Edited By
Anna Petrov

A new generation of AI security scanners is shaking up the crypto scene, with one in particular auditing live deployed contracts. This development raises concerns over the effectiveness of automated bug-fixing in decentralized environments.
AI security scanners, specifically designed for GitHub repositories, have seen a slow but steady rise in popularity. Aeonโs vuln-scanner is noteworthy for its successful track recordโ74 repositories hardened with issues like DNS rebinding and SSRF bypasses documented on its disclosure page.
This week, Aeon's scanner shifted focus to Solidity, taking aim at live deployed contracts and fresh Solidity repositories.
"The team claims it has already found vulnerabilities in Binance SDK and OpenSea contracts," said a representative. Although these issues arenโt public yet, the proactive stance is clear.
Automated audits come with unique challenges. Deployed contracts are immutable and cannot be patched like traditional code. When an issue is found, developers must either upgrade or migrate, which isn't always straightforward.
Many ask, is an autonomous scanner for live contracts a boon or just more noise?
Comments on user boards suggest mixed sentiments. Many believe the scanning process will generate unnecessary noise, complicating the response for professional auditors already stretched thin.
"Seems like a bad ad it mostly generates noise,โ one user remarked.
Others worry about the implications for responsible disclosure, given the lack of patch options.
74 repositories audited and secured by Aeonโs vuln-scanner
Found vulnerabilities claimed in major industry SDKs and contracts
Industry experts divided on the scannerโs effectiveness
"Verification still isnโt solved,โ points out a seasoned auditor. โFalse positives are a real cost for maintainers."
As AI takes on a more prominent role in auditing, its effectiveness and efficiency remain under scrutiny. While some see it as a revolutionary step forward, others are cautious, fearing it could lead to more issues than resolutions. With the stakes high in the crypto space, how will the industry navigate these uncharted waters?
For more on the evolving state of crypto security, visit CoinDesk.
Thereโs a strong chance that as AI security scanners become more embedded in the crypto ecosystem, weโll see an increase in reliance on automated solutions, especially among smaller firms looking to save on audit costs. However, experts estimate around 40% of traditional auditors may find themselves overwhelmed by false positives generated by these tools, leading to potential conflicts or errors in the review process. The crypto communityโs sensitivity to unresolved vulnerabilities suggests that while automated audits may bolster some aspects of security, they will likely prompt a push for clearer protocols and cooperative frameworks between AI tools and human auditors, which could lead to more standardized verification strategies in the coming years.
The current situation mirrors the introduction of assembly lines in the early 20th century. Initially, laborers resisted this shift, fearing job loss and the mechanization of skilled work. Yet, over time, the assembly line didnโt replace skilled laborers but transformed their roles, allowing them to focus on more complex tasks that required human insight. Just as those early factory workers adapted to new technology, todayโs auditors may find their roles evolving rather than disappearing, leading to a more nuanced partnership between human expertise and AI capabilities.