"Could've cost millions."
That's how Trail of Bits refers to a bug they found in the Miden VM core library while testing our systems from the ground up. The key word is could've, because they found it, and fixed it.
Miden VM runs on its own assembly language, MASM. When Trail of Bits first looked at MASM, it had almost no developer tooling: no editor support, no linter, no static analyzer.
So they spent six months building it all from scratch, before the review even started. AI helped. ToB's agents, both Claude and Codex, built an editor plugin, a decompiler, a static analysis engine, and a formal model of the VM in Lean, under human supervision.
That’s 100+ commits of tooling that didn't exist, enabling humans to go deeper than any manual review, Trail of Bits says.
The results:
🔸A high-severity signature-forgery bug, caught and fixed pre-launch
🔸95 machine-checked correctness proofs covering the core library's binary arithmetic
🔸A static analysis engine we've adopted permanently -- every future change gets the same scrutiny
Trail of Bits looked at where security reviews are headed in the age of AI. What can agents build and how do you manage them? And, why the economics of deep audits just changed.
https://lnkd.in/eD75A3mv