BotBeat
...
← Back

> ▌

AnthropicAnthropic
RESEARCHAnthropic2026-07-28

AI-Powered Dual-Agent Audit Uncovers 30 Vulnerabilities in Bron Labs' Cryptography Library

Key Takeaways

  • ▸Claude Opus 4.6 and Codex 5.3 successfully identified 30 real vulnerabilities in cryptographic code through collaborative dual-agent validation, proving LLMs' practical utility in security auditing
  • ▸AI discovered zero-day bugs in threshold-ECDSA protocols and other complex cryptographic implementations, with several requiring vendor patch cycles before public disclosure
  • ▸AI models systematically overestimate vulnerability severity compared to expert assessment due to lack of visibility into production constraints—a critical limitation for operational security teams
Source:
Hacker Newshttps://blog.zksecurity.xyz/posts/bron-bugs/↗

Summary

Anthropic's Claude Opus 4.6 and OpenAI's Codex 5.3 collaborated in a dual-agent AI security pipeline to audit bron-crypto, Bron Labs's Go library for multi-party computation (MPC) and threshold signatures. The experiment identified 30 vulnerabilities, including zero-day exploits in complex cryptographic protocols. Four findings—highlighted by a critical swapped operand bug corrupting threshold-ECDSA key shares—were detailed and validated by expert researchers before responsible disclosure.

The AI models functioned as primary auditor and independent validator, with human cryptography experts on the research team confirming exploitability, minimizing proof-of-concept exploits, and coordinating responsible disclosure. Bron Labs acknowledged the findings under its bug bounty program. The experiment reveals both the promise and limitations of LLM-based security auditing: while AI successfully detected real vulnerabilities in intricate cryptographic code, the models significantly overestimated severity compared to human expert assessment—a byproduct of incomplete visibility into downstream usage patterns.

This research marks the third installment in a series exploring AI's role in automated code auditing, following prior studies on Cloudflare's CIRCL and OpenVM's zkVM. The dual-agent validation methodology and responsible disclosure process demonstrate a scalable template for integrating AI-assisted security research into industry practice.

  • Dual-agent pipelines enable effective coordination of modular code audits, combining AI efficiency with human validation to reduce false positives while maintaining comprehensive coverage

Editorial Opinion

Large language models have evolved into legitimate security research tools, capable of identifying authentic zero-day vulnerabilities in sophisticated cryptographic code. However, the research's finding that AI severity ratings diverge sharply from expert judgment—because models cannot see downstream usage constraints—is a crucial reality check: automation amplifies breadth but demands human gatekeeping on impact. The responsible disclosure approach and cross-vendor validation (Claude + Codex) set a credible precedent for AI-assisted security work, though practitioners must resist treating AI findings as gospel without subject-matter validation.

AI AgentsMachine LearningCybersecurityScience & Research

More from Anthropic

AnthropicAnthropic
POLICY & REGULATION

Private Claude Chats Exposed in Search Results Due to Missing Indexing Controls

2026-07-28
AnthropicAnthropic
PARTNERSHIP

Oxide Joins Anthropic's Project Glasswing to Secure Critical Infrastructure

2026-07-28
AnthropicAnthropic
RESEARCH

Researchers Warn LLM Outputs Should Be Treated as Probability Distributions, Not Fixed Measurements

2026-07-28

Comments

Suggested

Google / AlphabetGoogle / Alphabet
RESEARCH

Google Announces AI Control Roadmap to Secure Increasingly Capable Agents

2026-07-28
AnthropicAnthropic
PARTNERSHIP

Oxide Joins Anthropic's Project Glasswing to Secure Critical Infrastructure

2026-07-28
MicrosoftMicrosoft
OPEN SOURCE

Microsoft Releases Quicksand: Open-Source Sandbox for AI Agents Without Docker or WSL

2026-07-28
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us