CIO Influence
CIO Influence News Machine Learning Security

Gno.land Launches Dora, an Autonomous AI Security Harness for Blockchain Vulnerability Detection

Gno.land Launches Dora, an Autonomous AI Security Harness for Blockchain Vulnerability Detection

Gno.land | gno.land Documentation

Dora finds and reproduces exploits before a human sees the finding, moving blockchain security from bug reports to proven fixes.

Gno.land, a next-generation Go-based smart contract platform developed by NewTendermint, today announced Dora, an autonomous AI agentic harness that continually audits the Gno.land codebase and its smart contracts, known as realms. Dora does not report a vulnerability. It proves one, reproducing each exploit against a live node before a human sees the finding. The release positions Gno.land among a number of blockchain platforms applying agentic AI directly to their security, rather than relying solely on periodic audits or bug bounty submissions after the fact.

“AI is changing who finds vulnerabilities first, and we would rather it be us,” said Jae Kwon, CEO at NewTendermint. “Dora gives Gno.land a way to think like an attacker, not just when someone files a report. Every finding it surfaces has already been proven and patched, which is a different level of security than a list of suspicions.”

Also Read: CIO Influence Interview with Hugo Dozois-Caouette, CTO and Co-founder at MaintainX

An Answer to a Changing Threat Landscape

Bug bounty submissions industrywide are increasingly written with AI assistance. Finding suspicious code has become c****. Confirming a suspicion is a real, exploitable bug has not, and attackers now have access to the same inexpensive tooling as defenders.

The margin for error is thin on a platform where attacker-supplied code runs on-chain. A single panic in the wrong place can halt consensus. Nondeterminism can split validators, and an overflow can move funds. Gno.land built Dora to close that gap by finding and proving exploits before anyone outside the company does.

How Dora Works

Dora processes each finding through seven purpose-built agents. A recon agent maps the codebase, a planner proposes candidate bugs, and a deduplicator filters out anything already known. A verifier then writes and runs a live test against a real Gno.land node. A reviewer adversarially checks that result before a fixer drafts a patch and a fix reviewer confirms it holds. Only a finding that survives every stage reaches a human, already reproduced and patched.

Part of a Broader AI Push

Dora extends a wider effort at Gno.land to build with and for AI. The platform recently released gnomcp, an open-source server connecting AI coding agents such as Claude Code and Cursor directly to Gno.land, letting agents read, write, and deploy realms using the same tools adopted across the industry. Because Gno.land smart contracts are published as plain, human-readable Go rather than bytecode, Gno.land has positioned its architecture as inherently suited to a development process increasingly mediated by AI agents, from writing code to auditing it.

Where Dora Stands Today

Dora remains an internal tool. Gno.land has not completed a full sweep of the codebase, but targeted runs to date have produced reproducible findings with low noise. Broader coverage is planned, with results published as it expands.

Catch more CIO Insights: What Does “Job-Ready” Really Mean in IT and Cybersecurity?

[To share your insights with us, please write to psen@itechseries.com ]

Related posts

Orca Systems Announces World’s First Fully Integrated SoC Solution for Direct-to-Satellite IoT Connectivity

CIO Influence News Desk

SuperGreen Solutions Integrates State of The Art Software That Gives Homeowners A Quick Solar Estimate That Can Help Them Reduce Their Electricity Bills

CIO Influence News Desk

GRIMM Private Vulnerability Disclosure Program Reveals Netgear SOHO Devices Vulnerability

CIO Influence News Desk