Why these projects have dev teams if dev teams are not using these models on their own code? And I do not mean that as disrespect.
The quantum computing angle, however. In March,
Google released a paper that claimed one had to install less than 500,000 physical qubits to break ECC. Previous estimates were in the millions. It is not quite there yet, but the distance is closing and. Despite NIST finalizing the standards in 2024, not many chains have actually made the switch to post-quantum cryptography.
So we have AI finding bugs that humans cannot find. And quantum computing on the verge of cracking the cryptography system that everything is based on. And most projects are taking no action on either.
Your two ideas at the end are pretty much correct. AI-enhanced auditing must be an ongoing process, not a tick-the-box exercise. The old way of paying CertiK or anyone else one time and sleeping tight at night? That is gone. Zcash just proved that it is gone.
And the less funded altcoins, the smaller team, the less eyes on the code? Yeah. I just do not want to think about what is written in those contracts these days.