Trail of Bits

4.2K posts

Trail of Bits banner
Trail of Bits

Trail of Bits

@trailofbits

We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.

New York, NY Katılım Mart 2010
257 Takip Edilen37.5K Takipçiler
Sabitlenmiş Tweet
Trail of Bits
Trail of Bits@trailofbits·
Over 700,000 repos ship crypto libraries that default to a static IV, creating widespread key reuse. We also released mquire, a Linux memory forensics tool, and added 12 new open-source Claude Code skills for security engineering. March Tribune: mailchi.mp/trailofbits/ma…
English
7
13
96
13.9K
Trail of Bits
Trail of Bits@trailofbits·
Adding LibAFL support to Ruzzy took longer than expected. We took detours in ELF file internals, .init_array DSO sections, SanitizerCoverage interceptors, lazy vs. eager loading, and Ruby C extensions. blog.trailofbits.com/2026/04/29/ext…
English
0
1
12
1.4K
Trail of Bits
Trail of Bits@trailofbits·
libFuzzer is in maintenance mode. We added LibAFL support to Ruzzy so Ruby devs and security researchers can run their next fuzzing campaign without harness modifications. 🧵
English
2
1
33
4.1K
Trail of Bits retweetledi
pashov
pashov@pashov·
@filipeV3nancio Everyone saying Trail of Bits, they really got the street credit
English
2
1
29
8.3K
Trail of Bits
Trail of Bits@trailofbits·
The fastest way to get a team to adopt AI is to make them put in reps. We run hackathons as a forcing function. @dguido at unprompted
English
7
3
40
4.9K
Trail of Bits retweetledi
Vijay Bolina
Vijay Bolina@vijaybolina·
“The org is designed from the ground up assuming AI is a core participant. Not a tool you pick up, but a teammate that’s always there.” this is the way.
English
0
2
9
2.9K
Trail of Bits
Trail of Bits@trailofbits·
When Claude reasons about code, it reasons about lists, but the questions that actually matter are graph questions. We just open-sourced Trailmark to make it easy for security engineers to parse source code into a call graph for Claude. 🧵
English
15
49
373
43.3K
Trail of Bits
Trail of Bits@trailofbits·
Trailmark supports 17 languages. We're also releasing 8 Claude skills built on its API. On Ed448, one classified 73% of surviving mutants as equivalent. Flat lists can't see that. blog.trailofbits.com/2026/04/23/tra…
English
1
12
56
6.2K
Trail of Bits
Trail of Bits@trailofbits·
Reframed: The machine doesn't cook for you. It makes you a faster, more efficient chef. The playbook for how we went from 95% resistance to 80-95% weekly Claude usage within a year: blog.trailofbits.com/2026/03/31/how…
English
1
2
19
4.7K
Trail of Bits
Trail of Bits@trailofbits·
If you market a machine that “cooks for you,” a chef will never buy it. This is called identity threat, one of the four reasons why people resist adopting AI. @dguido breaks it down at unprompted:
English
5
19
158
22.8K
Stephen | DeFi Dojo
Stephen | DeFi Dojo@phtevenstrong·
PSA for protocols: Shortlist of good Opsec Providers ► @trailofbits@opsek_io@0xGroomLake@SEAL_911@DigOppGroup If you're building a protocol or worried that your opsec might not be airtight, PLEASE reach out to at least one of these teams.
Nomatic@Nomaticcap

OK OpSec audits needed yesterday. I've actually started trying to push this more with teams I have a decent amount of my personal $$$ stored with and teams I've invested in.

English
22
15
129
25.9K
Trail of Bits
Trail of Bits@trailofbits·
We're testing frontier AI models like GPT-5.4-Cyber as part of @OpenAI's Trusted Access for Cyber program. AI is dual-use, and the fastest way to find what attackers will do is to let defenders go first. openai.com/index/accelera…
English
2
11
79
9.2K
Trail of Bits retweetledi
Craig Gidney
Craig Gidney@CraigGidney·
Congrats to Ryan Keegan for being the first to exploit the simulator we used to validate the secret quantum circuits: blog.trailofbits.com/2026/04/17/we-… It kills me that the (now fixed) bugs were simple (we didn't port the op validation code from C++ to Rust!), but that's to be expected.
English
6
12
79
7K
Trail of Bits retweetledi
Steve Weis
Steve Weis@sweis·
Great write up of how Trail of Bits was able to find vulnerabilities in Google’s zero knowledge prover and generate a fake proof: blog.trailofbits.com/2026/04/17/we-…
English
0
21
105
6.9K
Trail of Bits
Trail of Bits@trailofbits·
Adoption is a ladder. Every team has clear levels, clear expectations, a clear path up, and real consequences for staying stuck. Every org's matrix should look different. Copy the system, not the specifics. blog.trailofbits.com/2026/03/31/how…
English
2
2
13
1.3K
Trail of Bits
Trail of Bits@trailofbits·
Our sales team's AI Maturity Matrix. Scored from 0-3, defining what AI-enabled work looks like at each level. 🧵
Trail of Bits tweet media
English
4
3
36
5K