# Adversarial AI Agents for Web3 Security I Preetam Rao

- Channel: [ETHGlobal](https://streameth.org/ethglobal)
- Date: 2025-11-09
- Duration: 15:55
- Topics: adversarial AI, reinforcement learning, red-team copilot, MDP, invariants, self-learning attacker, Web3 security, smart contract auditing, zero-day discovery, re-entrancy, timestamp bug, symbolic execution, fuzzing limits, LLM agent security, prompt injection, memory erasure, nondeterminism, guardrails, QuillAudits, QuillGuard, continuous security, cross-chain exploits, DeFi vulnerabilities
- Watch: https://streameth.org/watch/yt-WpiGhgodmRI
- YouTube: https://www.youtube.com/watch?v=WpiGhgodmRI

## Description

Preetam Rao (QuillAudits co-founder) explores how adversarial AI agents and reinforcement learning can harden Web3 systems. After noting today’s sprawling attack surface (cross-chain bridges, modular stacks) and the limits of static/symbolic analysis and fuzzing, he argues that LLM-powered agents introduce non-determinism and new prompt-hacking risks (memory erasure, fund transfers).

He proposes self-learning, RL-based “red-team” agents that model attacker behavior, search contract/agent state spaces, and optimize against invariants (win conditions). Using an RL framework (states → actions → rewards), his team’s “Red-Team Copilot” learned re-entrancy, then discovered a new timestamp bug without being explicitly trained. He closes by positioning adversarial agents as a continuous, proactive layer alongside audits—applied both to smart contracts and LLM agents (via their “QuillGuard” guardrails).

00:02 Opening & background (QuillAudits, 1,500+ protocol engagements)
01:37 Constant in Web3: weekly hacks/scams despite growth
02:13 Trust deficits: founders/devs/third parties; broader attack surface (bridges, AMMs, lending)
03:15 Why current tooling falls short: static, symbolic, fuzzing limits
05:20 LLM agents are attackable: prompt injection, memory wipe, nondeterminism
06:54 Real incident: agent manipulated to transfer funds (~$100k)
08:04 Monitoring/AI “auditors” trained on past bugs struggle with zero-days
09:41 Enter adversarial RL: self-learning attacker agents
10:42 MDP framing: state, action, reward; define invariants as win conditions
11:48 Applying to contracts & agents; reward signals and learning loops
13:05 Red-Team Copilot demo concept: access-control & multi-tx paths
14:14 Result: RL trained on re-entrancy later found a timestamp vulnerability unprompted
14:52 Extending to AI agents: QuillGuard for guardrails
15:25 Call to action & research paper; future of self-learning adversaries

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

🇮🇳 *Pragma New Delhi*
Pragma New Delhi 2025 was held on September 25th at the JW Marriott Hotel in Aerocity New Delhi and was an in-person summit for builders and leaders in the web3 ecosystem. Watch the full Pragma New Delhi YouTube Playlist here: 

ETHGlobal's Pragma series takes place in cities around the world, and is designed to be a different kind of event. Pragma is a one-stage conference with founders-only on stage, bringing together a small group of curated attendees and speakers to discuss the future of web3 and reflect on the past. 

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

✅ Follow Preetam Rao
X: https://x.com/raopreetam_

✅ Follow QuillAudits
X: https://x.com/QuillAudits_AI

✅ Follow ETHGlobal
X: https://x.com/ETHGlobal​
Warpcast: https://warpcast.com/ethglobal
Website: https://ethglobal.com
YouTube: https://www.youtube.com/@UCfF9ZO8Ug4xk_AJd4aeT5HA 

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _  

Are you interested in Ethereum development and entrepreneurship?
👉 Sign up for the next ETHGlobal event: https://ethglobal.com/events
🎁 Get exclusive access and perks with ETHGlobal Plus! https://ethglobal.com/plus
📣 Want us to throw an event in your city? Tell us where! https://ethglobal.com/city

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
