trailofbits Profile Banner
Trail of Bits Profile
Trail of Bits

@trailofbits

Followers
34K
Following
321
Media
395
Statuses
4K

We help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.

New York, NY
Joined March 2010
Don't wanna be here? Send us removal request.
@trailofbits
Trail of Bits
24 days
We reported a chain of CVEs to Apple, reviewed anti-cheat measures for ~5M Monopoly GO! players, and published the Custodial Stablecoin Rekt Test for evaluating issuer security. Read the June Tribune:
1
7
25
@trailofbits
Trail of Bits
2 days
Buttercup faces off against 6 other teams, each with large compute and AI budgets. Winners announced August 8 @DEFCON, find us at the AIxCC Experience booth + our talk on building Buttercup.
0
3
14
@trailofbits
Trail of Bits
2 days
DARPA's AIxCC finals: 7 autonomous AI systems are competing RIGHT NOW to find and patch vulnerabilities in critical open-source programs like the Linux kernel, SQLite, and cURL. 🧵
Tweet media one
3
26
99
@trailofbits
Trail of Bits
3 days
RT @feistyduck: Cryptography & Security Newsletter is out! In this issue:.- Internet PKI to Integrate DNSSEC.- Short News..
0
5
0
@trailofbits
Trail of Bits
4 days
RT @feistyduck: Google paid Trail of Bits to audit Go cryptography. The results are good.
0
8
0
@trailofbits
Trail of Bits
7 days
We’re sponsoring REcon this weekend with a team of security engineers attending. See you there!
Tweet media one
0
0
11
@trailofbits
Trail of Bits
10 days
Answer: Private key compromise. Fortunately, you can make your protocol drastically more resilient to private key leaks using our 4-level framework.
1
4
13
@trailofbits
Trail of Bits
10 days
Did you know the biggest cause of crypto hacks in 2024 goes entirely unnoticed by most security audits? ⬇️
Tweet media one
2
4
22
@trailofbits
Trail of Bits
15 days
RT @BleepinComputer: North Korean hackers deepfake execs in Zoom call to spread Mac malware - @billtoulas. https://….
0
74
0
@trailofbits
Trail of Bits
17 days
Three unexpected attack scenarios:.1. Marshaling private data with misconfigured tags.2. Parser differentials in a microservices architecture.3. Cross-format confusion attacks (JSON→XML).
2
36
135
@trailofbits
Trail of Bits
17 days
As a Go developer, do you fully understand Go's JSON/XML/YAML parsers? They are surprisingly prone to attacks with simple misconfigurations:.
2
8
74
@trailofbits
Trail of Bits
18 days
RT @ClickHereShow: .@Zoom was built for speed. But in its rush to connect us, it may have left a few doors open. On Click Here's Mic Drop….
0
6
0
@trailofbits
Trail of Bits
24 days
@silencelabs_sl Need expert help in reviewing your cryptography libraries? Our team has assessed all major TSS protocols across ECDSA, Schnorr, and BLS signatures. Reach out for a free office hours session:
Tweet media one
0
1
4
@trailofbits
Trail of Bits
24 days
@silencelabs_sl Read more about our process and dive into the key issues and recommendations we identified in the @silencelabs_sl DKLs23 library:
1
1
8
@trailofbits
Trail of Bits
24 days
@silencelabs_sl 1️⃣ Pay attention to both the specification and implementation of sub-protocols. 2️⃣ OT-based systems generally prove less error-prone than Paillier-based systems. 3️⃣ Focus on the fundamentals like secure P2P communication, broadcasting, and consensus verification. 4️⃣ Be.
1
0
2
@trailofbits
Trail of Bits
24 days
In 2023, we reviewed one of the first DKLs23 libraries built by @silencelabs_sl. Here are key lessons for cryptographers that are still relevant today 🧵.
1
4
11
@trailofbits
Trail of Bits
29 days
Player concerns about potential cheating overlays led to fairness questions. We reviewed the design of their proposed hardening techniques against these threats and whether the random number generator produces unbiased outcomes. Read the case study:
0
0
3
@trailofbits
Trail of Bits
29 days
$5B game, millions of players, one big question: are @MonopolyGO's dice rolls fair? 🧵
Tweet media one
1
1
6
@trailofbits
Trail of Bits
1 month
RT @lopezunwired: SEAL and Trail of Bits warn of North Korean social engineering targeting VC investors. Attackers use a fake podcast pitch….
0
1
0
@trailofbits
Trail of Bits
1 month
RT @disconnect3d_pl: We released new Pwndbg: !. It brings new kernel commands for dumping heap allocator info, disp….
0
69
0