RoboDuck: Theori's LLM-only proof-of-vulnerability pipeline, AIxCC third place ============================================================================== RoboDuck placed third in AIxCC (1.5 million dollars) with a pipeline that relies on LLM reasoning alone to produce proofs of vulnerability, without fuzzing or symbolic execution. Maintainer: Theori Website: https://theori.io Category: Cyber reasoning systems (DARPA AIxCC) Targets: C, Java Approach: LLM-only pipeline with no fuzzing or symbolic execution Access: Open source Status: Open-sourced 2025 Strengths: Simple architecture. | Competitive result without fuzzing. Limits: No execution ground truth. | C and Java. Firms using it: none listed Sources: https://www.darpa.mil/news/2025/aixcc-results | https://arxiv.org/abs/2602.07666 Source page: https://agentsast.com/tools/roboduck/ Compiled by: agentsast editors (https://agentsast.com/about/) Last reviewed: 2026-09-13