DARPA Selects Xint.io to Research Source Code Vulnerabilities in Critical Messaging Applications Used in Military Communications
DARPA Selects Xint.io to Research Source Code Vulnerabilities in Critical Messaging Applications Used in Military Communications
DARPA will use Xint’s proven ability to find critical flaws in source code, runtime, and binaries to test the use of AI to protect the security of military communications across inhouse, open-source, and proprietary messaging applications at scale.
AUSTIN, Texas--(BUSINESS WIRE)--Today Xint announced that the U.S. government’s Defense Advanced Research Projects Agency (DARPA) has selected Xint to research the use of autonomous AI application security to conduct deep security analyses of internally and externally developed messaging applications that are used throughout the Department of War.
As part of its submission, Xint identified in a single, one-hour scan, three uncaught-exception vulnerabilities that caused the Android version of the encrypted messaging application Signal to crash. These bugs were responsibly disclosed to Signal project maintainers and patched in the 8.11 release.
“If you’re the target of state-sponsored hackers, whether you’re the military, a major financial institution, a critical infrastructure provider, or a technology enterprise, you have the highest requirements for application security, especially for keeping communications private,” said Brian Pak, CEO and co-founder of Theori and Xint. “The encryption in a messaging app is the part that gets reviewed. The code around it, everything touching the network, and the operating system, rarely gets the same scrutiny and that's where an attacker goes. We can now check that code cost-effectively enough to do it routinely, with the source code or with only a binary."
“Messaging and communications applications are unique in that an attacker needs read-only access to compromise the entire point of the app,” said Andrew Wesie, CTO and co-founder at Xint. “Third-party SDKs and libraries embedded in these apps can create hidden data risks, where even seemingly minor leaks may expose a user’s location or other personally identifiable information during sensitive communications – often without the user or even the developer knowing. That is why independent attestation is critical.”
Xint and its parent company Theori have over a decade of experience working with commercial and governmental organizations to secure their code and applications. That work most recently culminated with the launch of Project Canopy, a public interest initiative disseminating AI-powered preemptive defense capabilities to organizations ranging from major companies across Asia and Europe to civilian infrastructure and open-source software (which often lacks security budgets).
DARPA and Xint first started working together in 2025 when Xint competed in DARPA’s Artificial Intelligence Cyber Challenge (AIxCC), a two-year, $29.5 million competition bringing together some of the top security researchers in the world. As one of the top performers, Xint continued working with DARPA as part of a bounty program to uncover and remediate vulnerabilities in critical open source software projects.
Through this engagement with DARPA, Xint will use its platform to analyze source code, including code from internally developed messaging apps and open source projects. Xint will also analyze compiled binaries using a new service launched in September 2026. The service is designed to assess software supply chain risk across compile code running in environments such as agents, on-premises software, appliances, network daemons, and other services.
About Xint.io
Xint.io is the award-winning autonomous pentesting platform built by the security researchers at Theori, the most decorated team of white hat offensive security researchers in the world. Xint offers both black-box as well as white-box pentesting with results, on average, in 24 hours or less, including: full trigger conditions and step-by-step reproduction pathing, exploit impacts, and suggested remediations so teams can quickly triage and patch the most critical vulnerabilities. Xint is working with organizations with the highest defensive security needs, including Samsung and Hyundai.
About Theori
Theori is an offensive cybersecurity firm dedicated to solving the industry's most complex security challenges. Founded in 2016 by Carnegie Mellon alumni, our elite team of white hat hackers is trusted by global technology leaders and government agencies, backed by 70+ international hacking competition wins including a record four consecutive DEF CON CTF championships.
The company offers a comprehensive security ecosystem: Xint (AI-powered application security testing), aprism (LLM security guardrail) and offensive security consulting. Certified to ISO/IEC 27001:2022 and ISO/IEC 27017:2015.