Formal verification is no longer optional

Formal verification is no longer optional.

Vitalik Buterin. Morpho. The White House. DARPA. The AMF.

Five independent voices. One conclusion: formal verification is essential to software and blockchain security. Every quote below is dated, sourced, and linked to the original document.

On the record

Ethereum
Vitalik Buterin

The genius behind Ethereum

$200B+ market cap. 1M+ daily transactions. ~12,000 monthly active developers.

Vitalik Buterin is arguably the most emblematic mind in blockchain.

So when he states formal verification of everything for security, he is not simply endorsing a technology.

He is defining the security standard for Ethereum.

Vitalik Buterin

Co-founder of Ethereum

The post that says it plainly
Vitalik Buterin @VitalikButerin
  • Formal verification of everything for security.
  • FV also makes us much more comfortable with canonicalization (having pieces of the protocol that are directly defined as a piece of bytecode expressed in some language). evm-asm is being written in part to become a canonical proof system for the EVM.
The manifesto

A shallow dive into formal verification

Vitalik Buterin · 18 May 2026 · vitalik.eth.limo

“Bugs in computer code become more scary when you put cryptocurrency into immutable onchain smart contracts from which North Korea can automatically drain all your money with no recourse if there’s a bug in the code.”
Vitalik Buterin @VitalikButerin

One application of AI that I am excited about is AI-assisted formal verification of code and bug finding. Right now ethereum's biggest technical risk probably is bugs in code, and anything that could significantly change the game on that would be amazing.

Vitalik Buterin @VitalikButerin

Many people have claimed that with AI-assisted bug finding, secure code (and hence trustless anything) will be impossible. I have a much more optimistic take, and AI-assisted formal verification is a major part of the reason why: vitalik.eth.limo/general/2026/05/18/fv.html

If you formally verify end-to-end, then you are proving not just that some description of the protocol is secure in theory, but that the specific piece of code that the user runs is secure in practice.
18 May 2026A shallow dive into formal verification Web source
Formal verification is not a panacea. But it is particularly well-suited for situations where the goal is much simpler than the implementation.
18 May 2026A shallow dive into formal verification Web source
If done right, this has potential to both output extremely efficient code, and be far more secure than the way programming has been done before.
18 May 2026 · On AI-assisted proofA shallow dive into formal verification Web source
Morpho

The rising star of DeFi

$11B+ in deposits. $175M raised. Coinbase, Kraken, Binance, Galaxy and Anchorage among its institutional integrations.

Morpho is building what is set to become the world's leading infrastructure for automated onchain finance.

Formal verification uses mathematical methods to prove that a smart contract satisfies certain properties for every possible input, not just the ones a tester thinks to try.
9 July 2026Securing Morpho Midnight Web sourceVerification register
At Morpho, ownership of formal verification is internal. The engineers designing and developing the protocol also work on formal verification, ensuring that they have all the required context.
9 July 2026Securing Morpho Midnight Web source
All Morpho smart contracts are immutable and non-upgradable. Once deployed, no one can upgrade, pause, or alter them.
9 July 2026 · Why proof, not patchesSecuring Morpho Midnight Web source
The White House & DARPA

The highest authorities in cybersecurity

The White House and DARPA: the U.S. presidency and the agency behind the foundations of the internet.

Their conclusion is unequivocal: in the age of AI-driven attacks, testing is not enough. Critical software requires formal verification.

The White House

Office of the National Cyber Director, Executive Office of the President of the United States

Cover of Back to the Building Blocks: A Path Toward Secure and Measurable Software

Back to the Building Blocks: A Path Toward Secure and Measurable Software

Office of the National Cyber Director, The White House · February 2024. Part II of the report devotes a dedicated section to Formal Methods (page 10).

While formal methods have been studied for decades, their deployment remains limited; further innovation in approaches to make formal methods widely accessible is vital to accelerate broad adoption.
26 February 2024Back to the Building Blocks · Part II, “Formal Methods”, p. 10 Web sourcePDF
Given the complexities of code, testing is a necessary but insufficient step in the development process to fully reduce vulnerabilities at scale. If correctness is defined as the ability of a piece of software to meet a specific security requirement, then it is possible to demonstrate correctness using mathematical techniques called formal methods.
26 February 2024Back to the Building Blocks · Part II, “Formal Methods”, p. 10 Web sourcePDF
They allow for proving the presence of an affirmative requirement, rather than testing for the absence of a negative condition.
26 February 2024 · On formal methodsBack to the Building Blocks · p. 10 PDF
As questions arise about the safety or trustworthiness of a new software product, formal methods can accelerate market adoption in ways that traditional software testing methods cannot.
26 February 2024Back to the Building Blocks · p. 10 PDF
With formal methods, we can generate a mathematical proof that offers that level of assurance, giving technology developers another powerful capability in their arsenal that provides greater certainty that entire classes of vulnerabilities are absent.
7 November 2024 · Anjana Rajan, Assistant National Cyber DirectorReadout: ONCD Participates in Formal Methods Conference at the University of Cambridge Web source

DARPA

Defense Advanced Research Projects Agency, U.S. Department of Defense

Active DARPA programme

expMath Exponentiating Mathematics

Information Processing Techniques Office · darpa.mil

“In theory, formalization in programming languages, such as Lean, could help automate proofs, but translation from math to code and back remains exceedingly difficult.”
Program manager
Patrick Shafto
Kickoff
March 2025, Arlington, Virginia
Convened
More than 130 attendees, including Fields medalists, Turing Award winners, and experts in mathematics and AI
Stated goal
To “radically accelerate the rate of progress” in pure mathematics by developing an AI co-author capable of proposing and proving useful abstractions
Nothing works better than formal methods when it comes to cyber-hardening. Like other engineering disciplines, using a mathematically based development process to create proof that software does what it is supposed to and does not do what it is not supposed to implies someone cannot hack it.
April 2025Revolutionizing Cyber Resiliency for Military Systems · DARPA portfolio DARPA portfolio (PDF)Formal Methods
Rather than validate the security of software code solely by testing it after it’s already written, formal methods’ mathematically based software development approach designs software through rigorous mathematical analysis, verifying its performance before and as it’s being built.
Read August 2026Formal Methods · DARPA research spotlight Web source
The growing role of DOD software in warfighting, in the protection of national assets, and the safeguarding of human lives creates a diminishing tolerance for faulty assurance judgments.
27 March 2023 · William Martin, PROVERS Program ManagerShow Us the Proof: Formal Methods Can Be Applied at Large Scale Web source
The formal method-generated code foiled all Red Team attempts to crack the Little Bird’s defenses. […] To this day, the system has yet to be successfully hacked.
HACMS case study · Red team vs. a formally verified autonomous helicopterHigh-Assurance Cyber Military Systems · DARPA Web source
AMF & ACPR

The financial regulators

Under the aegis of the AMF and ACPR, a working group bringing together auditors, scientists, banks, protocols and Dowsers examined how smart contracts should be certified as onchain finance scales under MiCA.

The conclusion was clear: formal verification offers, by far, the greatest level of assurance, with the strongest potential to scale.

AMF & ACPR

The AMF and ACPR are France’s main financial regulators, with the ACPR operating under the aegis of the Banque de France while the AMF is an independent public authority.

Cover of Forum Fintech ACPR-AMF: Report of the Working group on Smart Contract Certification

Forum Fintech ACPR-AMF: Report of the Working group on Smart Contract Certification

Joint working group of the ACPR and the AMF, set up January 2024, published 3 February 2025. Section 3 examines formal verification methods in detail (pages 29-31).

Compared with static or dynamic analyses, formal verification is much more ambitious: it aims at demonstrating compliance with the specifications in a logical-mathematical sense.
3 February 2025 · ACPR-AMF Fintech ForumReport of the Working group on Smart Contract Certification · p. 29 Web sourcePDF
The potential of formal verification methods lies in their capacity to be automated, which in theory can allow for unrestricted scaling.
3 February 2025Report of the Working group on Smart Contract Certification · p. 29 PDF
Formal verification methods, on the other hand, are ideal for assessing whether the smart contract code satisfies the “compliance principles”, and in particular for checking that the program actually performs the expected operations.
3 February 2025Report of the Working group on Smart Contract Certification · p. 31 PDF
Formal methods have so far been mainly used for developing algorithms in critical areas, involving the safety of people, such as the transport or nuclear industry.
3 February 2025Report of the Working group on Smart Contract Certification · p. 30, footnote 62 PDF
Certification would be obtained following an auditing process performed by a human expert, or using formal methods or a combination of these methods.
3 April 2023 · §3-2-2, Certifying the computer code used in DeFi applications« Decentralised » or « disintermediated » finance: what regulatory response? · ACPR Web sourcePDF
Dowsers

They set the standard.
Dowsers turns it into reality.

Dowsers brings formal verification, the mathematical technology trusted in nuclear, space, railway and aeronautics engineering, to smart contracts and blockchain infrastructure.

Code Maths is law

Dowsers

Dowsers®. Formal verification for blockchain. Maths is law.

Every quotation on this page is reproduced verbatim from the source document linked beside it, for the purpose of accurate reference and comment. No quotation constitutes an endorsement of Dowsers, and none of the people or organisations quoted has reviewed or approved this page. Dowsers took part in the ACPR-AMF Fintech Forum working group on smart contract certification; apart from that, no organisation quoted here is affiliated with Dowsers. Names and logos are the property of their respective owners.

The AMF-ACPR working group report states that it "does not constitute a proposal for a regulatory framework or an official position of the ACPR, the AMF or any other authority that participated in the working group."

Compiled 11 August 2026.