Skip to content

How does artificial intelligence affect the security of cryptocurrencies?

More and more AI logins make it difficult to detect real security issues

For years, open source software development has been based on a simple idea. The more people review the source code, the more likely it is that security vulnerabilities will be discovered before someone tries to exploit them.

This is especially important in the crypto industry. Bitcoin, Ethereum, digital wallets, cross-chain bridges, and DeFi platforms rely on publicly available code, independent security experts, and bug bounty programs to encourage reporting of vulnerabilities found.

But during 2026, the founder of Linux, Linus Torvalds, warned of a new problem. Artificial intelligence is increasingly used to create reports of alleged security vulnerabilities, which is why project maintainers have to review a large number of reports that often do not contain real vulnerabilities.

The problem is not that AI can help find real errors in the code. The bigger challenge is that it can generate a large number of convincing reports in a very short time, which still require manual verification.

In many open source crypto projects, small teams are in charge of security that maintain the systems through which assets worth billions of euros or dollars pass. As a result, a large number of invalid reports can slow down the detection of real security issues and put additional strain on existing processes.



Source: cointelegraph

What does Linus Torvalds say about everything?

Linus Torvalds warned about this problem during a discussion about how to report security vulnerabilities in the Linux kernel. His criticisms were not directed at artificial intelligence as a technology, but at the way it is used to create applications.

According to him, project maintainers are increasingly receiving a large number of similar applications created with the help of AI tools. Many of them describe possible problems in the code, but do not show whether the vulnerability can actually be exploited, whether it is already known, previously corrected, or does not even pose a real security risk.

This puts additional pressure on security teams. Every report needs to be reviewed, as there may be a real security flaw among them. At the same time, each analysis requires time, technical verification and additional evaluation.

A report that can be compiled with the help of AI tools in just a few minutes is often analyzed by experts for hours before determining whether it is a real problem or a false alarm. It is this disproportion that is becoming an increasing challenge for the open source community.



Source: cointelegraph

How do AI logins create "noise" in security analytics?

AI tools today can compile technical reports very convincingly. They can analyze the source code, identify unusual patterns, and write an application that looks detailed and professional at first glance. However, a well-written report does not automatically mean that a security flaw actually exists.

In order to confirm a vulnerability, it is necessary to answer several important questions. Can the problem reliably recur? Does it appear in real terms of use? Does it affect important functions or sensitive parts of the system? Is the vulnerability already known or has it been fixed earlier? Is it a real possibility of exploitation or just a theoretical assumption?

A large number of AI-generated reports do not provide answers to these questions. Instead, they often point out minor irregularities, misinterpret the way certain functions work, or exaggerate the importance of problems that do not have a major impact in practice.

An additional challenge is that such reports are often very neatly written and seem convincing. As a result, more time needs to be invested in distinguishing reports that indicate an actual security breach from those that are of no greater value.

In discussions within the open source community, the term AI slop or noise is increasingly used for this phenomenon. This describes a large number of reports that consume security teams’ time and resources, while rarely contributing to the discovery of new security vulnerabilities.



Source: cointelegraph

Why is this problem especially important for crypto projects?

Security flaws in the crypto industry often have more serious consequences than in many other areas. While a social network glitch can cause downtime or data leaks, a vulnerability in a crypto bridge or DeFi protocol can lead to hundreds of millions of dollars worth of asset losses.

This is why the speed at which security vulnerabilities are detected and checked is particularly important.

A large part of the crypto ecosystem is based on open source development. Smart contracts, blockchain protocols, digital wallets, and decentralized applications are available for public review, and bug bounty programs encourage security researchers to report vulnerabilities found.

Artificial intelligence can be useful in this process. In practice, there is a possibility that a large number of AI-generated reports will put additional strain on security teams.

If bug bounty programs start receiving a large number of such reports, it may be more difficult for project maintainers to identify which vulnerabilities require an immediate response. At the same time, quality reports from security researchers may wait longer for review due to the large number of reports that do not reveal real problems.

An additional challenge is that attackers are not required to report found vulnerabilities. They can use AI to look for security vulnerabilities without any warning or public announcement. That’s why security teams need to identify and analyze reports that point to real threats as quickly as possible.



Source: cointelegraph

The problem of incentives in bug bounty programs

Bug bounty programs are based on a simple idea. Finding serious security vulnerabilities requires knowledge, time, and technical effort.

Artificial intelligence is changing this relationship.

Today, researchers can use large language models and automated tools to review code, compile reports, and produce reports with significantly less time than before. As a result, there may be a higher number of reports, especially from users with less experience who try to get rewards through the quantity rather than the quality of the issues found.

This pattern starts to resemble spam emails. When it is possible to create a large number of weak reports with very little effort, some users may try to take advantage of such an approach. Even if only a small number of applications lead to a reward, this way of working can be profitable for some.

Crypto projects may have to adjust the way bug bounty programs work because of this. Some of the possible changes include:

  • Looking for more detailed evidence to confirm the vulnerability
    • Setting stricter criteria for applications
    • restricting participation in open bounty programs
    • Greater focus on vetted security researchers
    • transition to programmes available only to invited participants

While such changes could reduce the number of low-quality applications, they could also reduce the openness that has been an important part of crypto project development for years.



Source: cointelegraph

How to Use AI Effectively in Security Research

This does not mean that AI has no value in the field of security. Experienced researchers are increasingly using AI tools for faster code review, fuzz testing, documentation analysis, and simulation of possible attacks.

The problem arises when AI-generated results are sent as ready-made security logins without additional verification.

The use of AI tools in security analyses requires human supervision and technical verification. Artificial intelligence can help find possible problems, but the final assessment requires expert analysis.

A quality security vulnerability report typically includes:

  • Step-by-step steps to reproduce the problem
    • Proof that the vulnerability can actually be exploited
    • An explanation of the potential impact on the system
    • confirmation that the problem has not been previously reported
    • A realistic assessment of the severity of the vulnerability
    • Propose a possible solution when possible.

Simply put, AI can help detect potential problems early, but human judgment still remains crucial when making the final decision.



Source: cointelegraph

The crypto industry needs to find a balance between AI tools and security

In the coming years, the issue of security could take on additional importance in the crypto industry, especially as artificial intelligence becomes more accessible to both attackers and security professionals. According to some experts, the goal will be to develop better ways to use AI tools to detect and eliminate security vulnerabilities before anyone tries to exploit them.

One possible direction is to make greater use of automated security analyses and the collaboration of a larger number of researchers who can help validate crypto projects. At the same time, projects will have to find a way to take advantage of AI technology without creating an additional burden through a large number of low-quality applications.

Discussions on this topic have become more intense after the development of new AI models that can help analyze code and simulate attacks. Although AI system manufacturers introduce various protection mechanisms, security experts continue to warn that the capabilities of these tools can be used in different ways.

Interest in security has further increased after several major attacks on DeFi protocols that have once again shown how vulnerabilities in smart contracts and cross-chain systems can have serious consequences. According to published information, one such case occurred when an attacker extracted about 116,500 rsETH tokens from the Kelp DAO bridge, the value of which at that moment was approximately $290 to $293 million.

These developments show that crypto projects will need to continue to develop security processes in a period when AI is becoming part of the daily work of developers and researchers. One of the key questions will be how quickly security teams can verify, understand, and remediate potential security vulnerabilities that AI identifies.



Napomena:  Ovaj članak služi isključivo u informativne svrhe i ne predstavlja financijski, investicijski, porezni niti pravni savjet. Kriptovalute nose rizik gubitka vrijednosti. Korisnici bi prije donošenja bilo kakvih odluka trebali samostalno procijeniti rizike povezane s kriptoimovinom.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful. For more details you can visit our legal questions