AI makes code scanning cheaper and faster, but it does not replace security judgment, and in digital assets, the most expensive failures have never been code bugs in the first place.
Ronin, Bybit, Drift: compromised keys, manipulated signers, governance issues. The smart contracts executed correctly.
AI agents are only as useful as the threat model of the team behind them. Teams that deploy AI tooling without that expertise are not buying security, but rather the appearance of it, which is worse.
During a full repository scan of Taiko, the Dedge platform surfaced an exposed private key in a public pull request. That finding did not come from a code vulnerability scanner, but rather a system built to understand operational exposure across the full development surface.
I heard recently that AI has already replaced Auditors. Someone said:
"There's no need to hire a web3 firm for smart contract audits, I think it's overkill, and AI does just as good a job nowadays."
My way of explaining why that's not the case was like this:
"Look at it also as, we all always had Google and Stack Overflow to search and solve our coding issues, but it made a difference who used them and how.
So, AI is powerful, yet it makes a difference how it’s used in what context and who is using it."
From my experience, it makes a huge difference for both development and auditing whether the person using AI is proficient.