The Ethereum Foundation’s Protocol Security team said coordinated AI agents helped identify a real networking issue in libp2p gossipsub, a peer-to-peer component used by Ethereum consensus clients.

The public case was disclosed as CVE-2026-34219 and fixed before wider disclosure. The same report also stressed a practical limit: agents produced many findings that still needed human review to separate real bugs from false positives.

This matters because AI is becoming a security tool, not just a coding assistant. For open networks, faster bug discovery can reduce exposure time. The second-order risk is operational noise: if teams trust automated reports too much, false positives may absorb reviewer time or hide more serious issues.

Next, watch whether major protocols build formal AI-assisted audit pipelines instead of one-off experiments.