logo

Auditing with ChatGPT: Complementary But Incomplete

ID: 82804ab1-1819-5bdc-8ef5-26e608d4d7fd

STIX ID: report--82804ab1-1819-5bdc-8ef5-26e608d4d7fd

Feed Name: CertiK Blog

Threat Score
60/100

Date Published: 2023-02-13

Date Updated: 2026-06-11

...
...

This report compares ChatGPT's pre-audit output with a CertiK audit of ZKasino smart contracts, showing that ChatGPT missed critical project-specific vulnerabilities (notably a transfer-revert refund exploit in the Bankroll contract enabling consistent attacker wins and fund drainage), failed to detect randomness/math issues in games (VideoPoker, Dice), and overlooked input validation and accounting inconsistencies (Plinko, Slots). The authors conclude that while ChatGPT surfaces common concerns, it often provides only surface-level analysis and should be supplemented by experienced human auditors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.