Help open up security AI_
A research team first: cryptography, zero-knowledge, offensive security, smart contracts, web vulnerabilities, benchmarks and the harnesses that tie them together — building the open registry, the public bench, and the platform that runs them. New York-based, remote-friendly, written-first. We hire slowly and read everything.
Written first.
Specs, decisions and post-mortems live in the repository. If it isn't written down, it didn't happen.
Remote-friendly, New York-based.
We work across time zones and meet in New York when it helps.
Ship weekly.
Every week something lands and gets a changelog entry.
We run it on real targets.
Everyone runs the product on real work; that is where the roadmap comes from.
Break and fix cryptographic code in the wild, then teach the workflows to find what you found.
ApplyFind soundness bugs in circuits and proof systems, and build the workflows that find them at scale.
ApplyRun the platform against real targets. Validate what it finds. File every miss as a fix.
ApplyOwn the EVM workflows and EVMbench. Find what the audits missed.
ApplyFind bugs in open-source web applications and APIs, disclose them, and turn the patterns into workflows.
ApplyOwn the methodology behind the bench: datasets, contamination checks, scoring, statistics, disputes.
ApplyRun the experiments that decide how workflows and profiles are built.
ApplyAuthor and maintain registry workflows across stacks, own part of the bench, publish what you find.
ApplyOwn the run pipeline: sandboxes, the mirror, credits and billing, the API and CLI.
ApplyWrite the bench reports, work with workflow authors, be the voice of the registry.
ApplyEvery role publishes. Every role runs the product on real targets.
Send a note and something you built or found.
Two conversations, one of them technical, both within a week.
A paid, scoped project on a real problem, then a decision.