AI is entering the encryption security process faster. Researchers indicated that, as the price and coverage of the relevant tools declined, the security clearance threshold before the smart contract went online could be redefined and the demands on the development team and institutions increased.

Significant decrease in audit costs

CoinDesk reported that the recently launched AI security system Mythos was moving from one-time manual inspections to more low-cost, more frequent automated reviews. According to ENS Labs Chief Information Security Officer Alexander Urbelis, such tools are pushing prices for basic audits to near zero.

He stated that it had taken weeks and a higher budget to complete the work in the past and that it might be done in a few minutes in the future. This means that small projects that would otherwise not have the capacity to undertake professional audits will also be able to obtain initial security assessments more quickly.

Moving from identifying loopholes to continuing review

According to researchers, traditional automation tools rely mainly on a large number of input-testing process anomalies, while AI tools begin to have greater reasoning capabilities. It not only detects code errors, but may also determine what the code was intended to achieve and compare it with actual performance results.

According to David Schwed, Chief Operator, SVRN, the block chain security company, the larger change is not necessarily just to identify more loopholes, but to begin to be feasible with ongoing audits. A low-cost, continuous monitoring and rehabilitation proposal may become a new security process compared to a one-time pre-line review.

If this pattern is widespread, the industry's judgement of “sufficient security checks” may also change. Urbelis argued that in the past, the team often cited the high cost of audits and the complexity of the process as reasons for not completing certain inspections; however, such reasons would become more difficult to justify when the tools were readily available and at low cost.

AI is still difficult to substitute for manual judgment

However, both researchers believe that AI is not yet a substitute for manual auditing. Machines are better at identifying code defects, but the understanding of economic models, incentive design and adversarial behaviour remains limited, and such problems relate precisely to significant losses.

Schwed states that simply handing over smart contracts to model tests does not amount to a complete security system. If users are unable to judge the reliability of the results of the model's return, it is possible to obtain only a sense of security, not a real security capability.

They also mentioned that many of the high losses in the encryption industry did not stem from smart contract loopholes, but from attacks by social workers, the disclosure of documents, the breaking of keys or the manipulation of signature processes. In such cases, for example, the code scanning tool cannot by itself prevent authorized signatories from approving transactions that they do not really verify.

Overall, AI will not eliminate the security of the encryption industry, but it is changing another more realistic variable: the cost of identifying code deficiencies is declining, and the industry's expectation of what safety checks should be completed before the project goes online may rise.