> Then why did you just mention the setup number? To make it clear to you that I'm not just giving Kimi K3 path to the code and telling it, "hey, bitch, gind me some issue/vulnerabilities". > Hopefully, the output code can actually prove that the flaw can be used in production to exploit the host. That’s the end goal. After I found the issues, my next step was to manually verify them using an Android emulator. And only after I verified them manually, and only then I made a report and sent it to the devs. And yes, I told all the developers that I'm not a "false prophet" or a cybersecurity guru, but simply a FOSS enthusiast who uses their product — which is why I decided to check their code. And yes, the devs verified my findings.

Replies (1)

Thank you for that work. But that's not what I am taking about. If it's a real flaw, the AI must prove it can abuse it and must successfully do so in world word wallets, with real phones and so on.. otherwise, it's too easy for the AI to simulate a fictional environment with weak security and prove itself without doing the actual work which is where you will find the unseen bugs.