Damn, I miss the early days of getting into Web3 security.
- Sleepless nights grinding through Solidity
- Reading the few blogs on how to become an auditor
- Security contests blowing up, everyone sharing wins on Twitter
- My first contests and how I was struggling to find a Low at least
- Reading everything I could just to understand how different protocols actually work
Looking back, that was the most interesting phase for me.
Now I see new auditors trying to outsource everything to AI before they’ve built any foundation.
They’re not even learning how to think anymore.
They’re not reading.
They copy-paste articles and ask AI to summarize them instead of understanding them.
That’s where it breaks.
They’re not using AI as a tool.
They’re using it as a replacement for themselves.
And that’s the problem.
You can’t shortcut understanding. You can’t skip the part where things don’t make sense and you struggle through them.
That’s the work you need to become better.
If you haven’t spent hundreds of hours reading code, breaking things, and actually thinking, AI won’t make you an auditor. It’ll just make you dependent and you will stay bad auditor.
Use it as an assistant. Not as a crutch.
There’s no way around paying the price.