Gno.land launches Dora to auto-prove blockchain exploits
Gno.land said Tuesday it has launched Dora, an autonomous AI security harness that audits its codebase and smart contracts by reproducing exploits on a live node before a human reviews the finding. The move is meant to shift blockchain security from suspicious bug reports to verified, patched vulnerabilities.
Why it matters: - Dora is designed to turn blockchain security findings into confirmed exploits, not just alerts. - That matters on-chain because a single panic, nondeterministic behavior or overflow can affect consensus or move funds. - Gno.land is betting that AI-assisted attackers require AI-assisted defenses that can prove a bug before a vulnerability reaches the wider public.
What happened: - Gno.land, a Go-based smart contract platform developed by NewTendermint, announced Dora on August 19, 2026. - Dora is an autonomous AI agentic harness that continuously audits the Gno.land codebase and its smart contracts, called realms. - Dora reproduces each exploit against a live Gno.land node before a human sees the finding. - Gno.land framed Dora as part of a broader move toward applying agentic AI directly to blockchain security.
The details: - Dora runs findings through seven agents: recon, planner, deduplicator, verifier, reviewer, fixer and fix reviewer. - The recon agent maps the codebase. - The planner proposes candidate bugs. - The deduplicator removes issues already known. - The verifier writes and runs a live test against a real Gno.land node. - The reviewer checks the result adversarially. - The fixer drafts a patch. - The fix reviewer confirms the patch holds. - Only findings that survive every stage reach a human, already reproduced and patched. - Jae Kwon, CEO at NewTendermint, said Dora gives Gno.land a way to think like an attacker and that each finding has already been proven and patched before it is surfaced. - Gno.land said the current threat landscape has changed because bug bounty submissions increasingly use AI assistance, making suspicion cheap but proof still difficult. - The company also said attacker-supplied code running on-chain raises the cost of missed vulnerabilities.
Between the lines: - Dora is not just a scanner. It is built to narrow the gap between detection and remediation. - The emphasis on live-node reproduction suggests Gno.land wants to reduce false positives and focus human review on issues that already behave like real exploits. - Gno.land is also signaling that its architecture is meant to fit AI-led development and auditing, not just AI-assisted coding. - The company recently released gnomcp, an open-source server that connects AI coding agents such as Claude Code and Cursor directly to Gno.land so agents can read, write and deploy realms. - Gno.land said its use of plain, human-readable Go and fully deterministic smart contracts makes the platform more suitable for AI-mediated development and review.
What's next: - Dora remains an internal tool for now. - Gno.land has not completed a full sweep of the codebase. - Targeted runs so far have produced reproducible findings with low noise, the company said. - Broader coverage is planned, and Gno.land said it will publish results as Dora expands.
The bottom line: - Gno.land is trying to move blockchain security from periodic audits and post-hoc bug reports to continuous, machine-verified exploit reproduction and patching.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Blockchain News Online
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.