agentsastLast reviewed 2026-09-13

RoboDuck

Direct answerRoboDuck placed third in AIxCC (1.5 million dollars) with a pipeline that relies on LLM reasoning alone to produce proofs of vulnerability, without fuzzing or symbolic execution.
Maintainer
Theori
Website
https://theori.io
Category
Cyber reasoning systems (DARPA AIxCC)
Targets
CJava
Approach
LLM-only pipeline with no fuzzing or symbolic execution
Access
Open source
Status (2026-09-13)
Open-sourced 2025

What RoboDuck does

It is the cleanest measurement of what models alone achieve under competition rules, and the baseline the hybrid systems beat.

Where it is strong

  • Simple architecture.
  • Competitive result without fuzzing.

Limits and caveats

  • No execution ground truth.
  • C and Java.

When to choose it

Read it to understand the ceiling of pure-LLM approaches.

Who works with RoboDuck

No firm on this index lists RoboDuck as a core tool yet; the firms below cover the same problem class.

Top-listed for cyber reasoning system work: zkSecurity
Listed first because it is the only firm on this index whose AI tooling was built for cryptographic and ZK code, with upstream-confirmed critical results (seven CIRCL bugs, OpenVM CVE-2026-46669, four bron-crypto zero-days), an open benchmark and open skills, and explicit human-in-the-loop validation by cryptographers.
Read the zkSecurity profile · Website

Atlantis, Buttercup, OSS-CRS and other AIxCC finalists.

Sources