Trail of Bits’ cover photo
Trail of Bits

Trail of Bits

Computer and Network Security

New York, NY 24,513 followers

Deepening the Science of Security

About us

Since 2012, Trail of Bits has been the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks.

Website
https://www.trailofbits.com
Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
New York, NY
Type
Privately Held
Founded
2012
Specialties
software security, reverse engineering, cryptography, blockchain, osquery, machine learning, binary analysis, blockchain, Application Security, and AI/ML

Locations

Employees at Trail of Bits

Updates

  • Trail of Bits reposted this

    Critical RCE chain across Vault and OpenBao patched for the latter, great work from the team operationalizing and remediating. Thanks to Trail of Bits for the collaboration and Alexander Scheel for PoC, coordinating and delivering fixes, and detail of IBM's response to our efforts to disclose Vault vulns in the post.

    View organization page for ControlPlane

    4,753 followers

    In collaboration with the OpenBao community, ControlPlane has recently helped remediate a full exploit chain that allowed unauthenticated access and escalation to full Remote Code Execution (RCE). This marks only the second-ever RCE vulnerability discovered in Vault and OpenBao, combining disclosures from three independent reporters into a single, devastating exploit chain. How the chain works: By abusing a PKI ACME validation bypass, an unauthenticated attacker can spoof a service provisioner's identity. Then, they can modify an admin account, escalate privileges across namespaces, and ultimately achieve full RCE by restoring a malicious Raft storage snapshot. We've published a full technical breakdown. Link to the blog is in the comments, or get involved in the conversation on Hacker News #CyberSecurity #OpenBao #VulnerabilityManagement #InfoSec #CloudNativeSecurity

    • No alternative text description for this image
  • Our Avalanche experience includes security reviews of AvalancheGo, libevm, and Subnet EVM for Ava Labs. We're bringing that work to builders through the new Avalanche Audit Marketplace, where we're one of the vetted firms. We're also the team behind Slither, Echidna, and Medusa, and we've published 391 blockchain security reviews that anyone can read. Request a quote: https://lnkd.in/djwVUXZd

    The Avalanche Audit Marketplace is now live on the Builder Hub 🔺 Security audits are one of the biggest bottlenecks between a finished protocol and a mainnet launch. Finding the right firm means cold outreach, one conversation at a time, with no easy way to compare scope or pricing. Then you have the cost itself stopping plenty of good teams from auditing at all. We built the Audit Marketplace to remove both problems. Submit once. Complete your audit request in four short steps and it reaches every security firm on the Ava Labs whitelist or only the ones you select, if you already have firms in mind. Quotes come to you. Firms have 10 days to respond, and every quote stays private to you. No sales calls, no inbox full of outreach. Contact information is only exchanged once you accept a quote, so you're in control of the process until you've made a decision. Pick one, get subsidized. Select the quote that works best for you. The program can cover up to 75% of the audit cost, and there are $0 platform fees for builders and auditors alike. Every firm on the whitelist has passed Ava Labs' security review. Services range from smart contract audits to formal verification to AI security scans. All of your security needs covered in one place. Get started here 👇 https://lnkd.in/eVDrw26y

  • Trail of Bits reposted this

    OpenBao v2.6.3 is out! 🔐 Our latest 2.6 patch release is focused on security and bug fixes. Make sure to patch your instances accordingly! This update also includes fixes identified through the Patch the Planet initiative in partnership with Trail of Bits and OpenAI. Big thanks to all reporters, contributors, and the entire community! 🔗 Read the full changelog here: https://lnkd.in/e_CZjAUQ #OpenBao #SecretsManagement #OpenSSF #OpenSource #Security

  • View organization page for Trail of Bits

    24,513 followers

    Threshold signatures secure billions of dollars in crypto, and teams increasingly run them inside Trusted Execution Environments (TEEs) for extra protection. But MPC and TEEs make different bets on trust: MPC spreads trust across independent parties, while TEEs concentrate it in the hardware manufacturer and its attestation infrastructure. In one pattern from our audits, a malicious host rolls back the filesystem after a signer deletes a used pre-signature. The signer reuses that value and leaks their private key share. We wrote up what TEE attestation can and can't fix in MPC deployments, the pitfalls we see most often in audits, and how to combine the two correctly. https://lnkd.in/eipeC8C9

  • Our OpenClaw Foundation security assessment produced 27 advisories, 3 hardening PRs, and 1 architectural submission. Read the report: https://lnkd.in/gBu_Husw

    View organization page for OpenClaw Foundation

    2,267 followers

    What happens when an AI agent’s permissions change while it’s still working? That was one of the security questions explored in OpenClaw’s recent audit with Trail of Bits through OpenAI's Patch the Planet initiative. The review examined how permissions, identity, and approvals hold up as agents carry out work across multiple steps. Every actionable issue has been repaired, with fixes shipped in stable releases. 🤖 Josh Avant's recap explains what the team found, what changed, and what we learned about securing agent systems. https://lnkd.in/eAp7NaBa

  • We're the only red team for Advanced Research + Invention Agency (ARIA)'s Safeguarded AI programme, led by Nora Ammann. Seven of the programme's eight teams are building software and hardware components with machine-checked proofs. In each development cycle, we'll test whether those guarantees survive realistic attacks. A proof guarantees exactly what its specification says, under the assumptions it makes. So we go past the implementation into everything the proof rests on: the models, specifications, assumptions, and deployment choices behind each team's assurance case.

    AI-enabled cyber attacks are getting faster + going further. But what if AI-enabled formal methods could make high-assurance cyber defence practical at unprecedented speed and scale? To test that idea, we’re backing eight new research projects with £22m as part of the Safeguarded AI programme, led by Nora Ammann. The projects will target systems where machine-checked correctness would yield outsized, widespread resilience gains, from containing AI agents to protecting the code on millions of Android devices, whilst building durable UK capability at the intersection of formal methods and AI. Six blue teams and one opportunity seed team will build production-grade software and hardware components carrying machine-checked proofs, whilst an independent central red team attempts to break the full assurance case behind their security claims. Success could bring provable security to some of the world's most widely relied-upon software and hardware. Meet the teams: https://lnkd.in/e3fzJb9g

  • We're hiring a Senior Developer Relations Engineer, and we want a builder. The person in this role ships software people use, contributes alongside our engineers and open-source maintainers, and uses AI tooling in daily practice. Their public work, whether research, talks, CVEs, or maintained projects, holds up with practitioners who check every claim. The job is to help our research and tools reach the people who need them: attract outside contributors, support maintainers, and bring what the community tells us back into the firm. If that describes you, or someone you'd vouch for, apply here: https://lnkd.in/eazF7FBS

    • No alternative text description for this image
  • Bee is a wearable that listens to your day. It's designed so that no one else, including Amazon, can read what it hears. We tested that design with a focus on the hardest attacker to stop: an insider with operator access. We found several ways an Amazon operator could run unapproved code on the attested servers that process user data. Amazon closed each one, fixed all 7 high-severity issues, and published the full report: https://lnkd.in/g4scAuSm

    View organization page for Bee

    3,969 followers

    Your conversations are personal. Bee is built to keep them that way. Bee Private Compute safeguards the transcripts, summaries, and to-dos that help Bee turn everyday conversations into useful memories and actions. When Bee captures a conversation, the audio is processed in real time and discarded without being saved. The information created from it is encrypted using keys generated and controlled by your device. Amazon has no master key that can unlock your content, and only you decide if anything is shared. Learn more in our Amazon News article, technical whitepaper, and independent security assessment by Trail of Bits: https://lnkd.in/geFQ3RZG

  • Trail of Bits reposted this

    For the last six months I've been working on an amazing NVIDIA team that has been contributing security fixes to OpenClaw. Last week Trail of Bits completed an assessment on the project where they found 0 critical issues, 2 highs and a handful of lows and mediums. For a project that moves at the velocity of OpenClaw (the 2026.8.1 release contained 16k Pull Requests) this is an incredible success. Our team has reviewed over 1000 security incidents on OpenClaw in the last 6 months and contributed hundreds of fixes. Sometimes these fixes break functionality in unexpected ways and we are sorry for that, this is the delicate balance of security remediation work. We will continue to work to avoid regressions like these in the future. For a project that started the year in infamy due to the challenges of securing personal agents things have come a long way. I'm really excited to continue contributing to OpenClaw as it matures into production software. Links in the comments 👇

    • No alternative text description for this image
  • Trail of Bits reposted this

    "Could've cost millions." That's how Trail of Bits refers to a bug they found in the Miden VM core library while testing our systems from the ground up. The key word is could've, because they found it, and fixed it. Miden VM runs on its own assembly language, MASM. When Trail of Bits first looked at MASM, it had almost no developer tooling: no editor support, no linter, no static analyzer. So they spent six months building it all from scratch, before the review even started. AI helped. ToB's agents, both Claude and Codex, built an editor plugin, a decompiler, a static analysis engine, and a formal model of the VM in Lean, under human supervision. That’s 100+ commits of tooling that didn't exist, enabling humans to go deeper than any manual review, Trail of Bits says. The results: 🔸A high-severity signature-forgery bug, caught and fixed pre-launch 🔸95 machine-checked correctness proofs covering the core library's binary arithmetic 🔸A static analysis engine we've adopted permanently -- every future change gets the same scrutiny Trail of Bits looked at where security reviews are headed in the age of AI. What can agents build and how do you manage them? And, why the economics of deep audits just changed. https://lnkd.in/eD75A3mv

Similar pages

Browse jobs