The Year Finding and Exploiting Bugs Became Cheap, and What to Do About It
ZK/SEC Quarterly
Opinion — commentary, not a factual news event.
Security researchers increasingly use LLM-based tooling to find bugs and build exploits, and the article says this has made exploit activity grow because both discovery and exploitation have become much cheaper for attackers and defenders. In 2026, two exploits against live ZK circuits are cited, including one that rescued about $1.5 million and another drained 5 ETH. The change pushes security toward continuous, layered defenses—updating tests, AI harnesses, audits, and formal verification—rather than relying on audits done once in the past.
Why it matters
As offensive capability becomes more abundant, the challenge for defenders will be handling critical bugs quickly. The piece argues that security infrastructure and integration will matter most, while formalization could reduce some costs but connecting proofs to production code remains difficult.