Cardano Auditors Call for Continuous Reviews as Intersect Bounties Go Unfunded

Security specialists at a Cardano Foundation roundtable said application reviews must extend beyond smart contracts to signing systems, software dependencies, and operational procedures. Intersect Security Council member Samuel Leathers said vulnerability reports are still being reviewed, but the current funding cycle has no money available for bug bounty payments.

By SongMarketCap

Cardano News - Cardano Auditors Call for Continuous Reviews as Intersect Bounties Go Unfunded

The September 28 discussion brought together Philip DiSarro of Midgard Labs, Santiago of TxPipe, Aleksandr of Tweag, Ben Hart of MLabs, and Leathers. Moderated by Cardano Foundation’s Denicio Bute, it examined how AI is changing both the discovery of vulnerabilities and the work required to defend Cardano applications.

AI Divides Cardano Security Experts

Bute opened by asking whether recent exploits in the Cardano ecosystem could have involved AI-assisted attackers. DiSarro argued that current models give skilled attackers powerful tools for examining code and pursuing complex exploits. In his view, development teams need to test their own protocols repeatedly as those tools improve.

Hart challenged the idea that AI can already perform the work of an expert attacker or auditor on its own. In audits where he used AI, people still identified the most significant problems. A human recognized the weakness in a product’s specification and devised a way to test it, even when a model helped produce the test code.

Leathers described a practical limit from Intersect’s vulnerability reports. Submissions have increased sharply, but many do not establish a real security issue. He said the strongest reports generally still come from researchers with relevant expertise. The panel offered no case-specific evidence establishing that AI was used in the Cardano exploits discussed during the session.

The speakers also rejected the assumption that Cardano’s extended UTxO model makes its applications difficult for AI tools to analyze because those tools are more familiar with EVM code. Leathers pointed to the available documentation for Cardano and Plutus. Cardano’s architecture prevents some classes of smart contract attack, but an application can still contain flaws in its own logic or surrounding systems.

Cardano Audits Extend Beyond Smart Contracts

The discussion moved from contract code to the full path by which an application handles user funds. Servers, software libraries, wallet connections, signing devices, and administrative keys can all affect the outcome of a transaction. A secure on-chain validator cannot protect users from every failure in those components.

Hart said AI-generated code has made specifications more important. If a development team cannot describe precisely what its product should permit and prohibit, an auditor has no reliable standard against which to check the implementation. Santiago added that teams must define their threat model and decide how much flexibility or upgradeability they want, since those choices can introduce additional ways to change a system.

That work gives tests and formal verification a concrete purpose: checking whether the application preserves its stated rules. DiSarro argued that teams should go further by attempting controlled attacks against their own protocols. Reviews also need to follow meaningful changes to code, infrastructure, and operating procedures, rather than relying indefinitely on an audit completed before launch.

The auditing firms described AI as part of that process. Models can scan for patterns, compare code with specifications, and suggest potential attack paths. Santiago said his team checks automated findings through human review; the panel also discussed using more than one model because different tools can uncover different issues. False positives still consume review time, while sensitive code and computing requirements affect whether a team uses a hosted or locally operated model.

Intersect’s Bug Bounty Program Faces a Funding Gap

Leathers then identified a separate problem for coordinated vulnerability disclosure. He said bug bounty funding was not approved in the current treasury cycle. Researchers can still submit reports, and the Security Council continues to examine them, but it cannot presently pay new rewards through that funding route. He said the council is working with Intersect on alternatives and that a community-approved treasury withdrawal could provide funding.

Intersect launched its bug bounty program in 2025 for infrastructure and tools it manages or sponsors. Smart contracts fall within its scope only when explicitly included. Leathers’s remarks concerned that program; the Cardano Foundation operates a separate bounty arrangement.

A larger volume of AI-generated reports also raises the cost of reviewing submissions. Leathers called for stricter triage so that reproducible vulnerabilities receive attention while incorrect findings and ordinary maintenance issues are classified appropriately. DiSarro separately urged individual DeFi protocols and bridges to establish their own rewards and incident procedures before an exploit occurs.

The roundtable left Intersect with a defined governance question. Its disclosure channel remains open and the Security Council is still assessing reports. Funding for researcher rewards now depends on a new arrangement or a treasury decision. That decision will determine whether a valid finding under Intersect’s program can again lead to the payment the program was designed to offer.