Ethereum

Vitalik Buterin Says Ethereum’s Security Now Depends on AI Tools

Buterin's updated roadmap puts quantum resistance and privacy at the centre, and says the formal verification underpinning it is only feasible with modern AI. That lands in a fortnight when AI has been implicated in a run of exploits across Bitcoin infrastructure.

⏱ 3 min read Ethereum
Quick Summary
  • Buterin set his 2023 Ethereum roadmap against the current Strawmap, adding quantum-resistant scaling, stronger privacy, native rollups and a deliberate simplification of the network's technical specifications.
  • He said Ethereum is relying more heavily on STARKs and formal verification, and that formal verification is only feasible with modern AI tools, making AI a dependency of the security model rather than an accessory.
  • Nothing in the post carries a date, and quantum safety has been at the centre of Ethereum's messaging since January without a shipped implementation.

Ethereum co-founder Vitalik Buterin says quantum resistance, privacy and AI-assisted security have become larger priorities for the network than they were when he published his last roadmap in 2023.

Writing on X on Monday, Buterin said he had updated that 2023 roadmap to set it against Ethereum’s current Strawmap, a working outline of the network’s long-term technical priorities.

‘What’s most striking, however, is that some completely new things are in the strawmap that are not in this diagram, because they were not in the 2023 roadmap at all,’ he wrote. ‘These reflect changing priorities.’

What Changed Since 2023

The additions are stronger privacy, scaling designed for a post-quantum world, and what Buterin calls the lean-ification of the spec, meaning a deliberate simplification of Ethereum’s technical specifications. The roadmap also covers native rollups and looks at a future beyond the Ethereum Virtual Machine.

The scaling approach has narrowed. Rather than trying to make every kind of Ethereum activity faster, the plan is to build specialised mechanisms with more restrictive properties that scale better, aimed at the heaviest loads the network actually carries today, such as token transfers and swaps, and expects to carry tomorrow, such as privacy protocols.

The AI Dependency

The most consequential line in the post is about how Ethereum plans to check its own work.

Buterin said the network is leaning more heavily on STARKs, a cryptographic technique for proving a computation was carried out correctly, and on formal verification, which means mathematically proving that code does what it is supposed to do rather than testing it and hoping.

Formal verification has existed for decades. What kept it out of reach was cost and speed, because proving a large codebase correct by hand is slow and expensive work. Buterin’s position is that AI has removed that constraint.

‘This can only be safe with formal verification, which is itself only feasible with modern AI tools,’ he wrote.

Read plainly, that makes AI a dependency of Ethereum’s security model rather than an accessory to it.

The Other Side of the Same Trade

That commitment arrives at an awkward moment, because AI has spent the past fortnight demonstrating the other side of the same trade.

Coinkite said it was likely someone used AI to review older Coldcard firmware and find the flaw that has cost holders well over $100 million. BTCPay Server, disclosing a vulnerability that let attackers drain Lightning nodes, said AI is changing the balance between attackers and defenders, and that Bitcoin projects are particularly exposed because they are valuable targets. A volunteer group filed 4,962 security findings across 390 Bitcoin projects in roughly 30 hours using AI agents.

Ethereum’s roadmap is a bet that the defensive side of that trade wins. Nothing in the post explains why it should.

What This Is Not

None of this is shipped. The Strawmap is an outline of priorities rather than a schedule, and Buterin’s post attaches no dates to any of it.

Quantum safety has also been at the centre of Ethereum’s messaging for most of this year. In January, Buterin urged developers to adopt quantum-resistant cryptography before the threat becomes immediate, and the Ethereum Foundation set up a dedicated post-quantum team. In February he laid out a phased plan to replace four potentially vulnerable parts of Ethereum’s cryptographic architecture. In July he put quantum safety and privacy at the centre of his proposed Lean Ethereum overhaul.

‘Ethereum will be quantum-safe. Ethereum will put users’ privacy first. Ethereum will be secure,’ he wrote at the time. ‘Ethereum will be censorship-resistant. Ethereum will be highly performant and scalable while satisfying the above. And Ethereum will be Lean.’

That is the fourth statement of the same intent in eight months. Ether was trading around $1,870 on Tuesday, down 2.2% on the day.

⚖️ Our Verdict ⚖️ Watch and Wait

Taking quantum risk seriously years before it bites is the right instinct, and formal verification at protocol scale would be a genuine step up from testing and hoping. But this is a diagram rather than a delivery, the fourth statement of the same priorities in eight months with no dates attached to any of them, and it rests on the same AI capability that has spent the past fortnight being used to break things.