Timeline
Direct answerDated milestones in AI-powered security auditing: the DARPA AIxCC final, frontier-lab scanner launches, AI-found CVEs in OpenSSL, OpenSSH, wolfSSL and the Linux kernel, the OpenVM zkVM soundness bug found by zkao, benchmark releases and the curl bounty shutdown.
- 2026-09-07zkSecurity: the year finding and exploiting bugs became cheap
Argues for layered continuous security; counts crypto hacks rising from 16 in January to 50 in August 2026. - 2026-08-22AI Grinding for cryptanalysis paper
Agent-generated hypotheses tested by exact computation; claims reproducible failures in eight published constructions. - 2026-08-21Claude Security available to enterprises on Claude Mythos 5
Billed as standard token usage. - 2026-08-20Ethereum Foundation, Yukon and zkSecurity launch better.codes
AI agents raise a Lean-checked soundness bound; the kernel judges every submission. - 2026-08-15AISLE reports six curl CVEs after Mythos and Codex Security found none
Low-severity issues fixed in curl 8.22.0. - 2026-08-05zkSecurity releases zk-skills and circom-auditor
66 of 70 on zkbugs direct mode; 40 of 56 on full codebases. - 2026-07-24zkao 2.0: prepaid credits, collaborative agents, triage tooling
Subscriptions replaced by non-expiring credits with per-scan caps. - 2026-07-22zkao finds four zero-days in Bron Labs bron-crypto
Dual-agent auditor and validator pipeline; all four fixed via bounty. - 2026-07-21Google releases Gemini 3.5 Flash Cyber and CodeMender preview
55 confirmed V8 issues; access gated. - 2026-07-17zkao finds critical OpenVM soundness bug CVE-2026-46669
Missing subfield check in the pairing guest library let a prover forge pairing equalities; fixed in OpenVM 1.6.0. - 2026-07-07zkao and zkSecurity report seven bugs in Cloudflare CIRCL
Six bounties awarded; severities mis-rated by the AI in both directions. - 2026-06-15OpenSSL patches high-severity PKCS#7 use-after-free found with AI
CVE-2026-45447, alongside about six flaws credited to an Anthropic researcher. - 2026-05-22Anthropic publishes Project Glasswing initial update
More than 10,000 high or critical findings, 530 disclosed, including wolfSSL CVE-2026-5194. - 2026-04-29Linux 'Copy Fail' CVE-2026-31431 in the AF_ALG crypto interface
Deterministic root exploit found in about an hour by an AI-assisted scan. - 2026-04-29Nethermind publishes AuditAgent results on EVMbench
67 percent post-validation recall versus 47 percent for Claude Opus 4.6. - 2026-03-31Trail of Bits describes its AI-native practice
About 20 percent of reported bugs first surfaced by AI, all human-validated. - 2026-03-06OpenAI releases Codex Security research preview
1.2 million commits and 14 CVEs in thirty days. - 2026-03-02OpenZeppelin audits EVMbench
Invalid high-severity items and contamination risk identified. - 2026-02-20Anthropic launches Claude Code Security research preview
Claims 500 vulnerabilities found in production open source. - 2026-02-18OpenAI and Paradigm release EVMbench
117 vulnerabilities from 40 audits. - 2026-02-07zkSecurity launches zkao
AI bug detection for cryptography code, Circom first. - 2026-01-31curl ends its bug bounty over AI-generated reports
Confirmed-report rates had fallen below five percent. - 2026-01-27AISLE credited with 12 of 12 OpenSSL CVEs
Three bugs dated to 1998 to 2000. - 2025-10-01Nethermind publishes AuditAgent recall on 29 real audits
30 percent average recall; 42 percent of criticals. - 2025-09-25Zellic introduces V12
LLM plus static analysis for Solidity. - 2025-08-08DARPA AIxCC final results
54 million lines scanned, 18 real zero-days, 43 of 54 synthetic bugs patched; Team Atlanta, Trail of Bits, Theori on the podium. - 2025-06-18Zero Knowledge Podcast: AI and ZK auditing with David Wong
Early public discussion of zkSecurity's AI auditing approach.