When AI Learns to Become a White Hat Hacker: A Fully Automated Pipeline from On-Chain Vulnerability Scanning to Fund Rescue
- Time
- 2026-08-08 09:30 ~ 10:00
- Speaker
- fffuuuming, Aaron Yeh
- Room
- TR511
- Co-write
Abstract
Smart contract incidents aren’t just a code problem—they’re an operations problem: threats emerge on-chain continuously, time-to-triage is short, and “finding a bug” is not the same as proving exploitability or preventing loss.
This talk presents an autonomous security agent designed to close the loop from discovery to action. Instead of only auditing source code or generating standalone proofs-of-concept, it continuously scans on-chain contracts, prioritizes targets using discovery heuristics, generates and validates exploit PoCs, estimates real economic impact via simulation, and performs rescue to reduce loss when authorized.
We’ll cover the system architecture, and focus on the most difficult part of the loop: how to move from a suspected vulnerability to an exploitable PoC, and then how to turn that PoC into an actually deployable attack or rescue contract. Through 1–2 concrete examples of vulnerabilities that could lead to fund loss (e.g., Reentrancy), we’ll discuss how the agent reasons about exploitability, gathers the required on-chain context, validates the exploit through simulation, and adapts the PoC into executable rescue logic.
The goal is simple: move smart contract security from periodic audits to continuous, end-to-end defense operations that prioritize what is actually exploitable, what matters economically, and what can be acted on safely.
Speaker
fffuuuming
Web3 Software Engineer Master @NTU CSIE
Aaron Yeh
- Web3 Software Engineer
- Google Developer Groups on Campus, Community Lead @University of Taipei
- Co-Founder @Corvo AI (SRE Agent)
平常就上上學和上上班的大學生,閒暇之餘也創創業、玩玩社群、搞搞區塊鏈。