The Ethereum Foundation is hiring a protocol security researcher to blend AI-driven discovery with traditional fuzz testing and manual audits to hunt for vulnerabilities across Ethereum’s core infrastructure. What the role entails - The new hire will join the Protocol Security team and investigate weaknesses across the execution layer (transaction and smart-contract processing), the consensus layer (validator coordination), the peer-to-peer network, protocol specifications, and the client implementations that enforce protocol rules. - Core responsibilities include building and improving fuzzing tools, reviewing changes slated for hard forks, performing manual protocol audits, coordinating responsible disclosure of confirmed issues, and using AI systems to help automate vulnerability discovery. Why AI plus human review The posting reflects lessons learned from recent experiments: AI agents and automated tools are powerful at surfacing potential problems but generate many false positives. The Foundation’s July 9 technical post said its coordinated agents “found real bugs,” but stressed that most of the work was separating true vulnerabilities from findings that only looked like bugs. Researchers must reproduce issues, produce proof-of-concept code, and apply human judgment before treating a report as a vulnerability. Real-world test case One confirmed result of those tests was a remotely triggered panic in libp2p’s gossipsub component (part of the peer-to-peer layer used by consensus clients). Developers patched the issue before it was publicly disclosed as CVE-2026-34219. That example underscores both the promise of automated discovery and the need for careful verification and disclosure processes—exactly the workflow this role aims to formalize. Who they’re looking for - Deep Ethereum protocol expertise—preferably candidates who have contributed to protocol development or are familiar with execution- and consensus-layer specifications. - Strong programming experience in languages used by clients and tooling, including Go, Rust, Java, C#, Nim, and Python. - The position is remote and open to applicants in Europe and other regions. Organizational context The opening comes after a significant restructuring: less than a month earlier the Foundation dissolved its Protocol Support team and cut 54 roles—about 20% of its workforce. Protocol Support had coordinated core developer meetings, tracked network upgrades, helped contributors navigate Ethereum Improvement Proposals, and ran training for new protocol developers. Some former Foundation researchers have since launched or joined independent ventures—examples include EthSystems, founded by ex-employees Mo Jalil, Oskar Thorén, and Aaryamann Challani (backed by Bitmine, SharpLink, and Consensys CEO Joe Lubin), and researcher Francesco D’Amato’s move to independent group Ethlabs on July 16. At the same time, the Foundation has signaled a continued focus on security: it appointed security researcher Pascal Caversaccio to its board on July 29 for an initial one-year voluntary term, expanding the board to four members and reinforcing priorities like security, privacy, and censorship resistance. Why it matters to investors and the ecosystem Protocol security has direct implications for U.S. and global markets because Ethereum underpins spot ETFs, stablecoins, tokenized assets, and many institutional applications. A vulnerability in consensus or client code could ripple well beyond the Foundation, affecting exchanges, custodians, and decentralized finance systems. The new hire is not a response to a freshly discovered flaw; rather, it strengthens the team charged with reviewing future hard forks and catching weaknesses before changes reach the mainnet. Read more AI-generated news on: undefined/news