product
DARPA AI Cyber Challenge (AIxCC)
Also known as AIxCC, AI Cyber Challenge
The AI Cyber Challenge (AIxCC) was a two-year DARPA competition, run with ARPA-H and frontier AI labs, to build autonomous AI "cyber reasoning systems" that find and fix vulnerabilities in open-source software.[1][2] At the August 2025 final, Team Atlanta won; the finalists' systems found 54 synthetic vulnerabilities, patched 43 and discovered 18 real ones, and were released as open source.[1][3][4]
Key facts
What it was
The AI Cyber Challenge (AIxCC) was a two-year competition run by DARPA, the US defense research agency. Partners included the Advanced Research Projects Agency for Health (ARPA-H) and frontier AI labs.[1][2] Teams built “cyber reasoning systems”, autonomous AI pipelines meant to find vulnerabilities in open-source software that critical infrastructure depends on, prove them and generate patches.[2]
Results
DARPA announced the final results on 8 August 2025. Team Atlanta won, Trail of Bits came second and Theori third.[1] Team Atlanta comprises experts from Georgia Tech, Samsung Research, KAIST and POSTECH.[5] DARPA said the top three would receive $4 million, $3 million and $1.5 million.[6]
In the final round the systems faced 63 challenges built from real software with planted vulnerabilities. Together they found 54 of those synthetic vulnerabilities and patched 43. They also found 18 real, previously unknown vulnerabilities, which were reported to the maintainers.[3] Teams analyzed more than 54 million lines of code, submitted patches in an average of 45 minutes and spent about $152 per competition task.[7] DARPA said the systems would be released as open source.[4]
Why it matters
AIxCC was a public, scored benchmark for automated vulnerability discovery and repair at the scale of real codebases.[3] It sits within a wider shift. In 2024 Google’s Big Sleep agent found an exploitable memory-safety bug in SQLite; Google called it the first public example of an AI agent doing so in widely used software.[8] In April 2026 Anthropic said its unreleased model, claude-mythos Preview, had found thousands of high-severity vulnerabilities, including some in every major operating system and browser.[9]
The same capability can serve attackers. Anthropic reported in November 2025 that its Claude Code tool had been misused for an espionage campaign in which AI did most of the work.[10] Whether AI favours defenders or attackers is discussed in AI and cybersecurity debate.
Progress and support
The systems improved sharply over a year. DARPA said teams identified 86% of the synthetic vulnerabilities in the final, up from 37% at the August 2024 semifinal. They patched 68% of those they identified, up from 25%.[11] Of the 18 real vulnerabilities found in the final, six were in C codebases and 12 in Java codebases. Teams also supplied 11 patches for real vulnerabilities.[12] Scoring rewarded fast patches and good analysis of bug reports, not just finding bugs. Every finalist team found at least one real-world vulnerability, and four teams produced patches only one line long.[13] Because the challenges were built from real software, the systems could also stumble on flaws nobody had planted.[3]
Frontier AI companies supported the competition. anthropic, Google and openai each donated $350,000 in large-language-model credits for the final, $50,000 per team, and Microsoft provided Azure credits for the semifinal.[14] On results day DARPA released four of the seven finalists’ systems as open source. DARPA and ARPA-H also added $1.4 million in prizes for teams to integrate the technology into real software used in critical infrastructure.[15]
Questions readers ask
Who won the AI Cyber Challenge?
Team Atlanta, made up of experts from Georgia Tech, Samsung Research, KAIST and POSTECH. Trail of Bits came second and Theori third.[1][5]
Did the AI systems find real bugs?
Yes. Besides the synthetic vulnerabilities planted for the contest, finalists discovered 18 real vulnerabilities, which were responsibly disclosed to open-source maintainers.[3]
Can anyone use the AIxCC systems?
DARPA said the finalists' systems were being made available as open source for broad adoption.[4]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
On 8 August 2025 DARPA named Team Atlanta, with members from Georgia Tech, Samsung Research, KAIST and POSTECH, the winner of its two-year AI Cyber Challenge, with Trail of Bits second and Theori third. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [2]
AIxCC was run by DARPA in collaboration with ARPA-H and frontier AI labs, to test autonomous AI systems that secure open-source software underlying critical infrastructure. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [3]
In the AIxCC final, competing systems found 54 of the synthetic vulnerabilities across 63 challenges, patched 43 of them, and also discovered 18 real, non-synthetic vulnerabilities. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [4]
DARPA said the finalists' AI systems were being made available as open source for broad adoption. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [5]
Team Atlanta comprises experts from Georgia Tech, Samsung Research, KAIST and POSTECH. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [6]
DARPA said the top three AIxCC teams, Team Atlanta, Trail of Bits and Theori, would receive $4 million, $3 million and $1.5 million respectively. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [7]
AIxCC finalists analyzed more than 54 million lines of code, submitted patches in an average of 45 minutes and spent about $152 per competition task. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [8]
In November 2024 Google's Big Sleep AI agent was reported to have found a previously unknown exploitable memory-safety bug in SQLite, which Google called the first public example of an AI agent doing so in widely used real-world software. confirmedas of 2024-11-01
- From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code · Google Project Zero · 2024-11-01 (retrieved 2026-10-10)
- [9]
Anthropic said Claude Mythos Preview had found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. confirmedas of 2026-04-07
- Project Glasswing: Securing critical software for the AI era · Anthropic · 2026-04-07 (retrieved 2026-10-10)
- [10]
Anthropic said the AI performed 80-90% of that campaign, with humans intervening at perhaps 4-6 critical decision points, and called it the first documented large-scale cyberattack executed without substantial human intervention. confirmedas of 2025-11-13
- Disrupting an AI-orchestrated cyber espionage campaign · Anthropic · 2025-11-13 (retrieved 2026-10-10)
- Disrupting an AI-orchestrated cyber espionage campaign · Anthropic · 2025-11-13 (retrieved 2026-10-10)
- [11]
DARPA said AIxCC teams identified 86% of the synthetic vulnerabilities in the final, up from 37% at the August 2024 semifinal, and patched 68% of those identified, up from 25%. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [12]
Of the 18 real vulnerabilities found in the AIxCC final, six were in C codebases and 12 in Java codebases, and teams also provided 11 patches for real vulnerabilities. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [13]
DARPA said AIxCC scoring rewarded creating patches quickly and analysing bug reports, that every finalist team identified a real-world vulnerability, and that four teams produced one-line patches. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 · Key competition highlights list (retrieved 2026-10-10)
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 · Key competition highlights list (retrieved 2026-10-10)
- [14]
Anthropic, Google and OpenAI each donated $350,000 in large-language-model credits for the AIxCC final, $50,000 per team, and Microsoft provided Azure credits for the semifinal. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [15]
DARPA released four of the seven finalists' systems as open source on results day, and DARPA and ARPA-H added $1.4 million in prizes for teams to integrate the technology into real critical-infrastructure software. confirmedas of 2025-08-08
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- AI Cyber Challenge marks pivotal inflection point for cyber defense · DARPA · 2025-08-08 (retrieved 2026-10-10)
- [16]
On 7 April 2026 Anthropic announced Project Glasswing with partners including AWS, Apple, Cisco, CrowdStrike, Google, Microsoft and the Linux Foundation, to use its unreleased Claude Mythos Preview model to find and fix vulnerabilities in critical software. confirmedas of 2026-04-07
- Project Glasswing: Securing critical software for the AI era · Anthropic · 2026-04-07 (retrieved 2026-10-10)
Revision history (2)
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"DARPA AI Cyber Challenge (AIxCC)." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/darpa-ai-cyber-challenge
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- AnalysisDoes AI help cyber attackers or defenders more?AI now finds and exploits software flaws. Evidence from DARPA's AIxCC, Google's Big Sleep, Anthropic's Mythos and a reported AI-run espionage campaign.
- ExplainerPost-quantum cryptography and security in 2026: a crash courseA sourced crash course on post-quantum cryptography: the quantum threat, NIST's new standards, deployment, migration deadlines and AI in security.
- WikiClaude MythosClaude Mythos is Anthropic's most capable model class, first released as a gated preview for cyber defence and later as Claude Fable.
- WikiCrypto-agilityCrypto-agility is the ability to replace cryptographic algorithms without rebuilding systems. Why the post-quantum transition made it a priority.
- WikiNIST Post-Quantum Cryptography projectNIST's open, multi-year competition that produced the ML-KEM, ML-DSA and SLH-DSA standards, plus HQC, FN-DSA and the work still in progress.
- DevelopingPost-quantum cryptography and security trackerA dated, sourced timeline of post-quantum cryptography and AI security milestones: NIST standards, deployment, government deadlines, 2024-2026.