On September 11, in San Francisco, Jensen Huang told an audience that cybersecurity is set to become AI's next major market. The line that traveled fastest was the sardonic one: "What creates demand better than creating a problem?" Read as a quip, it is a throwaway. Read as a pricing model, it is exact — and the market has transcribed the wrong implication. The consensus takeaway is an AI-software story: models write code, models find bugs, and a new SaaS layer absorbs enterprise security budgets. The second-order story is narrower and considerably more investable. It concerns the widening gap between how fast code can now be produced and how fast it can be verified — and there is one asset class where that gap settles in real time, at block finality, with no rollback and no counterparty to sue. That asset class is not an AI market. It is crypto.
What Huang actually described, stripped of keynote cadence, is a supply-side shock. Automated programming raises code throughput per engineer by an order of magnitude and lowers deployment latency across every software vertical. By symmetry it also lowers the cost of producing an exploit. Those two effects are not equal, and the asymmetry is the entire trade. In conventional software a vulnerability is an incident: a patch, a postmortem, a disclosure window measured in weeks. In on-chain systems a vulnerability is a settlement. Immutability is not a toggle that can be flipped off when the code is wrong; it is the property that makes the ledger worth holding at all. Rollback is a governance vote and a legitimacy cost. There is no chargeback layer, no indemnity, and no discovery process that recovers user funds once finality is reached.

The scope matters. Bridges, lending markets, oracle feeds, stablecoin reserve attestations, staking derivatives, token contracts — each is a state machine holding bearer instruments, and each is now being authored, patched, and shipped with tooling that has undergone a step change in capability. Historically, security was priced as an operating expense: budgeted annually, reviewed after an incident, and modeled on the assumption that the attack surface changed slowly. That assumption no longer holds. The rate of change of the attack surface is now a function of generative throughput, and generative throughput is the one input in the stack currently enjoying a step-function decline in cost.
Start with the mechanism rather than the mood. The economically relevant quantity in security is not the number of vulnerabilities; it is the width of the window between exploit discovery and patch deployment, multiplied by the value at risk inside that window. A zero-day behaves like an asset with a term structure. Its value approximates the discounted cash flow of the exploit over the interval before remediation or disclosure kills it. AI compresses both ends of that interval. The problem is that the attacker's end compresses faster, because the attacker optimizes a single objective function with no change-management process, while the defender must coordinate patches across audited contracts, multisig signers, governance timelocks, and increasingly, regulated disclosure obligations. One side ships; the other negotiates.
We can observe this in the only genuine market for vulnerabilities that crypto operates: bug bounties. Payout schedules are, functionally, a price signal on the marginal cost of finding a class of bug. When critical-severity payouts for logic errors sit below the expected value of holding the same finding privately — and in a bull market, with total value locked elevated, they demonstrably do — the rational move is not to report. That is not a moral failing. It is an arbitrage, and arbitrage is precisely the activity automation performs best.
Here the real constraint becomes visible. Audit capacity is inelastic. Human review hours do not follow a Moore's Law curve, and the number of people who can competently evaluate a novel AMM invariant or a cross-domain message-passing implementation is small, poorly distributed, and already fully allocated. Formal verification helps, but only against properties you can state — and the failures that actually drain treasuries are rarely violations of stated invariants. In 2020, when I built the DeFi Liquidity Multiplier to quantify how impermanent-loss hedging was synthesizing a hidden leverage layer across Aave and Uniswap, the finding was not a bug in either protocol. Both were correct. The risk lived in the composition. The residual attack surface in mature crypto is compositional and economic, not syntactic — and composition is exactly the layer that neither a linter nor a language model reasons about reliably.
Now place that in the current regime. Security expenditure is procyclical. In a bull market, treasuries fill, teams ship faster, incentives attract deposits, and the ratio of audit spend to value locked compresses — not through negligence, but through arithmetic. TVL can triple in a quarter; the verification pipeline cannot. Liquidity is the pulse; policy is the brain — and neither is currently steering capital toward verification. The vulnerability backlog is being accumulated right now, in the most expensive quarter of the cycle in which to accumulate it. When the regime turns and liquidity thins, that backlog does not evaporate. It matures.
The surface also extends below the application layer, where security is not purely cryptographic but operational and jurisdictional. Since the fourth halving, revenue per unit of hashrate has compressed enough that only well-capitalized, geographically concentrated operators remain economic, and hash power has drifted toward a handful of pools. A majority-hashrate cluster is not an attack that requires malice; it is a coordination dependency that prices identically to a custody risk. The decentralization argument, in other words, has migrated from a consensus property to a compliance property — and compliance properties are what regulators believe, not what the code enforces.
Europe's MiCA framework produces a comparable asymmetry on the fiat rail. Reserve requirements and CASP obligations are fixed costs, and fixed costs are regressive. A large issuer absorbs continuous attestation and monitoring the way it absorbs legal fees; a small one cannot, and will by construction ship thinner verification, fewer monitoring hooks, and less incident-response capacity. Consolidation is not a side effect of regulation; it is the intended transmission mechanism. Which means the tail risk of the next cycle will not sit with the issuers who can afford to be audited. It will sit one layer down, with the integrators nobody is watching.
The same reasoning applies to the identity and attestation layers that venture capital keeps funding. Three years of soulbound-token advocacy have produced remarkably little voluntary adoption, for an unglamorous reason: a permanent, portable credit record is a liability to the person holding it. If adoption arrives instead by mandate — through travel rules, attestation requirements, or institutional onboarding — the resulting registries become concentrated, queryable, and high-value. Which is to say, a honeypot with a compliance department.
The prevailing interpretation of Huang's remark is defensive: security AI will outpace offensive AI because defenders hold more telemetry, more capital, and the incumbent position. I find that thesis fragile. Defenders operate under constraints that scale badly — liability, change management, uptime requirements, disclosure timing, and the obligation to keep serving traffic while patching. Attackers optimize one variable. That is not a fair fight, and no amount of model quality corrects an asymmetry in the objective function. There is also the vendor's incentive to note: an executive selling compute has a structural interest in a threat environment that expands indefinitely, and the demand curve he describes — people lining up to buy — is evidence of a sales channel, not of a threat. This is the same reflex I applied when I mapped the BAYC secondary market with graph algorithms and found a majority of volume originating from a small, interlinked cluster of addresses. Value is a consensus, not a fundamental truth — and so, for that matter, is security. A chain is secure to the exact extent the market believes it is secure, and that belief is reflexive: it holds until the block that proves otherwise.
Finally, the blind spot that bulls and skeptics share. The largest realized losses in this sector have not been code exploits at all. They have been key compromise, social engineering, signer collusion, and governance capture. None of those are inference problems. A model that reads Solidity flawlessly will not stop a treasury manager from signing a malicious transaction, and it will not make a five-of-nine multisig more independent than it actually is. The industry is buying protection against the failure mode that is legible and underweighting the one that is common.
So watch the spread, not the headline. The tradeable variable is the divergence between deployment velocity and verification throughput, and the position that expresses it is not generative AI, nor the tokens that merely point at it. It is verification, attestation, monitoring, and insurance — the unglamorous layer that gets paid when everything else is wrong. Exploit latency is a liquidity variable, not a security metric. When the marginal cost of writing a working exploit approaches zero, what exactly is the price of trust — and who, at present, is authorized to quote it?