Security research and adversarial testing for cryptography, blockchain, and AI systems
Trail of Bits is a security research firm staffed primarily by senior security engineers (51–200 employees, New York-based since 2012) working across cryptography, reverse engineering, blockchain, and now AI/ML attack surfaces. The project portfolio—smart contract security reviews, adversarial robustness testing, model extraction detection, and frontier system assessments—reveals a shift beyond traditional application security into emerging-risk domains. The language mix (Rust, Python, Go, OCaml, Haskell, Solidity) and active hiring in security roles signal deep technical depth oriented toward novel attack and defense research rather than commodity tooling.
Trail of Bits provides security research, testing, and advisory services for technology organizations facing novel and high-stakes security risks. The firm operates across multiple domains: smart contract and blockchain security, cryptographic systems, AI/ML robustness, binary analysis, and reverse engineering. Work includes custom security reviews, tool development for automated analysis, and novel attack discovery. The company is privately held, headquartered in New York, and operates exclusively in the United States market. Active projects span open-source security tooling, infrastructure assessment, and detection frameworks for emerging threats—reflecting a research-first operational model.
Primary languages are Rust, C++, Python, Go, and OCaml. Stack also includes Solidity (blockchain), Haskell, Java, and JavaScript. Infrastructure runs on macOS, Windows, and Linux, with CrowdStrike Falcon and Jamf Pro for endpoint management.
Active projects include smart contract security reviews, AI/ML security testing frameworks, adversarial robustness tools, blockchain security analysis, model extraction detection, and frontier system assessment work.
Other companies in the same industry, closest in size