
Helius Labs CEO Mert Mumtaz warns that AI and formal verification will expose fragile crypto protocols. Here is what that means for project due diligence.
The CEO of Solana infrastructure firm Helius Labs has warned that the crypto industry is heading into a security reckoning where artificial intelligence and stronger software verification tools will expose projects built on weak foundations.
Mert Mumtaz said in a series of posts on X that many crypto protocols are like "straw houses" – they appear functional under normal conditions but cannot withstand serious stress. The rising capability of AI agents to find vulnerabilities, combined with the adoption of formal verification methods, means teams that skip rigorous engineering will face a reckoning.
Formal verification is a mathematical technique that proves a piece of software behaves exactly as intended for all possible inputs. It is standard in aerospace, defence and high-frequency trading but rare in crypto. Most projects rely on bug bounties, manual audits or fuzz testing, which catch known patterns but miss edge cases. AI-driven tooling accelerates both the discovery of exploits and the ability to verify code at scale.
Mumtaz argued that the industry has tolerated sloppy code because the economic incentives have favoured speed over reliability. That trade-off is closing. AI agents can now parse smart-contract bytecode, locate reentrancy vectors and simulate attack paths faster than human auditors. A single AI-audited report can surface vulnerabilities a team of manual reviewers might miss over weeks.
The "straw houses" problem is not limited to small projects. Mumtaz pointed to high-profile hacks on protocols that had been audited multiple times. The audits gave users false confidence, he said, because they checked for known flaws rather than proving the absence of flaws. Formal verification does not eliminate all risk – it requires a precise specification of what the code should do – but it raises the bar for what counts as secure.
Crypto investors have a limited set of signals to judge security. A list of audit firms on a project's site says little about the depth of the review. Mumtaz's framing suggests a better question: is the team using formal verification tools, and if not, why not? Teams that treat security as a checkbox will look increasingly exposed as AI-driven analysis becomes standard.
The warning comes at a time when institutional capital is flowing back into crypto after the 2022-2023 bear market. Mumtaz noted that larger allocators already demand higher software standards. As more of them enter, the gap between infrastructure-grade protocols and speculation-grade contracts will widen.
None of this means the industry collapses. It means the projects that survive will be the ones built with the same rigor expected in traditional finance. The rest will be the straw houses that fall.
Mumtaz did not name specific tokens or teams in his posts. His point was structural: the technology that made crypto accessible also made it fragile. AI is now making that fragility visible.
Prepared with AlphaScala research tooling and grounded in primary market data: live prices, fundamentals, SEC filings, hedge-fund holdings, and insider activity. Each story is checked against AlphaScala publishing rules before release. Educational coverage, not personalized advice.