1. X
  2. Trail of Bits
Log inSign up
Trail of Bits
4,345 posts
Trail of Bits profile banner
@trailofbits

Trail of Bits

@trailofbits
We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
New York, NY
trailofbits.com
Joined March 2010
261
Following
39K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @trailofbits
    Trail of Bits
    @trailofbits
    Aug 27
    We signed the call for collective action. Across 3 months, we audited 50 open-source projects using frontier cyber models. To date, we've found 1,268 potential issues and wrote 298 patches. Critical infrastructure around the world carries the same technical debt, but has far
    @gdb
    Greg Brockman
    OpenAI
    @gdb
    Aug 27
    An open letter for a global surge in cyber defense, signed by over 100 organizations including Anthropic, AWS, Google, Microsoft, OpenAI, and Oracle.
    Article cover image
    Article
    A call for collective action on cyber defense
    An open letter for a global surge in cyber defense, signed by over 100 organizations including Anthropic, AWS, Google, Microsoft, OpenAI, and Oracle. We have a limited window to strengthen cyber...
  • @trailofbits
    Trail of Bits
    @trailofbits
    Aug 26
    We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times. In its final escape, the agent found three 0-days on its own and chained them into a working exploit.
    Image
    VMs won't contain cyber-capable agents
    From blog.trailofbits.com
  • @trailofbits
    Trail of Bits
    @trailofbits
    Aug 25
    We found a bug that lets any user grant themselves admin access to live financial assets on Provenance, a Cosmos SDK chain. 82 token accounts were exploitable, representing ~$500K in drainable HASH. Now patched.
    Image
    State divergence enables unauthorized access
    From blog.trailofbits.com
  • @trailofbits
    Trail of Bits
    @trailofbits
    Aug 14
    PATCH THE PLANET BUG SPOTLIGHT: We found a medium-severity bug in aiohttp, Python's HTTP engine that had 600M+ downloads last month. Denys Pakizh caught oversized requests dodging its size limits. Now patched. CVE-2026-54277 in the dashboard:
    Image
    Dashboard · Patch the Planet · Trail of Bits
    From trailofbits.com
  • @trailofbits
    Trail of Bits
    @trailofbits
    Aug 11
    We're a day-one auditor for @signalapp's new Automatic Key Verification, which depends on external auditors to confirm everyone sees the same keys. We built our auditing software from scratch, open-sourced it, and run it as a public good.
    Image
    How Trail of Bits helps verify the integrity of your Signal chats
    From blog.trailofbits.com
Advertisement
Advertisement