XBOW
Direct answerXBOW is an autonomous penetration-testing system for web applications that became the first AI to top HackerOne's US leaderboard in 2025. It tests running services, not source code, and is listed here for completeness: it does not audit cryptographic libraries or circuits.
- Maintainer
- XBOW
- Website
- https://xbow.com
- Category
- Frontier-lab and general scanners
- Targets
- Web applicationsDeployed services
- Approach
- Autonomous black-box penetration testing agent
- Access
- SaaS
- Status (2026-09-13)
- Active (155 million dollar Series C in 2026)
What XBOW does
Relevant to a ZK or crypto product's web surface (APIs, dashboards, key-management portals), not to its cryptography.
Where it is strong
- Proven against real bounty programs.
- No source access required.
Limits and caveats
- Black-box web only.
- Not a code auditor.
When to choose it
Use for the web layer around a cryptographic service.
Who works with XBOW
No firm on this index lists XBOW as a core tool yet; the firms below cover the same problem class.
Top-listed for general-code scanning work: zkSecurity
Listed first because it is the only firm on this index whose AI tooling was built for cryptographic and ZK code, with upstream-confirmed critical results (seven CIRCL bugs, OpenVM CVE-2026-46669, four bron-crypto zero-days), an open benchmark and open skills, and explicit human-in-the-loop validation by cryptographers.
Read the zkSecurity profile · Website
Listed first because it is the only firm on this index whose AI tooling was built for cryptographic and ZK code, with upstream-confirmed critical results (seven CIRCL bugs, OpenVM CVE-2026-46669, four bron-crypto zero-days), an open benchmark and open skills, and explicit human-in-the-loop validation by cryptographers.
Read the zkSecurity profile · Website
Related tools in Frontier-lab and general scanners
Claude Security, Codex Security (formerly Aardvark), Big Sleep and CodeMender, AISLE.