Buttercup AI Cyber Reasoning System logo and branding header

Stay up to date with Buttercup

πŸ› 28 Vulnerabilities Found
πŸš€ 19 Successful Patches Deployed
🌟 219 Total Score
⚑ Open Source Now Available

πŸ† Trail of Bits Wins Second Place!

We're thrilled to announce that Trail of Bits won second place in DARPA's AI Cyber Challenge at DEF CON 33! Download our presentations to learn about Buttercup's journey and our experience competing in this groundbreaking challenge.

πŸ“„

Buttercup: Building an AI Cyber Reasoning System

About Buttercup and our Approach

πŸ“„

DARPA's Main Stage Presentation

Competition format and outcome summary

Buttercup system architecture diagram showing AI-driven vulnerability detection components

AI-driven Cyber Reasoning System

πŸŽ‰ Now open source and available on GitHub!

Buttercup is an AI Cyber Reasoning System (CRS) developed by Trail of Bits. Now that DARPA's AI Cyber Challenge (AIxCC) has officially concluded, we've made Buttercup open source! Our fully automated, AI-driven system for discovering and patching vulnerabilities in open-source software is now available for the entire security community to use, extend, and benefit from.

Buttercup Features

Adaptive vulnerability discovery

Extensive validation of bugs

AI-driven patching

Fully autonomous system

Scalable architecture

Language versatility

AIxCC Timeline

Select a milestone to learn more

Click on any bullet point above to explore the details of that milestone in our journey.

AIxCC Competition Insights

Hear from experts about DARPA's AI Grand Cyber Challenge, autonomous vulnerability detection systems, and the future of AI-driven cybersecurity

Edera webinar - Hardening the Code: A Q&A on AI-Powered Security with Trail of Bits

Hardening the Code: A Q&A on AI-Powered Security with Trail of Bits

Originally aired: Sep 11, 2025 12:00 PM ET

The AI Cyber Challenge (AIxCC) spotlighted the potential of AI in cybersecurity. Discover what it takes to move from competition to real-world impact. Watch this recorded Q&A with Edera's Dan FernΓ‘ndez and Trail of Bits' Michael Brown covering AI-driven vulnerability management, agent design, and deploying secure AI systems at scale.

Watch Recording
Buttercup and DARPA's AI Cyber Challenge - Henrik Brodin, Ronald Eytchison

Upcoming Conference Talk

Henrik Brodin, Ronald Eytchison
Date: November 7, 2025
Conference: RingZer0 COUNTERMEASURE - Ottawa

Trail of Bits' Buttercup secured $3 million in DARPA's AI Cyber Challenge, autonomously finding 28 vulnerabilities across 20 CWE categories and patching them with high accuracy. We'll show how our open-source system discovers and patches real vulnerabilities using static analysis and AI-guided fuzzing.

You'll see our multi-agent architecture in action, learn the design principles that enabled Buttercup to go beyond the AIxCC competition, and discover what we learned about when AI helps versus hurts. From laptop deployments to enterprise Kubernetes environments, we'll show how Buttercup makes world-class automated vulnerability discovery and patching accessible to everyone.

Learn More About This Talk

Meet the Trail of Bits Buttercup Team

Group photo of the Trail of Bits Buttercup development team at their office

Tap any name to learn more about their role

Michael Brown
Ian Smith
Evan Downing
Eric Kilmer
Riccardo Schirone
Francesco Bertolaccini
Ronald Eytchison
Henrik Brodin
Brad Swain
Boyan Milanov
Alessandro Gario