BotBeat
...
← Back

> ▌

AikidoAikido
PRODUCT LAUNCHAikido2026-06-19

Aikido Launches Code Audit: AI-Powered Tool to Find Complex Logic Vulnerabilities Before They Ship

Key Takeaways

  • ▸Code Audit uses AI agents to trace references across files and identify multi-step logic vulnerabilities that SAST engines miss because they don't follow predictable pattern-matching rules
  • ▸Works on static code only—no staging environment, auth credentials, or live system access required; can audit undeployed code, feature-flagged paths, and admin routes
  • ▸Delivers pentest-grade findings at 10x lower cost than traditional pentesting, with median of 25 vulnerabilities per codebase and zero false-negatives in early testing
Source:
Hacker Newshttps://www.aikido.dev/blog/introducing-code-audit-find-complex-vulnerabilities-hidden-in-your-codebase↗

Summary

Aikido has launched Code Audit, an AI-powered security tool that uses agentic reasoning to identify complex, multi-step vulnerabilities in source code—filling the gap between traditional SAST tools and penetration testing. The product is designed to catch logic-based flaws like IDOR chains, ReDoS patterns, and authorization bypass routes that pattern-matching security scanners cannot detect. Code Audit works entirely on static code without requiring live staging environments, making it applicable to web apps, mobile apps, smart contracts, and legacy codebases alike.

According to Aikido, the tool covers approximately 70-80% of what a full penetration test surfaces at roughly 10x lower cost. Early users have discovered a median of ~25 security issues per codebase, with every audit finding at least one vulnerability. Each finding includes root cause analysis, code-based evidence, and an AutoFix feature that automatically generates pull requests to remediate issues. The timing of the release comes amid growing concerns about increasingly capable AI models being leveraged by attackers to discover and chain exploits automatically.

  • Applicable across web apps, mobile apps, smart contracts, and legacy languages with thin SAST coverage; includes AutoFix capability for instant remediation

Editorial Opinion

Code Audit represents a shrewd defensive application of agentic AI at a critical inflection point: as increasingly capable models become available to attackers through jailbreaks and open-source releases, organizations need equivalent capability on the defense side. By automating the discovery of logic-based vulnerabilities that humans struggle to find systematically, Aikido is addressing a genuine gap in the security tooling landscape. This could prove transformative for teams managing complex codebases where pentests are infrequent and SAST tools are inherently limited.

Large Language Models (LLMs)AI AgentsCybersecurityAI Safety & Alignment

More from Aikido

AikidoAikido
RESEARCH

Invisible Unicode Supply-Chain Attack Floods GitHub and NPM with AI-Generated Malicious Packages

2026-03-16
AikidoAikido
INDUSTRY REPORT

Researchers Uncover Supply-Chain Attack Using Invisible Unicode Code to Bypass Security Defenses

2026-03-14
AikidoAikido
PRODUCT LAUNCH

Gitleaks Creator Launches Betterleaks, Next-Generation Open-Source Secrets Scanner

2026-03-12

Comments

Suggested

AnthropicAnthropic
FUNDING & BUSINESS

Nobel Prize-Winning AlphaFold Pioneer Departs Google DeepMind for Anthropic

2026-06-20
Google / AlphabetGoogle / Alphabet
RESEARCH

Google Automates Model Design for Edge AI, Achieving 45× Speed Improvements on Microcontrollers

2026-06-19
GoDaddyGoDaddy
OPEN SOURCE

Major AI Companies Announce Agentic Resource Discovery Specification (ARD)

2026-06-19
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us