Bitcoin

CertiK Director Lau Advances AI as Net Positive Despite Risks

8Views


Key Takeaways

CertiK’s Kaijern Lau: AI Will Be Positive For Web3 Security, But Also A ‘Double-Edged Sword’

The world of blockchain security and auditing is rapidly changing as exploits and vulnerabilities are now being harnessed and discovered much faster due to the involvement of artificial intelligence (AI) in vulnerability discovery processes.

Generalized concerns about the risks of the rising role of AI in these activities have risen with the Hugging Face incident, where an AI platform suffered a hack, which was the first intrusion “driven, end to end, by an autonomous AI agent system.”

The occurrence, later blamed on an OpenAI model escaping its testing sandbox, confirmed that agent-driven cybersecurity warfare is a reality and that institutions need to be prepared to face these risks now, not tomorrow.

Concerns have also reached the Web3 ecosystem, where security is more passive than active, managed by audits and security considerations designed during the production phases and that oftentimes cannot be upgraded in real time before deploying new contracts.

In an exclusive interview with Bitcoin.com News, Kaijern Lau, Senior Director of Engineering at CertiK, examined the role of AI in both these attacks and the process of auditing code to prevent them.

Lau stresses that AI can be a useful tool for identifying a vulnerability and examining potential attack vectors on a platform. Nonetheless, the involvement of a human-in-the-middle is still necessary “to ensure that the AI has analyzed the code thoroughly and to verify that any reported vulnerabilities are genuine rather than false positives.”

Lau declared that recent research covering hardware-wallet attack surfaces illustrates the limitations of AI and the relevance of human involvement. “AI can help surface patterns and accelerate analysis, but experienced researchers are still needed to validate the findings and assess their actual impact,” he assessed.

Hugging Face Incident Isolated, Not Proof Of “Rogue Agents”

Lau stressed that the Hugging Face incident arose during a specific evaluation setting and that an instance of such a contingency does not mean that AI models are uncontrollable.

Even so, he pointed out that the attack highlighted the current capabilities of AI agents, which are increasingly able to execute complex cybersecurity operations, including identifying and combining weaknesses that appear manageable in isolation, such as an exposed service, a misconfiguration, excessive permissions, or compromised credentials, and turning them into a coordinated attack path at machine speed.

Consequently, this also shows how investing in AI for security purposes is becoming the norm for companies with code-based products, such as the Web3 and blockchain industry.

“AI will make both attackers and defenders more capable. That is why blockchain companies should invest more in AI-driven security to protect their code and infrastructure. We are entering an era where the key question is no longer whether to use AI, but how many AI resources (or tokens) organizations invest in defending their systems compared with the resources attackers invest in launching increasingly sophisticated attacks,” the expert declared.

AI and Blockchain Security: Where We Stand

While Lau is sure that AI and blockchain security will inevitably become intertwined, he acknowledges that it is still too early for vulnerability discovery and secure software development tasks to be completed without human intervention.

CertiK even considers defensive agents and its tools as part of the surface attack, as they can be probed for prompt injection, malicious tool inputs, excessive permissions, data leakage, or unsafe automated remediation. In fact, the company has designed a tool, the AI Skill Scanner, to help identify risks in AI skills before deployment, increasing the controls exerted over AI agents.

Lau revealed that CertiK will continue to invest heavily to build advanced AI-powered security. “Our in-house developers and security researchers are working around the clock to advance AI-driven blockchain security,” he confirmed.

CertiK has also developed AI Auditor, a tool that conducts an automatic analysis of blockchain projects, identifying common security risks. “This multi-model, multi-agent approach improves both the accuracy and reliability of security assessments,” said Lau, describing how the company was developing its defensive capabilities against AI-assisted actors.

AI’s Balancing Act: Where We Go From Here

While AI lowers the barriers to attack, as threat actors are already leveraging agents to discover exploits and scan smart contracts for vulnerabilities, Lau ensures there are real advantages to using AI for defensive purposes.

“AI dramatically elevates our threat detection efficiency and scope. CertiK has improved the efficiency of formal verification by integrating AI into its proprietary CertiK Prover engine,” Lau specified.

CertiK’s contribution to the space, Lau said, goes beyond detecting vulnerabilities and aims to ensure that defensive security measures stay ahead of these emerging AI threats by also training and employing its AI models to secure its customers.

“Overall, AI will be a net positive force for Web3 security, but it is undeniably a double-edged sword that requires a continuous balancing act,” Lau concluded.



Source link

Leave a Reply