The Year Finding and Exploiting Bugs Became Cheap, and What to Do About It AI-assisted bug finding and exploit development became cheap and practical toward the end of 2025, according to security researcher and ZKSecurity author, with the cost of finding and exploiting bugs falling exponentially while total losses have not been reduced and exploits of smaller projects are increasing exponentially. In 2026 the first two known exploits against live ZK circuits occurred: one was exploited by white hats to rescue roughly $1.5 million and the other was drained for 5 ETH, both rooted in Groth16 verifiers generated from trusted setups that had not been finalized correctly. The author's AI-assisted pipeline found real vulnerabilities in Cloudflare's CIRCL, OpenVM's zkVM, and Bron Labs's MPC library, and argues security strategy must combine testing, AI tools, manual reviews, and formal verification continuously rather than relying on one perfect audit. Over the past few years, nearly every security researcher I know has incorporated LLMs into their process. What began with chatbots quickly evolved into scripts calling model APIs, then agents, skills, custom harnesses, autoresearch loops, and more approaches than anyone can reasonably keep track of. Toward the end of 2025, something shifted. Models and the harness/systems around them became better, and AI-assisted bug finding and exploit development stopped feeling like an interesting experiment, but it became reality, while we start observing an increased amount of exploits