The latest technical disclosure by the ETA Foundation shows that AI has been able to identify some of the real problems in the software and contract systems on which it relies, but that the more resource-intensive link at present is not to continue to generate a loophole, but to determine which reports actually pose security risks.

The company disclosed that the protocol security team had recently tested the cover system software, the password library and the high-security smart contract. The conclusion is that AI is suitable for raising suspicious points on a large scale, but that a large number of results end up in unattainable code paths, repeat known problems, collapses in debugging environments only, or formalizations that do not prove real risks.

Confirmed a libp2p loophole

The team disclosed that an identified problem appeared in the gosipsub component of libp2p. This component is part of the point-to-point network layer and is used by the Taifung Consensus client. The Foundation stated that the problem could be triggered remotely and that the relevant loophole had been repaired, followed by CVE-2026-34219.

This is also one of the examples used by the Foundation to illustrate the AI capacity boundaries. It does not deny that AI can find a real loophole, but emphasizes that the real difficulty is to sift out effective discoveries from a large number of “looks reasonable” false reports.

Multi-agent process first.

In order to reduce the rate of misreporting, the Foundation uses a multi-agent process that allows multiple AI agents to work at the same time for the same code warehouse and to control the shared status through the version rather than relying on a single central coordinator.

Among them, the reconnaissance agent shrinks the face of the attack and forms testable assumptions; the gap-duging agent follows the hypothetical tracking code and tries to construct a recovery; the report that the record of the vacancy agent has been accepted and rejected to avoid duplication of effort; and the certification agent independently examines the candidate issue to weigh and determine whether it is a real loophole.

  • Indicate the physical contactable target code
  • Clear corresponding security non-variant
  • Explain the failure mechanism and provide evidence

In addition, the report will need to be accompanied by independently run recovery materials, as well as deweighted marking keys to ensure that researchers can test conclusions directly on the production code.

Artificial recurrence remains the final standard.

The Foundation states that one of the most important standards throughout the process has not changed: This loophole cannot be justified if the problem cannot be repeated in the real code repository by anyone other than the reporting agent.

This requirement, in its view, would exclude a wide range of common misstatements, including improbable paths of attack, failure in debugging mode only, and a test result that, although formally established, did not prove that actual security attributes had been compromised.

The team also noted that, even if it were technically re-emergible, the issue of candidatures would need to continue to be assessed for practical availability. The deficiencies that any network participant can trigger are not the same as the problems that must rely on privileges or unrealistic computational conditions.

Additional information:According to the Foundation, AI ' s performance remains unstable when it comes to judging the accessibility of the attack, the extent of the gap and the problems that require long-link interaction. At this stage, it is more appropriate to act as a support tool with a status test framework than as a substitute for senior security researchers.