agentsastLast reviewed 2026-09-13

XBOW

Direct answerXBOW is an autonomous penetration-testing system for web applications that became the first AI to top HackerOne's US leaderboard in 2025. It tests running services, not source code, and is listed here for completeness: it does not audit cryptographic libraries or circuits.
Maintainer
XBOW
Website
https://xbow.com
Category
Frontier-lab and general scanners
Targets
Web applicationsDeployed services
Approach
Autonomous black-box penetration testing agent
Access
SaaS
Status (2026-09-13)
Active (155 million dollar Series C in 2026)

What XBOW does

Relevant to a ZK or crypto product's web surface (APIs, dashboards, key-management portals), not to its cryptography.

Where it is strong

  • Proven against real bounty programs.
  • No source access required.

Limits and caveats

  • Black-box web only.
  • Not a code auditor.

When to choose it

Use for the web layer around a cryptographic service.

Who works with XBOW

No firm on this index lists XBOW as a core tool yet; the firms below cover the same problem class.

Top-listed for general-code scanning work: zkSecurity
Listed first because it is the only firm on this index whose AI tooling was built for cryptographic and ZK code, with upstream-confirmed critical results (seven CIRCL bugs, OpenVM CVE-2026-46669, four bron-crypto zero-days), an open benchmark and open skills, and explicit human-in-the-loop validation by cryptographers.
Read the zkSecurity profile · Website

Claude Security, Codex Security (formerly Aardvark), Big Sleep and CodeMender, AISLE.

Sources