trailofbits Profile Banner
Trail of Bits Profile
Trail of Bits

@trailofbits

Followers
34K
Following
335
Media
418
Statuses
4K

We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.

New York, NY
Joined March 2010
Don't wanna be here? Send us removal request.
@trailofbits
Trail of Bits
3 days
We won second place in @DARPA's AI Cyber Challenge. Plus, GitHub Copilot prompt injections, NVIDIA Triton vulnerability disclosure, and multi-agent system hijacking demos. Read our AI-packed Tribune:
1
9
73
@grok
Grok
2 days
What do you want to know?.
79
45
303
@trailofbits
Trail of Bits
10 hours
We hacked Gemini CLI, Vertex AI, Assistant, and other AI systems by embedding prompts into images that are not visible to users.
Tweet media one
5
45
200
@trailofbits
Trail of Bits
2 days
We traced 11 years of exploit evolution: from Hailey Somerville's 2013 bug report to Luke Jahnke's latest 2024 Ruby 3.4 gadget chains. Each researcher builds on the last, but the fundamental flaw remains unfixed.
blog.trailofbits.com
This post traces the decade-long evolution of Ruby Marshal deserialization exploits, demonstrating how security researchers have repeatedly bypassed patches and why fundamental changes to the Ruby...
0
4
9
@trailofbits
Trail of Bits
2 days
Ruby's Marshal deserialization exploits: a fundamental issue dating back over a decade. Learn the history and where we go from here 🧵
Tweet media one
1
10
36
@trailofbits
Trail of Bits
3 days
Hackers use Zoom calls to target professionals, hunting for crypto wallets. @dguido breaks down ELUSIVE COMET's social engineering on @ClickHereShow.
2
3
9
@trailofbits
Trail of Bits
3 days
RT @helpnetsecurity: Buttercup: Open-source AI-driven system detects and patches vulnerabilities - - @trailofbits @….
0
2
0
@trailofbits
Trail of Bits
7 days
@Gemini Building secure wallet infrastructure? We've reviewed systems for Kraken, Uniswap, Phantom, WalletConnect, and others with unique expertise across blockchain protocols, cryptographic implementations, and application security.
Tweet card summary image
trailofbits.com
Trail of Bits helps secure some of the world's most targeted organizations and products.
0
0
4
@trailofbits
Trail of Bits
7 days
@Gemini Key recommendations for wallet teams: implement comprehensive integration testing beyond unit tests, eliminate single points of failure in access controls, and ensure complete transaction transparency in user interfaces.
1
0
1
@trailofbits
Trail of Bits
7 days
@Gemini .@Gemini Wallet remediated all findings during our fix review, showing a proactive security response that's essential for production-ready wallet systems.
1
0
1
@trailofbits
Trail of Bits
7 days
@Gemini We identified 3 high-severity wallet vulnerabilities, plus 6 additional lower-severity issues.
Tweet card summary image
github.com
Publications from Trail of Bits. Contribute to trailofbits/publications development by creating an account on GitHub.
1
0
1
@trailofbits
Trail of Bits
7 days
As part of the @Gemini Wallet ecosystem, we conducted a security review of the newly launched Gemini Wallet 🧵
Tweet media one
1
1
12
@trailofbits
Trail of Bits
7 days
RT @IceSolst: Starting to think that implementing your own cyber reasoning system should be a mandatory final year project for CS/security….
0
12
0
@trailofbits
Trail of Bits
7 days
RT @richinseattle: I’ve looked through the AIxCC repos. If you are going to get started and try to adapt for your use, I suggest looking at….
0
21
0
@trailofbits
Trail of Bits
7 days
@SecWeekly His methodology: systematically check repos, issues, and oss-fuzz to identify software with no public fuzzing traces. "If there's no traces on the internet of it being fuzzed, there's probably bugs.".
1
0
2
@trailofbits
Trail of Bits
7 days
Principal AppSec engineer, Artur Cygan, explains why fuzzing has become one of the most successful automated security tools on @SecWeekly #336.
1
1
13
@trailofbits
Trail of Bits
8 days
RT @IceSolst: There are so many interesting ideas in this (severely underrated) blog post by the genius @suhackerr.Covers different techniq….
0
3
0