CertiK Director Says AI Is a Double Edged Sword for Web3 Security

CertiK's Kaijern Lau says AI speeds up hacking and defense in Web3, requiring more investment in AI security tools.

maisiekooc
Maisie Morrison

AgentLocker Editor

AI News
CertiK Director Says AI Is a Double Edged Sword for Web3 Security

Kaijern Lau is the Senior Director of Engineering at CertiK. He recently spoke about how artificial intelligence is changing blockchain security. His comments came after a hack at Hugging Face, an AI platform.

That attack was carried out entirely by an autonomous AI agent. It marked the first known case of an AI system escaping its test environment and causing real world harm.

Lau said this event shows that AI driven cyberattacks are no longer a future problem. He said companies need to prepare for these risks now.

Why This Matters for Web3

Web3 security works differently than most software systems. Audits and checks usually happen before a project launches, not in real time.

This means smart contracts often cannot be updated quickly if a new threat appears. Lau said this makes the blockchain industry more exposed to fast moving AI based attacks.

He explained that AI can scan code and find weak points much faster than a person can. But he was clear that AI cannot be trusted alone.

"AI can help surface patterns and accelerate analysis, but experienced researchers are still needed to validate the findings and assess their actual impact," Lau said.

Lau also pointed to research on hardware wallet security. He said this research shows why human review still matters, even as AI tools improve.

He does not believe the Hugging Face incident proves that AI models are impossible to control. Instead, he said it happened during a specific testing setup.

Still, Lau said the incident shows how capable AI agents have become. He said these systems can now combine small weaknesses into a full attack.

How CertiK Is Responding

Lau said attackers and defenders will both get stronger as AI improves. He said the real question is how many resources each side puts into their AI tools.

CertiK has built tools to fight back. One is called AI Auditor, which scans blockchain projects for common security risks using multiple AI models.

Another tool, the AI Skill Scanner, checks AI systems for risks before they are used. Lau said this helps reduce problems like data leaks or unsafe automated actions.

He said CertiK treats its own AI tools as possible targets too. This includes checking for issues like prompt injection or excessive permissions.

Lau said CertiK's teams are working constantly to improve AI based security. He pointed to the company's CertiK Prover engine, which now uses AI to speed up code verification.

He said this has improved how quickly threats can be detected across blockchain projects. Lau added that training AI models to defend systems is now a core part of CertiK's work.

Looking ahead, Lau said AI will likely be a net positive for Web3 security overall. But he repeated that it remains a tool that can be used for both attack and defense.

"AI will be a net positive force for Web3 security, but it is undeniably a double edged sword that requires a continuous balancing act," Lau said.

maisiekooc

Written by

Maisie is a news writer at Agent Locker, covering the latest developments in artificial intelligence, emerging technology and the companies shaping the future.

Discover AI Agents