Trail of Bits

4.2K posts

Trail of Bits banner
Trail of Bits

Trail of Bits

@trailofbits

We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.

New York, NY Katılım Mart 2010
256 Takip Edilen37K Takipçiler
Sabitlenmiş Tweet
Trail of Bits
Trail of Bits@trailofbits·
Over 700,000 repos ship crypto libraries that default to a static IV, creating widespread key reuse. We also released mquire, a Linux memory forensics tool, and added 12 new open-source Claude Code skills for security engineering. March Tribune: mailchi.mp/trailofbits/ma…
English
7
12
83
10.9K
Trail of Bits retweetledi
InsanityBit
InsanityBit@InsanityBit·
Lack of mutation testing in Rust has always been a bummer (tbh it is such a rare treat in any language). Could be huge, excited to check this out. Mutation testing + property testing are just orders of magnitude more effective than industry standard.
Trail of Bits@trailofbits

MuTON and mewt introduce bugs, run tests, and find what coverage misses. MuTON supports TON languages, built in collaboration with @ton_blockchain. mewt covers Solidity, Rust, and more. blog.trailofbits.com/2026/04/01/mut…

English
0
3
11
1.7K
Trail of Bits
Trail of Bits@trailofbits·
We saw high coverage mask a fund-draining vulnerability, and caught it with mutation testing. Then we built the tools to make this routine. 🧵
English
2
0
30
2.8K
Trail of Bits
Trail of Bits@trailofbits·
We’re sponsoring the event and will be on-site. Come find us and get some swag.
English
0
0
5
765
Trail of Bits
Trail of Bits@trailofbits·
The full toolkit lives at github.com/crytic. Static analysis, fuzzing, EVM disassembly, compiler management, and pre-built security properties.
English
1
1
3
875
Trail of Bits
Trail of Bits@trailofbits·
If you're competing in the @‌Wonderland CTF later today, these are the most common open-source tools we use to review contracts in production. 🧵
English
2
7
56
6.9K
Trail of Bits
Trail of Bits@trailofbits·
We made the paper. Dimensional analysis catching Solidity bugs hiding in plain sight. 13 down in the @RektHQ Summit crossword. Come find us in Cannes.
Trail of Bits tweet media
English
2
5
55
5.3K
Trail of Bits retweetledi
forefy
forefy@forefy·
@trailofbits 's dimensional-analysis is *provenly the best auditing skill to detect logic vulnerabilities in smart contracts you may disagree - as I only compared it to 2 other logic-focused bug finding skills, and only ran a couple of iterations against each - but that's the best benchmark out there for this so far best part - you just need 1 click and an AI agent to contribute to the benchmark and try it yourself forefy.com/benchmarks/058…
forefy tweet media
Trail of Bits@trailofbits

Four phases: discover a vocabulary of base units, annotate the codebase, propagate dimensions across function boundaries, then validate for mismatches. It also generates a DIMENSIONAL_UNITS.md you can commit to your repo. blog.trailofbits.com/2026/03/25/try…

English
6
6
77
20.6K
Trail of Bits
Trail of Bits@trailofbits·
Four phases: discover a vocabulary of base units, annotate the codebase, propagate dimensions across function boundaries, then validate for mismatches. It also generates a DIMENSIONAL_UNITS.md you can commit to your repo. blog.trailofbits.com/2026/03/25/try…
English
2
6
46
14K
Trail of Bits
Trail of Bits@trailofbits·
We tested against dimensional mismatch issues from several unpublished audits. The plugin also cut standard deviation from 20% to 12%. Better results, more consistent. github.com/trailofbits/sk…
English
2
2
15
4.8K
Trail of Bits
Trail of Bits@trailofbits·
93% recall vs 50% for baseline prompts. Our new dimensional-analysis plugin for Claude Code doesn't ask it to find bugs. It annotates your codebase with dimensional types, then flags mismatches mechanically. 🧵
English
4
19
160
41.2K
Trail of Bits
Trail of Bits@trailofbits·
We've used this technique successfully in real audits. During an audit, dimensional analysis caught code passing decimals where it expected token amounts. Identified in seconds, no deep code review needed.
English
1
1
10
2.7K
Trail of Bits
Trail of Bits@trailofbits·
Physicists catch formula errors in seconds with a trick most DeFi developers have never heard of. You should learn dimension analysis. 🧵
English
8
20
151
20.9K
Trail of Bits retweetledi
Benjamin Samuels
Benjamin Samuels@thebensams·
How many stablecoin providers are actually resistant to private key compromise? If there's one thing everyone should learn from Resolv, it's that you must EXPECT your private keys to be compromised.🧵
English
2
6
32
4.9K