Main takeaway: The Ethereum Foundation's AI agent found a gossipsub bug that could crash nodes and take validators offline until operators restart. The issue was quickly fixed and disclosed as CVE-2026-34219; the AI excelled at spotting bugs but struggled with multi-step issues.
币界网消息,以太坊基金会表示,最近在其软件上部署的AI代理发现了一个可能导致验证者离线的漏洞。虽然发现了漏洞,但仍需细致的人类判断来区分真实漏洞与假阳性。该漏洞位于gossipsub中,允许远程系统触发崩溃,导致节点软件出现无法计算的情况,进而关闭验证者,直到操作员重启。该漏洞已迅速修复并披露为'CVE-2026-34219'。以太坊基金会还指出,AI代理在识别漏洞方面表现出色,但在处理跨多个步骤的漏洞时则显得较弱。