Ethereum Foundation Expands AI Security Team to Protect Core Protocol
Keeping Ethereum secure is becoming an even bigger priority as the Ethereum Foundation looks to strengthen the team responsible for finding weaknesses before they can affect the network.
The organisation is recruiting an AI-focused Protocol Security Researcher to help identify vulnerabilities across Ethereum's core infrastructure, combining automated security testing with detailed human analysis.
The new role is designed to support the Foundation's Protocol Security team, which reviews critical parts of Ethereum before software updates reach the main network.
Rather than responding to an active security incident, the recruitment is aimed at strengthening long-term protocol security.
The Role Covers Every Layer of Ethereum
The successful candidate will investigate security issues across Ethereum's execution layer, which processes transactions and smart contracts, as well as the consensus layer that coordinates validators.
The work also extends to the peer-to-peer network, protocol specifications and the client software responsible for implementing Ethereum's rules.
Responsibilities include developing fuzzing tools, reviewing protocol changes planned for future hard forks, manually auditing updates and coordinating the responsible disclosure of confirmed vulnerabilities.
The Foundation also expects the researcher to use AI systems to automate parts of vulnerability discovery while independently verifying every confirmed finding before it is reported.
Why Human Researchers Still Matter
Although AI is becoming increasingly useful for identifying possible security flaws, the Foundation said human expertise remains essential to determine which findings are genuine.
During recent internal testing, coordinated AI agents examined Ethereum protocol code, cryptographic software and other network components.
The experiments successfully uncovered real software flaws, but researchers found that verifying those discoveries required far more effort than detecting them.
"The agents found real bugs…Agents finding bugs wasn't the surprise. The surprise was how little of the work went into finding them, and how much went into telling the real bugs from the ones that just looked real."
One confirmed issue involved a remotely triggered panic affecting libp2p's gossipsub component, which is used by Ethereum consensus clients for peer-to-peer communication.
Developers fixed the vulnerability before it was publicly disclosed as CVE-2026-34219.
Researchers said every AI-generated report still required reproducible evidence, proof-of-concept code and manual review before it could be classified as a genuine vulnerability.
Experienced Ethereum Engineers Preferred
The Foundation is looking for candidates with deep knowledge of the Ethereum protocol and has indicated that engineers who have already contributed to protocol development or understand execution-layer and consensus-layer specifications will be preferred.
The role involves working with programming languages including Go, Rust, Java, C#, Nim and Python.
It is a remote position open to applicants across Europe and other regions worldwide.
Recruitment Continues After Foundation Restructuring
The vacancy follows a recent restructuring at the Ethereum Foundation that resulted in the closure of its Protocol Support team and the removal of 54 roles, representing about 20% of the organisation's workforce.
The former team had coordinated core developer meetings, tracked network upgrades, supported contributors working on Ethereum Improvement Proposals and managed training programmes for new protocol developers.
Since then, several former researchers have moved into independent organisations.
Mo Jalil, Oskar Thorén and Aaryamann Challani launched EthSystems, a commercial company developing confidential Ethereum infrastructure for regulated institutions with backing from Bitmine, SharpLink and Consensys CEO Joe Lubin.
Former Foundation researcher Francesco D'Amato also joined independent protocol research group Ethlabs on 16 July 2026.
Despite the broader restructuring, the latest recruitment shows the Foundation continues to invest in specialised security expertise while some development and coordination work moves beyond the organisation itself.
Security Remains A Core Priority
The Foundation has continued reinforcing its security focus in recent weeks.
On 29 July 2026, security researcher Pascal Caversaccio joined its board for an initial one-year voluntary term, expanding the board to four members with an emphasis on security, privacy and censorship resistance.
The Foundation said the latest hiring should not be viewed as a response to a newly discovered vulnerability.
Instead, the position strengthens the team responsible for reviewing future protocol upgrades and identifying security weaknesses before changes are deployed across Ethereum's main network.