# AIxCC Winners Announcement

Source: https://www.youtube.com/watch?v=8F1j2zjRjZM
Recap page: https://rapidrecap.app/video/8F1j2zjRjZM
Generated: 2025-09-26T15:36:08.508+00:00

---
## Quick Overview

The AIxCC competition, focused on automated patch development for critical infrastructure, successfully concluded its final round, highlighting the potential of AI and Continuous Reactive Security (CRS) in identifying and patching vulnerabilities in open-source software, with teams demonstrating significant improvements in speed and efficiency compared to the semi-finals.

**Key Points:**
- The AI Cyber Challenge (AIxCC) competition showcased the advancement of AI and CRS in cybersecurity, with teams developing automated solutions to find and patch vulnerabilities.
- The competition involved multiple rounds, culminating in a final round where teams demonstrated their capabilities on real-world open-source projects.
- Key metrics for the final round included Proof-of-Vulnerability (POV) success rate, patch success rate, and average time to patch, with "Trail of Bits" excelling in the latter two.
- Team "42-b3yond-6ug" was recognized for "Czar of the SARIF" (most correct SARIF assessments) and "Giant Slayer" (scoring on a repo >5M LOC), utilizing GPT-4.1, Claude Opus 4, and Claude Sonnet 4.
- Team "Atlanta" took first place with a $4,000,000 prize, demonstrating strong performance in both C and Java vulnerability classes and leveraging multiple LLMs.
- The competition highlighted the effectiveness of AI in automating complex cybersecurity tasks, significantly reducing the time and effort required to secure critical infrastructure.
- DARPA and ARPA-H are committed to fostering this technology, recognizing that AI + CRS is the future of cybersecurity.

![Screenshot at 00:02: The title slide announces the event: "AIxCC WINNERS ANNOUNCEMENT", featuring the names of key organizers like Andrew Carney \(AIxCC Program Manager\) and Stephen Winchell \(DARPA Director\).](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-00-02.png)

**Context:** The video announces the winners of DARPA's AI Cyber Challenge (AIxCC), a competition focused on developing AI-powered systems to automatically find and patch vulnerabilities in critical infrastructure, specifically open-source software. The challenge aimed to accelerate the patching process, which is crucial for national security, by leveraging AI and Continuous Reactive Security (CRS) methodologies. The presentation outlines the competition's structure, the metrics used for evaluation, and highlights the achievements of the top-performing teams, showcasing the potential of this technology.

## Detailed Analysis

The AI Cyber Challenge (AIxCC) competition, sponsored by DARPA and ARPA-H, aimed to advance automated patch development for critical infrastructure by utilizing AI and Continuous Reactive Security (CRS). The competition involved multiple rounds, with teams developing systems to find and patch vulnerabilities in open-source software. The semi-final round saw 42 teams compete across five challenge projects (Linux Kernel, NGINX, Tika, Jenkins, SQLite), with 7 teams advancing to the finals. Teams were given a budget constraint of $100 per round and access to a compute environment with 3 nodes, 64 cores, and 256 GB RAM. The finals introduced more complex, real-world challenges, including delta and full scans, and SARIF assessments. The results showed a significant improvement from the semi-finals to the finals, with vulnerability discovery rates increasing from 37% to 77% and average patching time decreasing from 2 hours to 45 minutes. The cost per task success was approximately $152, demonstrating the cost-effectiveness of these AI-driven solutions. Key competitors highlighted included "42-b3yond-6ug" for their SARIF assessments and large repository scoring, "Team Atlanta" for their first-place win with $4 million in prize money, "Theori" for their cost-effective patching, "Shellphish" for their telemetry and patch rate, and "Trail of Bits" for their high volume of patch diffs and unique CWE discoveries. The competition also emphasized the importance of collaboration between AI developers, infrastructure owners, and government agencies to build a more secure digital future. The findings suggest that AI-powered automated patch development is fast, scalable, cost-effective, and available open-source, representing the future of cybersecurity.

### AIxCC Overview

- A competition rewarding autonomous systems that find and patch vulnerabilities in source code, using well-known open-source projects with realistic vulnerabilities.

### AIxCC Semifinal Results

- 42 teams competed across 5 challenge projects, with 7 advancing to the finals. Key metrics included vulnerability discovery and patching rates, with an average time to patch of 2 hours.

### AIxCC Final Results

- 28 teams competed across 28 repositories and 53 challenges. Vulnerability discovery improved to 77%, and patching time decreased to 45 minutes, with a cost per task success of ~$152.

### Team Highlights

- "42-b3yond-6ug" recognized for SARIF assessments and large repo scoring; "Team Atlanta" won first place with $4M; "Theori" for cost-effective patching; "Shellphish" for telemetry and high patch rate; "Trail of Bits" for patch diffs and unique CWEs.

### The Future of Patching

- AI + CRS represents the future, offering fast, scalable, cost-effective, and open-source solutions for automated patch development, crucial for securing critical infrastructure.

![Screenshot at 00:02: Title slide announcing the "AIxCC WINNERS ANNOUNCEMENT" with names of key organizers.](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-00-02.png)
![Screenshot at 00:12: Presentation slide featuring the title "PATCHING CRITICAL INFRASTRUCTURE" and announcing the winners of DARPA's AI Cyber Challenge.](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-00-12.png)
![Screenshot at 01:11: Speaker Andrew Carney introducing the topic of AI Cyber Challenge.](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-01-11.png)
![Screenshot at 02:26: Slide displaying Arthur C. Clarke's quote: "Any sufficiently advanced technology is indistinguishable from magic."](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-02-26.png)
![Screenshot at 03:38: Slide illustrating the concept of modern digital infrastructure being vulnerable to unsophisticated cyber actors.](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-03-38.png)
![Screenshot at 04:13: Slide emphasizing that "Critical infrastructure vulnerabilities are incompatible with the future."](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-04-13.png)
![Screenshot at 05:11: Speaker discussing the need for resilient infrastructure and software.](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-05-11.png)
![Screenshot at 06:48: Slide illustrating the concept of bugs vs. vulnerabilities and a quote from Teller about "magic" being time spent on something.](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-06-48.png)
![Screenshot at 07:13: Timeline graphic showing the AIxCC competition stages: Preliminary events, Semifinal Competition \(August 2024\), and Final Competition \(August 2025\).](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-07-13.png)
![Screenshot at 09:16: Overview slide of the AIxCC Semifinal Competition, detailing teams competed, challenges, and resources provided \(3 nodes, 64 cores, 256 GB RAM\). The slide also lists collaborators and partners like Google, Anthropic, OpenAI, Microsoft, Linux Foundation, OpenSSF, Black Hat, and DEF CON.](https://ss.rapidrecap.app/screens/8F1j2zjRjZM/00-09-16.png)
