prediction contracts, bets, stocks, tickets, collectibles, crypto, and information services—settles its own scores in the global market.

marsbit2 saat önce

Beyond the Stadium: The Profitable Games Surrounding the World Cup

marsbit2 saat önce

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

This article explains the three primary methods for Codex to interact with a computer, each with distinct use cases, permission boundaries, and trust levels. **1. Computer Use:** This offers the broadest access, allowing Codex to visually control and interact with the graphical user interface of authorized macOS/Windows apps, system settings, and even iOS simulators. It's ideal for tasks lacking APIs or structured tools, such as operating legacy software or multi-app workflows. However, it's the slowest method and has the widest permission scope, requiring careful supervision for sensitive actions. **2. Chrome Extension:** This grants Codex access to the user's logged-in Chrome browser state, including cookies, profiles, and open tabs. It's best for tasks requiring user identity across websites like Gmail, LinkedIn, Salesforce, or internal dashboards. Its key advantage is multi-tab control for complex workflows. While more powerful for browser-based tasks than Computer Use, it carries higher sensitivity as actions are performed under the user's identity. **3. In-App Browser:** This is a browser isolated within the Codex thread, separate from the user's personal browsing data. It excels in web development and debugging scenarios—previewing local servers, testing responsive layouts, or annotating designs directly on the page. Its isolation is a strength for development but a limitation for tasks requiring login sessions. The core principle is to choose the narrowest, safest, and most structured interface for the task. Use plugins or MCPs first, resort to visual control (Computer Use) only for GUI-dependent tasks, employ the Chrome extension for identity-reliant browser work, and prefer the In-App Browser for isolated development. **Appshots** are clarified as a fourth, complementary tool for *inputting* context—capturing a screenshot of a window to point Codex to something—rather than a method for Codex to *act*. Together, this layered approach highlights a key to AI agent productization: not granting unlimited permissions, but constraining them within clear boundaries for specific tasks while preserving user oversight.

marsbit3 saat önce

How Does Codex Use a Computer? Three Entry Points and Permission Boundaries

marsbit3 saat önce

İşlemler

Spot
Futures
活动图片