# Grego AI | Going Beyond the Harness: Why Most AI Bug Detection Is Still Theater - Justus Hanna

- Channel: [CryptoCanal](https://streameth.org/cryptocanal)
- Date: 2026-09-25
- Watch: https://streameth.org/watch/yt-9Oobw0pHmaQ
- YouTube: https://www.youtube.com/watch?v=9Oobw0pHmaQ

## Transcript

For my esteemed guest. Thank you for visiting. So, I'm Justin Hannah. I am the CEO of Grego AI. We are now an AI-based cybersecurity company specializing in Web3. We are also moving into traditional cybersecurity. My talk today is about going beyond conventional hardware and why you perceive a lot of this AI error detection as theater rather than real error detection, unique errors that you can exploit. So, let's take a look. Further. That's it. So, everyone, and I really have to go through this quickly . So, you can run Claude, and you can type in a query, find all the errors, and then you can create the hardware. Uh, you can do a bunch of different things using AI to find bugs. Good. So, everyone is convinced that their way is the best. And why do we need to pay for a security audit now? Because everyone has their AI tools and they think that, um, they can find all the bugs with that. Why pay for it at all ? Uh, the reason why it's not is because what happens with artificial intelligence is that you have, uh, models, and then you have what's called a framework around that. You guys have heard this before. The strapping can actually be the essence of the product. So, a bund is a protected moat. Uh, and it could be a very basic type of be a very basic type of , uh, tip or skill. You've seen Pashov's skills. It could be, uh, something like that, or it could be a very advanced kind of framework in the infrastructure that we have. Uh, the difference between these two is huge. Uh, there are many levels in this science, I like to call it, uh, where you can have a lot of noise, you can have a lot of false positives, uh, and you can just waste a lot of your time, doing a lot of computation, or you can actually get to the signal and get real meaningful vulnerabilities, uh meaningful vulnerabilities, uh , by going really, really deep, using a lot of computation, uh, which is what we're doing. Uh, just to quickly review this, I don't have much time. Um, like I said, uh, this is basically a general level. So maybe we can talk about what we do a little differently, uh, that you might consider doing on your own if you want to try it. Uh you want to try it. Uh , we built an entire company around this for 2 years, developing what years, developing what we use to find bugs, or you just call us. Uh, but some of the things we do, uh, structural mapping of the code, uh mapping of the code, uh , to start with, we break down the whole protocol and make, essentially, a bunch of separate pieces. An algorithm for ranking users by tracking a bunch of different agents on it. It is very difficult to go into all the details here. We've trained it on thousands and thousands of attack vectors. We have thousands of agents. We probably spend a trillion tokens, uh, probably every month. We do our checks extremely thoroughly, and basically teams of agents are looking into this and trying to crack your protocol, trying to find bugs that humans can't find because these things are too complex for any human to be able to dig as deep as AI can to find these edge cases. Also, what you don't do on your own with your security, what we do is we take our findings that we find with our artificial intelligence and say, "Hey, listen, we're also going to develop a proof-of-concept." We have experienced security researchers working in our company who check and verify everything from start to finish to provide our clients with only the best signals. So we're not going to give you like our competitors who give you 100 false positives and say, "Hey, here's the report, pay us money." We only come to you with valid reproducible errors, like in a human audit report, except our quality is on par with human, sometimes higher than human, because we find things they literally can't find. And also, as I said, our approach is hybrid. We use the capabilities of artificial intelligence, but we still use the capabilities and abilities of people who are able to manage it and understand the results, understand the tool. You can't just blindly take AI and say, " take AI and say, " Hey, even with all the tools, and say, "Hey, find bugs. "Uh, what does fixing this error look like?" And our senior specialists can say, “Hey, look, here’s a suggested fix. That's why it makes sense. "Uh, that's why it doesn't have one." Okay, this is a good slide that we could focus on for 1 minute. Uh, some theory vs. execution stuff, right? Uh, understanding the code, uh, general AI capabilities, and then what we do, uh, on top of that. So, basically, this speaks to your overall capabilities of using AI, the main point is that you just won't get as much benefit from it no matter how much you take the professional approach that we've already done. Everything we do is focused on security and finding bugs. While a company is building its product, it sells it to customers and then thinks it can do a great job. It's like me when my wife says, when my wife says, "Hey, you need to fix the plumbing." I do plumbing repairs once a year and I try my best , but I won't be as good as a professional plumber. So perhaps the same analogy applies to security. Maybe you should contact us instead of just trying to set up your own security. So, we are the number one AI tool on Immunify and Hackenproof. We have won 600,000 bounties in the last 6 months. Um, we... Our biggest payout was 250,000. We saved 27.7 million. These are all relevant, critical, and high-quality findings, uh, on public bug bounties. These are not benchmarks. These are not audit results. We want to prove how good our tool is compared to others. We just found real bugs that were lying there in the blockchain, uh, that no one else could find with their artificial intelligence tools. So we thought this was a great way to say, “Hey, use our services. Uh, give us a chance, and here's why. I'm not just blowing smoke . This is, uh, a pretty powerful tool. So if you're interested, uh, please contact me. Here is my Telegram. Um, we're happy to cover anything you need with your team. And we hope that we can help your security at a very affordable price that scales and keeps you safe from being hacked. Thank you very much.
