agentsastLast reviewed 2026-09-13

LLM plus fuzzing

Direct answerThe model proposes harnesses, seeds or mutation patterns; the fuzzer supplies ground truth by crashing or violating an oracle.

In more detail

This is the AIxCC architecture and the zkCraft design. Its strength is that reported bugs are real by construction; its weakness is that it only reaches what the fuzzer can execute.

Tools that address it

Buttercup, zkCraft (with zkFuzz), Atlantis.

False positive rate, Precision vs recall, Agentic scanning, LLM plus symbolic execution or formal verification, Hallucinated vulnerabilities, Triage burden, Benchmark contamination, Human-in-the-loop, AI-assisted audit vs AI audit, Prompt injection in auditing pipelines, Responsible disclosure of AI-found bugs, Continuous scanning and run-count coverage, Proof-of-concept harness, Threat model file, Severity calibration

Getting help

Firms on this index that handle this in practice: zkSecurity, Trail of Bits, Zellic, Nethermind Security.