The Etherwood Foundation recently disclosed that its development team, using software on which to rely for co-testing with AI proxy, discovered a remote-triggered crash hole in the Internet news system goosipsub. The problem has been repaired and registered as CVE-2026-34219.
This test also reveals another, more realistic problem: AI does not have the difficulty of giving a seemingly complete and logical description of a loophole, but a significant part of it does not constitute a real risk. The Foundation stated that the real time-consuming link was not “triggers”, but rather a distinction between real loopholes and high-level and credible misinformation.
The leak is on the message transfer level
The network consists of a large number of nodes, which are responsible for the preservation of data in the chain and the transmission of information to the adjacent nodes. The certifier is based on this layer of network and is responsible for the pledge of ETH and participation in the validation of block validity, so that the steady delivery of the information is directly related to the proper functioning of the certifier.
According to the Foundation, the problem discovered was in Gossipsub. The attacker can break down from the remote trigger node software, which allows the program to exit directly after encountering unmanageable calculations. Once the node is closed, the relevant certifier will be offline until the transporter is able to restart manually.
AI will write like a real false report.
The foundation ' s developer, Nikos Baxevanis, stated that the surprise of the exercise was that it was not in itself the most difficult to find a suspect, but to determine which problems really existed. Traditional fuzzy testing tools usually return to crash positions and duplicate records, and engineers can confirm them more quickly; however, AI agents often produce a set of descriptions at the same time, including attack paths, impact descriptions, severity judgements and even demonstration codes.
The problem is that, even if it is based on a false premise, it can be written in a very real way. The Foundation summarized three common types of misinformation:
- Only crashes in test construction
- External assailants can't actually reach danger. Value
- Formalized certification only proves irrelevant conclusions
Complex attacks still require manual verification.
The Foundation also mentioned that AI was better at analysing the issue of a single moment, but was less sure about the loophole that “each step appeared normal and combined before the attack”. Such problems are the very common pattern of many encrypted protocol attacks this year.
For example, Edel Finance and BONK related attacks involved a series of apparently legitimate operations that were not unusual at each step, but that would result in damage if executed in a given order. The Foundation therefore takes a more cautious approach: let AI first propose suspicious steps worth testing and then complete the validation by traditional testing methods and manual review.
This means that AI ' s role in the security of the agreement is closer to the thread-generation tool than to the final adjudicator. In the case of infrastructure such as the Ether Workshop, automated tools can expand the scope of the screening, but the existence and the realness of the gaps will depend on the engineering team to confirm them on a case-by-case basis.
