Security in the AI Age | Krum Pashov, Pashov Audit Group | ETHSofia 2026
ETHSofia·Tue, Oct 6, 2026, 12:00 AM
Krum Pashov, founder and CEO of Pashov Audit Group, on how AI has reshaped Web3 security in 2026. With audit contests drying up, he argues that bug bounties are now the best permissionless path into the field, makes the case for specialising in a niche such as Bitcoin and BTCFi security, and shows how Pashov's free, open-source Solidity Auditor skill found 11 of the 13 high-severity bugs from a 2025 audit contest in under an hour. The talk closes with audience questions on what AI will and will not automate, and how the security researcher's job is changing. Keynote at ETHSofia 2026, 24 September 2026, Sofia Tech Park, Sofia. Part of Blockchain Week Bulgaria 2026. Speaker ▸ Krum Pashov, CEO, Pashov Audit Group Krum or "pashov", is Founder & CEO of Pashov Audit Group, protected over $100B of funds with 400+ security audits. LinkedIn: https://www.linkedin.com/in/pashov X: https://x.com/pashov Chapters 00:00 Introduction 00:11 Web3 security in 2026: what changed 02:11 Why bug bounties are the place to be 06:26 Freelance, full-time or your own firm 07:23 Go niche: the Bitcoin and BTCFi opportunity 10:46 Build your own AI auditing agent 12:17 Solidity Auditor V4: 11 of 13 high-severity bugs in an hour 16:01 Fork the open-source skills and build on them 18:12 Will AI replace security researchers? 20:15 Q&A: What AI will and will not automate 21:52 Q&A: How the daily job is changing 24:07 Q&A: Why Krum started Pashov Audit Group 25:38 Q&A: How an audit firm makes money 26:46 Q&A: Should we worry about AI-driven threats? 28:07 Closing titles Blockchain Week Bulgaria: https://www.blockchainweek.bg ETHSofia: https://www.ethsofia.com Future Finance Forum: https://www.blockchainweek.bg/f3 Follow Blockchain Week Bulgaria X: https://x.com/BWBulgaria LinkedIn: https://www.linkedin.com/company/blockchain-week-bulgaria Follow ETHSofia X: https://x.com/EthSofiaBG LinkedIn: https://www.linkedin.com/company/ethsofia Telegram: https://t.me/+b-33LJUpAB5iODNk Nothing in this video is financial advice. About the organiser Blockchain Week Bulgaria, ETHSofia and the Future Finance Forum are organised by the Bithope Foundation, founded in 2014 by Vladislav Dramaliev. Inspired by Andreas Antonopoulos, it is Europe's first non-profit operating exclusively with bitcoin donations. Over more than ten years, it has supported 50+ charitable campaigns, and in January 2016 it co-founded the Sofia Crypto Meetup, now the region's longest-running monthly crypto event. https://bithope.org
Transcript
[music]
Good to be here. Let's talk about security in the AI age. Um many things have changed since last year. It has been a turbulent year in web three security. Um we have a lot really to talk about when it comes to security in the AI age.
So um what is really worth working on right now? Because now we do not have so much activity when it comes to contests, which was usually the way that people got on boarded into web three security. It was the way that people got um a permissionless way to start and really to build a career out of it. So many people were making uh $10,000, $20,000, even more per security contest, and now we do not have this. Um this year we had layoffs in some big companies.
Um now we have some good news. We had uh one of the biggest companies when it comes to security audits, Open Zeppelin, be being acquired by a very serious company, uh S&P Global. And from what I heard, they'll be hiring a lot, so there'll be full-time opportunities there. Uh which is good for everybody, good for the growth of the space. Still, if you are an individual contributor, right now it's hard.
You don't have too many opportunities. Um but here is what is working right now. Here is a tweet I posted about a great security researchers, one of the most elite security researchers right now, Vivek 0xVivek. We work with him at Porsha for the group. And uh he has gotten paid over $300,000 in the past 3 months.
Um which in this state of the space is almost insane. Many people are saying there are absolutely no opportunities, the space is in a bad state, but this is absolutely incorrect. You're just looking at the wrong places if this is if this is your mindset. Bug bounties are the place where all individuals can go in and in a permissionless way they can contribute to the space and they can get paid. Yes, it's hard as everything else that is valuable, of course.
And you get ghosted by clients, by developers, even by the platforms themselves. Uh they'll be slow to respond. You do responsible disclosures when you speak to to developers directly, which will get ignored. But still if you keep going, you'll make it. We have seen this with so many people.
There are people in this room that have gotten paid great bounties in five figures or six figures worth of US dollars just for finding a single vulnerability. So it's really worth it. As I said here, when others are lazy, do the work. Right now, lots of people are kind of scared to work in web 3 security. This is the right time to push.
I'm certain because uh the demand is still there. Every company, every web 3 company badly needs cybersecurity services. They need great white hat hackers to work for them and to really protect them from the bad guys, from the black hats. And it has been working from what I'm seeing. The space has matured a lot.
Now all companies and all white hats are using AI in their own workflows. Uh we'll get to this a little bit later, but the space has matured so much that a lot of whole sets of attack vectors are now non-existent. You can very hardly find them find these types of vulnerabilities on an audit or even on an on a live contract. Which is great. Again, the space is maturing.
Still, there are a ton a ton of vulnerabilities um in contracts that have been audited. And this is proven exactly by this. This is proven by all of these payouts in bug bounties. So, code that has already been audited still can be vulnerable vulnerable. And the bug bounty part is where you come in.
This is the way to work permissionlessly. Nobody has to approve you. Nobody has to allow you. You just go in. You just open your laptop what wherever you are.
You look for vulnerabilities. And if you can find them find them, which happens through uh your learning, your studying, your practice, you will be getting paid. You can make a great living. And as you see, some people are doing a great living. This guy um his 2026 earnings are now over $1.
4 million, which is insane for even not the full year has passed. So, definitely this should be a good motivation for you to keep going. Keep going with bug bounties is the right thing to do. Also, of course, with Pessimistic Group, we have good opportunities. We work with people who are um very uh very experienced, of course.
But we also have opportunities for people who have just found a few um bug bounties, who have proven themselves already, but just a little bit. So, feel free to reach out to on Twitter to Tsvetanov. You can find him very easily. He is our head of auditors. He'll take care of you.
He'll give you some great advice. Now, so far we we discussed about individual contributors. As individual contributors, you can either go to bug bounties, which I think a good amount of your time should go to. You can build your own toolings, of course. You can also work with companies such as Pessimistic Audit Group.
There is Zenit Bell Sec. There is Sherlock. There are a lot of companies that work with freelancers. Um this is another opportunity that that you can take, but you usually need some kind of experience, some kind of a portfolio. Uh so if you do not have this, you go on Immunify or on HackenProof to do some bug bounties.
And um now as I mentioned, there can be the third option with a full-time opportunity, where again, it should be from what I heard, OpenZeppelin will be hiring. So, that's a great opportunity. OpenZeppelin are good good company to work for. Now, if you do not want to just work for someone else, maybe you want to build your own thing, maybe you have some special type of idea, you want to contribute to the space in your own unique way, what are the options? Here is something very cool I have seen.
This is actually of an auditor of ours, of Pessimistic Audit Group, who looks like he's starting his own thing with another colleague of his. I decided to put this in the in my talk here because it's a very very cool idea. It's different from what I see. Um their mindset was okay with AI, now vulnerabilities are cheap. Everybody can find a lot of vulnerabilities.
But how can you maximize your rewards? How can you know that you will get paid well? Um how to maximize your chances? Now of course with bug bounty as we said, you can get paid well but not always. Maybe if you submit 10 vulnerabilities, maybe um just a few of them will be valid.
Just a few of them will get a payout. Still, if you go to the sources where there is the most amount of liquidity, the most amount of um the there should be the the biggest payouts should be exactly in the places where you can have the biggest amounts of liquidity. So, the Bitcoin ecosystem, this is the place right now. Because you know Bitcoin has a lot more than a trillion dollars worth of volume in in in US dollars, which is huge. Now, this is where you should be focused in right now if you want to build something.
This is a great niche to attack. Just the place of Bitcoin security. If you focus only on this niche, um you have you carve out your own space, which is the way to start. You shouldn't start you should start more narrow. Um you should have an exact specific spot to attack.
I say the Bitcoin ecosystem and especially now the layer tools which are related to Bitcoin, the DeFi applications which are related to Bitcoin, they're a great place to go. Um many venture capital companies uh are really focused right now on Bitcoin BTC 5. This is a good place to be at. Make sure to focus there. Of course, there are many other opportunities.
Try to be creative, get your own ideas. My advice here is really to go niche. Go niche, choose something more specific. Do not go Do not go very broad. Maybe start with some specific type of technology.
Um again, Bitcoin is a good one. But yes, do not go Do not go broad, go narrow. And of course, to be growing, you have to be learning. You have to be studying. Um now with AI, so many things have changed.
So many things have happened. Uh we have skills. We have every company building their own tooling. We have every individual building his own tooling. So, a lot of things are happening, a lot of moving parts.
Which are the good ones? Here are some of some things that I have shared. Again, some Twitter screenshots. Um Assen Sek, my colleague Assen, uh who is building our own AI solution at Pasha Folic Group, he has started writing some great blog posts about how to create your own AI agent, which every individual security researcher really should be doing. You should be experts with your own um AI solution.
Uh and it should be finding the vulnerabilities for you. Vulnerability discovery is really very well done by AI agents at this age. Um so, really 80% of this work should be done by your agents. Now, how to start with this? Go to this blog post.
You can find this on Twitter. Um really, you can learn about how to build your first agent. This is a series of blog posts. You'll be reading There are two already out. There will be a few more.
You'll be learning how to add context to your agent, just how to start with it. You'll learn how to make it more deterministic because this is a problem of AI agents. The more times you run it two times and it will have different results. But now, if you add scripts, you can make it more deterministic. Of course, you should play around with this.
You should put a lot of time to toy with this stuff. Really play around, try different things. And Assem has a great guide on how to start. This is good for beginners. Also, yesterday we just announced the V4 of our Solidity Auditor skill, which really is part of Pashov's skills.
We have multiple other ones. We have three skills. We have a fuzzing solution, threat modeling solution, and just an auditing solution for Solidity code. Um we have seen thousands and thousands of developers and security researchers use this. We've had security researchers who have gotten paid um like $5,000 or even more by finding a vulnerability by just running Solidity Auditor on a code base and reporting it.
So, it works. It delivers on its promise. It's free. You can run it with just your cloud subscription or with your ChatGPT subscription. Um and now we just uh deployed our latest version, the V4, which is different in the way that it has looping mechanism.
It has some memory ledger, which remembers every previous run. Um it remembers the findings from it and it builds on top of it. It iterates. So, right now, as you can see on the screenshot, it has delivered 85% of recall um, on a security contest just exactly a year ago from a year ago. This contest run uh, this contest run on September 2025.
There were 13 high severity vulnerabilities. Um, and it was a very big contest. There were big rewards, a thousand a hundred thousand dollars of um, pool of rewards to really spread around the security researchers who participated. The top auditor I think got him paid maybe around $30,000 and it was mainly because he found so many high severity vulnerabilities. Now, Pashov skills or Solidity auditor finds in a single run 11 out of these 13 vulnerabilities in just less than an hour.
This used to take weeks. And actually, if you go to this contact contest, you'll see that the top auditor, the top performing auditor, he did not have 11 high severity vulnerabilities of himself. Which shows that with just a simple skill, you can have better performance than top tier elite security researcher from just a year ago. Which is insane. Again, you have to do the triage.
You have to understand which findings are valid, which are not, what severities they are. But if you have the basic knowledge in web three security, you should do this very well. And in no time, in let's say a a day of work, running the skill, triaging the findings, you get the same results that um a very senior auditor used to get a year ago. Pretty much the same. But some findings will be better, some findings will be worse, but overall it's better.
Just think about it for a second. A year has passed by, and what used to cost for companies tens of thousands of dollars, now it's it's pretty much free. It's just a skill that you clone from GitHub, and you run it for an hour, you get all these findings. So, what you should do, make sure to clone our skills, make sure to play around with them, fork them, build your own, build your own solution, build on top of them. This is what many many many individual security researchers are doing.
We have a Discord community. You can join us from our website, and you can talk to other security researchers who have done it successfully, and who have started gotten getting paid in bug bounty platforms just by using the skill. This is a good strategy to start with learning. Uh there will be a lot of innovation in the space happening. There is There are new tools coming out every day.
We have a lot of skills to come as well. We have our own open source contributor 0xFirefist. Make sure you follow him on X. He's great. He has contributed to uh X-Ray to Fist, to Solidity Auditor, all of our skills.
Um and he'll be building a lot more. There is a lot more coming. For you, the best strategy as security researchers is really to take advantage of all of this open source technology, build your own stuff on top of them. And really bug bounties are the place to be in right now. This is what I'm seeing.
You can build your own portfolio there in a permissionless way. You really do not need anybody to approve you. You just need the protocols to accept the findings, but if if your findings are truly valid, with no time you have built a great portfolio. After that, you can go work for a company such as Pashov Audit Group as a freelancer or as a full-time employee at some company such as Open Zeppelin. And of course, you can always continue with the bug bounties.
This is always working, always happening. As you saw, a security researcher has gotten paid $320,000 over this in 3 months, which is insane. Making $100,000 per month is not bad. It's okay. So, um again, we're not day one of AI in Web3 security.
Uh this has started last summer. Uh so, this is already ongoing. I'm certain that you have played around with some technology. And really many people um have had doubts. They have thought they will they will their job will get automated or something, that they will be useless.
This is incorrect. If you continue If you continue studying, if you make use of all of these new technology, you be the guy who actually um take over your own position from before, and you will be at the frontier. You will be using the latest and greatest technology. People will be asking you questions, people will learning from you. So, while others right now are very fearful, while they are lazy, make sure you're working very hard, as hard as possible right now.
Take advantage of this. Uh so, you can be forward, be in front of others. And really, now is the right time to lock in. Right now. If you put in the effort now, the demand is rising again for the security services, the market is picking back up.
Better times are coming. And if you lock in right now, you will reap the rewards very soon. I'm certain of this. That's pretty much it. Thank you so much.
[applause]
Uh we can have some minutes to take questions.
Okay.
[laughter]
Maybe you want to choose a few questions.
Um you can go. You can go.
Okay, sure. Um So, let's start with this one. Which parts of smart contract security do you think artificial intelligence will eventually automate well, and which parts will still require human judgment?
I think none will fully automate, but um the work is getting very different. What we need now, I think where your focus should be really is in building tooling, because tooling can really automate so much of your work. But again, you need the expertise. It It's not just enough to know how to build with AI, to be a great engineer, to know how to build a system. You need your 10% in the beginning to give the right directions to the AI.
Um of course, to build it you need to really run your AI when it comes to a security engagement, when it comes to an audit, or maybe formal verification, or fuzzing. There will be a lot of great tools and solutions built there. Um and the tools will be doing most of the work, like 80% of the work. But again, in the end, in the beginning, and in the end, you will have like 10% 10% in the beginning, 10% in the end. So, this work will actually make a huge difference.
Um amount-wise, it won't be a lot. Effort-wise, it won't be a lot. But um the results will be very different depending on your knowledge and expertise. So, build your expertise and let the robots do the work. Let the robots do the work.
Use your expertise.
And then we have the next question. How is your daily job evolving with artificial intelligence? Because regular non-security developers are sometimes burned out turning it into bot managers instead of code coder. So
Is it's about my job the question?
Yes, please.
[laughter]
The mic.
They're not doing what they used to like, you know, thinking about how do I debug this or
So, are we talking are we speaking for developers?
So, so it's just uh I heard that from developers, non-security developers, that essentially they turn into those bot managers and they don't like their job so much. But from how you speak about AI, you you sound very energetic and enthusiastic about it. So, it doesn't sound like your day-to-day has turned into something you don't like so much. Yeah. Uh so, like yeah, if you can give some perspective on that.
Yeah, the job has changed. Really, what this what I want to uh I wanted to mention very briefly. While so many things have changed, almost nothing has changed as well because the end result is the same. With security, you want to find a lot of vulnerabilities. You want your clients to feel secure, to be more confident.
With development, you want to build a great system, you want to build a great product. You need a front end so the clients can see it or whatever, depending on what you're building. You have the same goals, but you do them differently. So, really you have to calibrate. The old times are not coming back.
This is 100% guaranteed. So, really you have to calibrate, you have to adapt. That's the only solution. Just do it. It's okay.
The results should be the same and you get your customers or your users or your employees very happy if you deliver. This should be the goal.
So, like no ego in the equation. Doesn't matter if it's a bot or you finding the the the critical as long as the critical is found. Kind of mindset, right?
Of course, this doesn't matter at all because you still need to polish it a little bit, you need to validate it. And what matters is finding the vulnerability before the black hats. So, it's even better if the AI bot finds it. It's faster. It scales more, so it's a good good thing.
Thank you.
Thank you. And we have one great question. What made you start that business in that specific niche?
Okay, so I was doing I was a developer. I was a software engineer in a crypto startup and we got in an audit from a big company and I thought, "Oh my god, this is so expensive, it's so inefficient. We did not get too many people working on this. We actually got in like two people, two security researchers were auditing my code that I wrote and I think one was senior, one was not even that senior." So, it was like this can be done so much better.
I saw the opportunity. We had all of these contests back then with Coderina and we had so many financial opportunities. Like you join a contest, you don't even have so much experience like you have just tried to hunt for vulnerabilities for like just a few weeks and you're already making thousands of dollars. So, this is what hooked me in the beginning. Of course, the financial opportunity.
And then I started meeting other hackers. We built this nice community on Twitter, on Discord, on Telegram. We have good communities and I just got sucked into it really and now this has been every day for the past 4 years. It has been day and night web three security. So, it's a great opportunity.
There is not too much competition. Still not many people believe this, but actually this will be growing so so much. So, the timing right now is great. I can tell you this.
And we have a few people here who have similar questions and that is on how do you make money? So, is that from using your your program or by taking a small percentage from your users?
So, is
Or something different?
Yes, is the question about how we make money or how they should make money?
How you make money?
How we make money? How we make money? So, our company Pashov Group is really focused on only one thing and it's audit security audits. Basically, we love code. We play with code.
We audit it. We find the vulnerabilities with it. This is our work. So, we every company in web three, they have technical products, every technical company. They basically give us access to their code and we start reviewing it both manually, both with automated tooling.
And we go very deep to find the vulnerabilities before they reach deployment time, before they reach production. So, this is what we do. We sell security audits. We hire security researchers and we we sell them to clients. This is our service.
And the last question, Um, should we be concerned about the tool advancement that's threatening payment securities?
Sorry, can you come again? Yes.
Shall we be concerned about the artificial intelligence advancement that's threatening payments securities?
Should we be worried? Now, if you ask a cybersecurity founder, he will always say yes, you should be very worried. And it's true, like there are so many exploits every day. I don't know if there is a day without an exploit in our ecosystem, and it's usually because of bad security practices. If you keep your good security practices, if you go through audits, if you make sure you invest into this and handle your operational security, train your employees, you will be in a much better spot.
So, of course, the threats are the same as always. There are many, many threats. But, if you work with the smart people, if you have the right team members or the right external experts, you should be in a very good position. So, as always, take care of your security. Nothing has changed.
You should always do this.
Thank you so much. We have more questions for Chrome, but we don't have time, unfortunately. But, I'm sure that you can find Chrome and chat with him.
[music]
Automatic transcript — names and jargon may be misspelled.