Trail of Bits
Trail of Bits is a privately held cybersecurity research and auditing firm founded in 2012 that delivers multi-disciplinary security reviews across AI/ML, blockchain, cryptography, and application security to enterprise clients including major Web3 protocols and technology companies.
- Company typePrivate
- Founded2012
- HeadquartersNew York, United States
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Trail of Bits does
Trail of Bits is a privately held cybersecurity research and auditing firm founded in 2012 and headquartered in New York with an additional office in San Francisco. The company delivers multi-disciplinary security reviews spanning the software development lifecycle across six service lines: AI/ML security, application security, blockchain, cryptography, security engineering, and research and development. Its client base is concentrated in blockchain and Web3 — including Offchain Labs/Arbitrum, Uniswap, Aave, Scroll, Optimism, Solana, StarkWare, Chainlink, DFINITY, Ripple, Franklin Templeton, and Gensyn — with additional engagements in mainstream technology such as Meta/WhatsApp Private Processing, Discord's DAVE end-to-end encryption protocol, OpenSSL, Homebrew, and PyPI. Pricing is quote-based and benchmarked at approximately $25,000 per engineer-week, with engagement durations ranging from 0.2 weeks for focused reviews to 47 weeks for comprehensive system audits.
The firm's technology stack is anchored by proprietary open-source tools widely adopted across the blockchain security ecosystem: Slither (static analysis for Solidity and Vyper with 6.3k GitHub stars and 1.1k forks), Echidna (property-based fuzzing for Ethereum smart contracts), Medusa (smart contract testing), and mquire (Linux memory forensics). In 2026 the company has pivoted toward an AI-native operational model, launching Trailmark (an AI-augmented audit framework), a Skills Platform of 74 specialized AI capabilities, and Buttercup — an autonomous bug-finding and fixing system developed for DARPA's AI Cyber Challenge. The company maintains a public library of 620 audit reports and 946 publications as core go-to-market assets and is an initial recipient of OpenAI's Trusted Access for Cyber program alongside the Patch the Planet open-source security initiative co-founded with OpenAI, HackerOne, and Calif.
Trail of Bits is structured as a closely held LLC with no disclosed external funding rounds, suggesting founder-led, cash-flow-funded operations. Ownership commentary identifies Dan Guido (CEO) and Alexander Sotirov (CTO) as co-founders, with operational leadership including a Head of Product and Financial Controller. The go-to-market motion is a hybrid of enterprise field sales (custom-scoped engagements initiated through direct client contact) and community-led demand generation (open-source tools and public research serving as lead-generation assets). The company positions itself as a top-tier, expertise-led auditor rather than a volume player, monetizing deep specialization in blockchain, cryptography, and AI/ML security through premium engineer-week pricing.
Trail of Bits firmographics
Firmographics- Name
- Trail of Bits
- Legal name
- Trail of Bits LLC
- Website
- https://trailofbits.com
- Company type
- Private
- Founded year
- 2012
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Trail of Bits is a privately held cybersecurity research and auditing firm founded in 2012 that delivers multi-disciplinary security reviews across AI/ML, blockchain, cryptography, and application security to enterprise clients including major Web3 protocols and technology companies.
- Ownership category
- akta.pro rank
Trail of Bits industry classification
Industry- Product category
- Cybersecurity Services and Security Research
- NAICS
- Investigation and Security Services (5616), Security Systems Services (56162)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Smart Contract Security Tooling (static/dynamic analysis, formal verification) (FSAPABAI)
- akta.pro secondary industries
- Security Testing Tooling (SAST/DAST for smart contracts, fuzzing) (FSAPAJAK), Smart Contract Developer Platforms & Tooling (SDKs, APIs, frameworks, indexing) (FSAPAAAH), Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where Trail of Bits is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Trail of Bits business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Security Auditing Services: Professional security review engagements where Trail of Bits performs multi-disciplinary security assessments across the software development lifecycle. Engagements range from short 0.2-week reviews to extensive 47-week comprehensive audits. Pricing typically quoted per engineer-week, with top-tier engagements charging approximately $25,000 per engineer-week.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Enterprise Security Audits |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels5 records
Trail of Bits product offering
Product offeringCore offering
Trail of Bits delivers multi-disciplinary security review engagements spanning AI/ML security, blockchain/smart contract audits, cryptography, application security, security engineering, and research & development. Engagements are scoped per engineer-week against a client's threat model and supported by proprietary open-source tools (Slither, Echidna, Medusa, mquire) and an AI-augmented audit framework (Trailmark). The firm also co-runs the Patch the Planet initiative with OpenAI to secure critical open-source software.
Product overview
Trail of Bits is a security research firm offering a comprehensive portfolio of security auditing services and open-source security tools. Their core offerings include multi-disciplinary security reviews across AI/ML, blockchain, cryptography, and application security domains, supported by proprietary tools including Slither (static analysis for Solidity/Vyper), Echidna (smart contract fuzzing), and Medusa (blockchain testing). The company has developed an AI-native operational model integrating AI throughout their security workflows, offering AI-augmented auditing through their Trailmark framework and specialized skills platform for tasks like Solana vulnerability scanning and agentic action auditing. Their Patch the Planet initiative, developed in partnership with OpenAI, represents their most significant AI-powered program, combining AI-assisted vulnerability research with human expert review to secure open-source software. Trail of Bits publishes extensive documentation and guides including ZKDocs for zero-knowledge proofs, testing handbooks, and educational materials, serving clients across blockchain, DeFi, and enterprise sectors.
Differentiator
Problem solved
Functional benefit
Brands
- Slither: Static analysis tool for Solidity and Vyper with built-in detectors and an API for custom checks, with 6.3k stars and 1.1k forks on GitHub.
- Echidna
- Medusa
Products and services
- Multi-disciplinary security review services (Software Assurance) Paid professional security review engagements scoped per engineer-week against a client's threat model. Practice areas include AI/ML Security, Blockchain, Cryptography, Application Security, Security Engineering, and Research & Development. Engagements have historically ranged from 0.2 to 47 weeks, with top-tier audits quoted at approximately $25,000 per engineer-week. Sold to enterprise clients in blockchain, Web3, AI/ML, and broader technology sectors.
- Patch the Planet initiative Open-source security initiative co-developed with OpenAI (Daybreak program) and partnering with HackerOne and Calif. Combines AI-assisted vulnerability research with human expert review to help maintainers of critical open-source projects (cURL, Python, Go, Sigstore, pyca/cryptography) identify and fix security vulnerabilities, develop patches and tests, and create reusable security workflows. Open-source projects apply via a dedicated program page.
- Slither Open-source static analysis framework for Solidity and Vyper smart contracts with built-in detectors and a Python API for custom checks. Used by Trail of Bits' blockchain auditors and the wider Ethereum developer community (6.3k GitHub stars, 1.1k forks). Sold implicitly as part of paid blockchain audit engagements and available standalone.
- Echidna Open-source property-based fuzzing tool for Ethereum smart contracts, part of the Crytic tool suite. Used alongside Slither and Medusa for comprehensive blockchain security analysis.
- Medusa Open-source fuzzing framework for smart contracts enabling automated vulnerability discovery. Used in combination with Slither and Echidna for blockchain security analysis.
- mquire Open-source Linux memory forensics tool released by Trail of Bits in March 2026. Analyzes memory dumps without requiring external debug symbols by leveraging Kallsyms data and BPF Type Format (BTF) type information, with an interactive SQL interface inspired by osquery. Supports paid application security and reverse engineering engagements.
- Trailmark AI-augmented audit framework and Skills Platform AI-augmented audit framework plus a collection of specialized AI skills (let-fate-decide, solana-vulnerability-scanner, c-review, differential-review, graph-evolution, sharp-edges, agentic-actions-auditor, genotoxic). Used to augment Trail of Bits' paid security review engagements with AI-driven diagramming, structural analysis, summary generation, and vulnerability scanning.
- MuTON and mewt Open-source mutation testing tools for blockchain languages including TON, Solidity, Rust, and others, designed to improve software testing for the agentic era and used by Trail of Bits in paid application and blockchain security engagements.
- Security Engineering and Research & Development engagements Embedded-team engagements in which Trail of Bits builds custom security tooling and remediates vulnerabilities across client pipelines, plus multi-year research programs that uncover Internet-scale vulnerabilities and turn findings into open-source tools, papers, and standards. Sold as multi-year contracts to enterprise and government clients.
- Cryptographic protocol review services Paid design and code review of cryptographic protocols, including zero-knowledge proofs, MPC, and post-quantum migration work, performed by PhD-level cryptographers. Sold to cryptocurrency projects, blockchain protocols, and any organization deploying cryptographic primitives (e.g., Discord DAVE E2E encryption protocol review).
Quantifiable outcome
- 620 public security reports published
- +5 more outcomes
Companies that use Trail of Bits
Customer profileNamed customers17 records
Segments4 records
Ideal customer profiles5 records
Trail of Bits technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability7 records
Feature7 records
Trail of Bits partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered flagship and core.
- OpenAIflagshipTrail of Bits co-founded Patch the Planet initiative with OpenAI as part of the Daybreak cybersecurity program. The partnership combines AI-assisted vulnerability research with human expert review to help open-source maintainers identify and fix security vulnerabilities. Trail of Bits engineers work directly with maintainers using OpenAI's security tools including Codex Security to review findings, develop patches and tests, and create reusable security workflows. Initial focus includes critical open-source projects such as cURL, Python, Go, Sigstore, and pyca/cryptography.
- HackerOnecoreHackerOne collaborates with Trail of Bits on the Patch the Planet initiative to support vulnerability classification and coordinated disclosure for participating open-source projects.
- CalifcoreCalif partners with Trail of Bits on the Patch the Planet initiative, providing security engineering, triage, and coordinated disclosure support for open-source maintainers.
- DiscordcoreTrail of Bits conducted comprehensive security audit of Discord's DAVE (Discord Audio and Video Encryption) protocol, an open-source protocol enabling end-to-end encryption for voice and video calls. The audit included both design review (4 weeks) and code review (5 weeks), with findings contributing to the protocol's March 2026 production deployment.
- OpenAI (Trusted Access for Cyber)flagshipTrail of Bits received access to GPT-5.4-Cyber and API credits through OpenAI's Trusted Access for Cyber program, a $10 million initiative to provide advanced cybersecurity capabilities to defenders. Trail of Bits is among initial recipients alongside Socket, Semgrep, and Calif.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Trail of Bits competitors and assessment
Company assessmentBroad incumbents
- NCC Group: Large global cybersecurity services firm with blockchain and application security practices; overlaps on enterprise application security and crypto advisory work but operates at significantly broader scale and scope.
Direct peers
- CertiK: Large, well-capitalized smart contract and Web3 audit firm using a hybrid expert + formal verification + Skynet monitoring approach; competes for many of the same protocol clients as Trail of Bits.
- OpenZeppelin: Open-source smart contract developer tooling and security audit firm; the closest direct peer given the overlap on Ethereum smart contract reviews, formal verification, and Slither-adjacent tooling like the Defender platform.
- SlowMist: Blockchain security firm covering smart contract audits, on-chain threat intelligence, and incident response; comparable on multi-service crypto security offerings.
- Consensys Diligence: Smart contract security audit arm of Consensys; directly competes for Ethereum protocol and DeFi audit engagements with MythX, Fuzzinglab, and dedicated security researchers.
- ChainSecurity: Blockchain security firm specializing in automated smart contract auditing with formal verification; closely comparable on Ethereum protocol audits and security tooling philosophy.
- Least Authority: Cryptography-focused security audit firm with substantial overlap on Ethereum protocol reviews, ZK systems, and cryptographic implementation work — directly comparable on cryptography services.
- Sigma Prime: Specialist blockchain security firm known for Ethereum 2.0 / consensus-layer reviews; comparable on deep protocol-level audits and open-source contributions (e.g., Lighthouse).
Emerging players
- Zellic: Rapidly scaling smart contract audit firm with strong crypto-native researcher team; competes directly for top-tier protocol engagements and emerging L1/L2 audit mandates.
- Spearbit: Independent security researcher network for smart contract audits; partial overlap on Ethereum/EVM audit delivery, differentiated by an aggregator model rather than full-time staff.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Trail of Bits social profiles
Digital presenceTrail of Bits financial estimates
Financial estimateRevenue estimate
Valuation estimate
Trail of Bits leadership team
Management profileNumber of profiles
Profiles4 records
Trail of Bits funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Trail of Bits M&A and investment
M&A and investmentM&A
Investments1 record
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Trail of Bits
What does Trail of Bits do?
Trail of Bits delivers multi-disciplinary security review engagements spanning AI/ML security, blockchain/smart contract audits, cryptography, application security, security engineering, and research & development. Engagements are scoped per engineer-week against a client's threat model and supported by proprietary open-source tools (Slither, Echidna, Medusa, mquire) and an AI-augmented audit framework (Trailmark). The firm also co-runs the Patch the Planet initiative with OpenAI to secure critical open-source software.
Is Trail of Bits a public or private company?
Trail of Bits is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Trail of Bits founded?
Trail of Bits was founded in 2012. It employs 101 to 250 people.
Where is Trail of Bits based?
Trail of Bits is headquartered in New York, United States, in the North America region.
How does Trail of Bits make money?
One revenue line is on record: security Auditing Services.
Who are Trail of Bits's main competitors?
NCC Group is listed as a broad incumbent. Direct peers are CertiK, OpenZeppelin, SlowMist, Consensys Diligence, ChainSecurity, Least Authority and Sigma Prime. Emerging players are Zellic and Spearbit.
Does Trail of Bits have an API?
Yes. Slither provides a Python API for custom checks, enabling developers to build custom static analysis detectors and integrate Slither's analysis capabilities into their own security tooling and workflows.
What industry is Trail of Bits in?
Trail of Bits's product category is Cybersecurity Services and Security Research. Its primary akta.pro industry code is FSAPABAI, Smart Contract Security Tooling (static/dynamic analysis, formal verification), with a secondary code of FSAPAJAK, Security Testing Tooling (SAST/DAST for smart contracts, fuzzing). Its NAICS code is 5616 and its SIC code is 7371.