A revealing discussion between Merkle Science and Olympix on September 26, 2025, laid bare the dual role artificial intelligence now plays in the Web3 security landscape, acting as both a force multiplier for defenders and an acceleration tool for attackers. As the cryptocurrency market navigates a period of heightened volatility with Bitcoin holding above $109,700 and Ethereum above $4,035, the intersection of AI and blockchain security has become one of the most consequential battlegrounds in the digital asset space.
The Synergy
The conversation between Dr. Justus Delp of Merkle Science and Channi Greenwall of Olympix established a critical framework for understanding AI in Web3 security: AI functions as an accelerator rather than a silver bullet. It amplifies the capabilities of skilled practitioners on both sides of the equation. Attackers leverage AI to scan codebases for vulnerabilities, generate exploit inputs, and surface patterns that would take human analysts significantly longer to identify. Defenders, meanwhile, can deploy AI to strengthen static and dynamic analysis, enhance behavior analytics, and accelerate incident triage when anchored to proven security controls.
Greenwall captured the dynamic succinctly: AI accelerates top people, enabling them to accomplish ten times what they previously could. The practical implication for 2025 is that organizations should invest in AI tools that enhance existing security workflows rather than pursuing solutions that promise to find everything with minimal human oversight.
AI Use Cases in Web3
In the defensive context, AI-powered tools are being integrated across multiple layers of the Web3 security stack. Static analysis tools now use machine learning models to identify suspicious code patterns in smart contracts before deployment. On-chain behavior monitoring systems leverage AI to detect anomalous transaction patterns that may indicate an ongoing exploit. Incident response platforms use AI to correlate events across multiple data sources, reducing the time between detection and containment.
However, the discussion also highlighted a sobering statistic: approximately 90 percent of exploited smart contracts had undergone security audits before being compromised. This finding underscores that point-in-time audits, while valuable, cannot serve as the sole safeguard in an environment where dependencies shift and exploits can unfold in seconds. The recommended approach is a layered security model, starting with proactive developer tooling, proceeding through disciplined testing and multiple audit passes, and continuing with continuous on-chain behavior monitoring and rehearsed incident response plans.
Data Privacy Implications
The growing use of AI in Web3 security raises important questions about data handling and privacy. AI models require substantial amounts of transaction data, code repositories, and incident reports to function effectively. Organizations must balance the security benefits of AI-powered analysis against the risks of centralizing sensitive blockchain data in AI training pipelines.
The supply chain attacks that plagued the npm ecosystem throughout September 2025 demonstrated that AI-generated code can itself introduce critical vulnerabilities. The S1ngularity incident began with an AI-generated GitHub Action that contained a command injection flaw, which attackers then exploited to steal publishing credentials and distribute malware. This creates a paradox where the same AI tools designed to improve security can inadvertently expand the attack surface.
The Innovation Frontier
Looking ahead, the most promising developments lie at the intersection of AI and real-time threat detection. Projects like Guardrail are deploying AI models specifically designed for continuous on-chain monitoring, partnering with major blockchain networks like Sui to provide proactive security support. These systems aim to detect exploits as they happen rather than relying on pre-deployment audits alone.
Institutional adoption of cryptocurrency is also driving innovation in AI-powered compliance tools. With traditional financial institutions entering the Web3 space, requirements around sanctions exposure, counterparty risk, and operational resilience are setting de facto standards that protocols and service providers must meet. AI-driven address attribution, automated anti-money-laundering screening, and behavior-based monitoring are becoming prerequisites for institutional partnerships.
Concluding Thoughts
The Merkle Science and Olympix discussion made clear that Web3 security in 2025 is fundamentally an organizational challenge, not merely a technical one. Executive accountability for security outcomes, board-level oversight of security baselines, and a culture that treats security as a continuous process rather than a checklist item are all essential components of an effective defense. As AI continues to reshape both attack and defense capabilities, the organizations that invest in skilled people empowered by AI tools, rather than replacing people with AI alone, will be best positioned to protect their assets and their users.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making investment decisions.
Dr Delp saying AI is an accelerator not a silver bullet is the most honest take ive seen from a security firm. most pitch AI as a solution
Social engineering attacks are becoming more sophisticated
AI attacking and defending at the same time. the attacker uses AI to find vulnerabilities in minutes and the defender uses AI to patch them. speed is the new battleground
red_team_ speed is the battleground but so is cost. AI scanning costs pennies vs a 50k audit. the democratization of security tooling matters more than raw speed
Kai N. AI scanning costing pennies vs a 50K audit is the democratization angle. solo devs can now run basic security checks that used to require a firm
Vesna T. AI scanning for pennies vs 50k audits is the real revolution here. solo devs finally have access to basic security tooling
the speed point is underrated. before AI tools an auditor might take weeks to find what AI surfaces in hours. the defense side needs that same acceleration or theyre always catching up
thabo m. speed helps but AI audit tools generate massive false positive rates. teams start ignoring warnings when 90% are noise. human verification is still the bottleneck
false_pos_ the 90% noise problem is real. teams get flooded with AI warnings and start ignoring all of them including the one that actually matters
false_rate_ the 90% noise problem creates alert fatigue. teams start ignoring everything and then miss the one real critical. seen it happen on three separate protocols
false_pos_reader 90% false positive rate means teams stop looking at alerts. then the real exploit slides through buried in noise. seen it happen twice
90 percent false positive rate means teams start blanket ignoring alerts. then the one real exploit slides through and nobody notices until funds are gone
BTC at 109k and ETH at 4035 means the attack surface is worth more than ever. a single contract bug at these prices is a 9 figure payday
Olympix and Merkle both know attackers use the same AI tools. the asymmetry favors whoever moves first on remediation
Real-time monitoring tools are getting better at catching exploits early
Layer2Fanatic real-time monitoring only works if the protocols integrate it natively. bolt-on monitoring catches the attack after the funds are already moving
Bjorn K nailed it. native integration vs bolt-on is the difference between stopping a $50M exploit and writing a postmortem about it
Multi-sig wallets should be the default for everyone in crypto
Delp and Greenwall are right that AI is a force multiplier. but when both sides have AI the attacker still wins because they only need to find one bug
bjorn k makes the best point in the thread. native integration means the monitoring is part of the protocol itself not an afterthought bolted on post-deploy
red_team_ had it right. speed is the battleground but defenders are still losing because patching requires a governance vote on most protocols
patch_lag_ governance votes for patching is the killer. by the time a DAO approves a fix the attacker already drained everything. emergency response cant be democratic
red_team_grind governance votes for emergency patches is insane. a multisig with a 24h timelock would fix this but DAOs refuse to give up control
governance votes to patch critical vulnerabilities is the dumbest DAO pattern still alive. a multisig with timelock would fix this overnight
red_team_grind governance votes for security patches is a structural problem nobody talks about. imagine if tradfi needed a shareholder vote to patch a critical vuln. absurd
AI scanning costing pennies while human audits run 50k is the real democratization moment. solo devs finally getting tooling that was gatekept by budget for years