A Bug Lurked for a Decade in Critical Code

▶ Watch (2:10)

An SSH vulnerability in Erlang OTP was disclosed in early 2025. The bug was introduced in 2014. It took maintainers 36 hours to patch. Cisco and NetApp still had unpatched hardware 4 months later. Andrew Carney called it trivial to find and trivial to exploit. He said tools could find it in 30 seconds. The bug survived because manual review cannot scale to the volume of critical infrastructure code.

Designing a Competition for Autonomous Patching

▶ Watch (3:41)

DARPA launched the AI Cyber Challenge (AIxCC) to build systems that find real vulnerabilities and patch source code automatically. The competition used synthetic forks of open-source projects with novel bugs never seen by any person or LLM. Patching quality mattered more than discovery. All finalist technology was released open source. Google, Anthropic, OpenAI, and Microsoft provided over $1 million in LLM credits and engineering support. The Linux Foundation and Open Source Security Foundation helped maintainers adopt the tools.

From Semi-Finals to Finals: Dramatic Improvement

▶ Watch (12:27)

In semi-finals teams handled simple reachable-bug challenges. For finals DARPA added real-world challenge types: patchiffs, full repo scoping, and bundle challenges that tie a triggering input to a patch and bug report. Teams discovered nearly 80% of synthetic vulnerabilities and patched over 60%. Java coverage jumped. They also found 18 real zero days and patched 11. Average time to patch was under an hour. Total spend was $360,000, with $82,000 on LLM credits. Carney said a typical patch cost less than $152.

Healthcare Cyber Attacks Demand Faster Patching

▶ Watch (17:24)

Deputy Secretary Jim O’Neill reported 650 ransomware incidents against healthcare providers from 2018 to 2024. Those attacks compromised 89 million patient records and caused $22 billion in downtime. Patching a vulnerability in healthcare takes 491 days on average versus 60–90 days in other industries. O’Neill announced HHS committed $20 million to translate winning solutions into real-world use. He called for 10X engineers, data scientists, and AI developers to join HHS.

DARPA’s $650M Bet and Open Source Release

▶ Watch (26:18)

Director Stephen Winchell said DARPA runs 14 programs with over $650 million invested in computer system security. He called AIxCC one of his favorite programs. Winchell announced four of the seven Cyber Reasoning Systems (CRSs) were released open source immediately. The other three follow in weeks. DARPA and ARPA-H added $1.4 million in prize money for applying the CRSs to critical infrastructure software. Total prize pool now exceeds $30 million.

The Winners and What They Achieved

▶ Watch (33:07)

Every team discovered a unique vulnerability class. Trail of Bits (second place) produced a 300-line scoring patch and scored on 20 vulnerability classes. Team Theory (third place) spent the least per vulnerability patched and found the most Java real-world bugs. Team Atlanta (first place, $4M) exceeded in all but one challenge category. Carney said these systems are the new floor and will only get better. The tools are now open source for anyone to use.

Notable Quotes

“trivial to find and trivial to exploit. It is literally why bother with authentication.” Andrew Carney · ▶ 2:40

“We gave them 70 known vulnerabilities. On top of that, they found 180 days. … The average time to patch is under an hour.” Andrew Carney · ▶ 14:19

“Patching a vulnerability in healthcare can take an average of 491 days compared to 60 to 90 days in most other industries.” Jim O’Neill · ▶ 19:16

“the machines are performing at superhuman levels already” Stephen Winchell · ▶ 28:16

Key Takeaways

  • AIxCC teams patched 60% of synthetic vulnerabilities and 11 real zero days in under an hour per patch.
  • Total competition spend was $360,000; a single patch cost less than $152 on average.
  • All seven finalist Cyber Reasoning Systems are open source and available for any maintainer to use.

About the Speaker(s)

Andrew Carney is Program Manager for the AI Cyber Challenge at DARPA and a Program Manager at ARPA-H. He has over 15 years in vulnerability research, reverse engineering, and automated program repair. He holds a master’s in computer science from Johns Hopkins University.

Stephen Winchell became DARPA’s 24th Director in May 2025. He previously led AI and autonomy portfolios at the DoD Strategic Capabilities Office and served as chief engineer for Project Maven. He is a U.S. Naval Academy graduate and former submarine officer.