Skip to content
Book a call Start a run

V12 is your security agent for mission critical code. Start with $100 in free credits.

Open app
The V12 command-line tool and web app running side by side on a movable desktop. A run on kestrel/streams finishes, its three findings arrive in the findings list, and the critical one opens to show the vulnerable code, a proof of concept that reproduces it, and V12's fix.

Drag this title bar to move its window. With the title bar focused, use the arrow keys to move, Shift plus an arrow key to move farther, and Home to reset its position. On narrow screens, the windows move vertically while their fixed left rails stay anchored.

v12.sh/findings

The V12 CLI starts a run on kestrel/streams and watches it complete with three findings. It saves the critical finding's proof of concept as a test, runs it with cargo to confirm the bug reproduces, and prints V12's proposed fix.

V12 CLI

Securing the code behind systems that cannot afford to fail.

We meet you where you work.

Every pull request gets a security review. Findings land beside the code, ready for your team to review.

Connect GitHub
MC
maya-chen commented 2 minutes ago

@v12sec please review the frontend & db surface

v12sec Bot commented just now, edited
Finding Severity Details
F-82768 Critical
Removed status guard enables replayable refund drain

Analyzed twelve files, diff 4f29a17...8bc320e.

Chat with V12 like it’s your security engineer. Ask it anything about the repo, and trigger a run for what actually matters.

Connect Slack

Your coding agent knows how to use V12. Audit the code, pull the findings, and patch themβ€”in one session.

Configure MCP

β€Ί Review V12 run 42.

β€’Called

β””v12.v12_findings({"runUid":42,

"severity":["critical","high"]})

3 of 3 findings.

β€’Run 42 complete β€” 1 critical, 2 high

UID 4 critical valid contracts/Vault.sol:41

Reentrancy permits complete vault drain

UID 9 high valid contracts/OracleAdapter.sol:88

Oracle price can be manipulated within one block

UID 11 high unreviewed contracts/WithdrawalAuthorizer.sol:126

Signature replay bypasses withdrawal limits

β€’UID 11 is unreviewed. Mark it valid, invalid, or acknowledged?

I can also change severity or add a note β€” after you confirm.

The entire audit lifecycle lives in your terminal. Quote, review, triage, fix, all from one binary.

Install CLI

$ v12 runs create \ --name "Treasury v4 audit" \ --repo acme/treasury --branch main

Scope: acme/treasury @ main

12 files2,841 LOC

Pricing input: 125,004 bytes

FILE BYTES LOC

AccessManager.sol 13,992 318

LiquidityPool.sol 26,488 602

… 10 more 84,524 1,921

Price $77.38, charged at start

Create this run? [y/N] y

βœ“ Run 42 created, queued

Audit your next PR, automatically.

V12 finds bugs in software you already run. Recent disclosures from V12 research include Signal, QEMU, PostgreSQL, and the Linux kernel.

Browse the disclosures
V12 @v12sec

today we are releasing a qemu escape

24 257 1.8K 330K 639
V12 @v12sec

Type text into Wikipedia. Get the shell's output back on the page.

A bug introduced 22 years ago.

Still alive in the wild, until it was found by V12.

Here's how EasyTimeline allowed arbitrary code execution (RCE) directly from wikitext.

9 86 662 122K 239
V12 @v12sec

AnyPwn: AnyDesk preauth 0click RCE (heap buffer overflow)

we will release PoC post disclosure and patch

29 235 1.6K 132K 775
V12 @v12sec

user β†’ root privesc 0-day in CUPS

a free PoC while we wait for some bigger disclosures to go through πŸ˜‡

9 71 539 43K 248
V12 @v12sec

🐬🐬🐬 dolphin rce 🐬🐬🐬

41 104 2.2K 206K 379
V12 @v12sec

Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud.

V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything.

Two separate critical bugs: arbitrary read and RCE.

Here's how. 🧡

17 146 722 136K 343
V12 @v12sec

another day, another universal linux LPE

40 329 2.5K 542K 1K
V12 @v12sec

Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page.

This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps.

PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance...

Breakdown and POC. 🧡

5 55 332 47K 235
V12 @v12sec

And here's postgres bidirectional RCE

no admin required, client infects server, server infects client β™»οΈπŸ›

12 120 938 186K 474
V12 @v12sec

Stick around on our web page for 10 minutes and all your funds are gone.

Just connect your wallet to the dApp and enjoy some Temple Run. Unlock your wallet again and it’s empty πŸ˜‡.

A silent signature extraction in @Rabby_io, leading to a full wallet drain. 🧡

42 131 967 320K 508
V12 @v12sec

Arbitrum Nitro normally runs natively, but disputes rely on fraud proofs run in a WASM VM.

If these two environments don't fully agree, it can get ugly… like β€œL1 bridge funds ($2.8B) can be extracted” ugly.

Here's how V12 uncovered two independent mismatches, autonomously.

5 12 113 12K 54
V12 @v12sec

found another one! redis 8.8.0 bidirectional RCE

we will release poc after the patch

19 104 801 226K 344
V12 @v12sec

unauthenticated root RCE on TerraMaster TOS4 NAS appliances. (+free additional LPE)

something light for sunday. bigger stuff this week! :-)

8 58 433 106K 153
V12 @v12sec

here's a mariadb RCE, what should we look at next?

13 45 396 72K 130
V12 @v12sec

we consistently find bugs human auditors miss

in this review for the Ethereum Foundation, we reported a unique High-severity bug. it stems from missing input validation

us and the human auditors found the same set of crits

3 3 63 13K 23

Every change gets reviewed before it reaches production. Autopilot audits every change as soon as it lands.

Set up Autopilot

2 Steers attached, one run

  • πŸ” Kill-switch fencing Complete2h
  • πŸ“’ Clock domains & epochs
  • Attach a Steer

2 Steers attached, one run

  • πŸͺͺ Session and identity Complete40m
  • πŸ“ Spec conformance
  • Attach a Steer

2 Steers attached, one run

  • πŸ” Signing and key custody Complete6h
  • πŸ” Retry and replay semantics
  • Attach a Steer

Tune the engine in your own words. A Steer is a short note on what reviews should look for. Point at past findings, runs and files, drop in a spec, then attach it to runs and Autopilot rules.

Write a Steer

What teams say about V12.

β€œWe had our cryptography library audited by V12 alongside a human auditor. V12 caught every critical bug the human found and surfaced several issues the human missed. For a team our size, an independent review at this depth with both cryptographic and engineering insights was invaluable.”

Winderica Ethereum Foundation

β€œV12 has given us greater confidence throughout our Solana smart contract audit process. It consistently catches issues that are easy for humans to overlook, helping us identify potential vulnerabilities earlier and focus more of our time on validating complex attack scenarios. It’s become a valuable addition to our security workflow.”

sudoku Meteora

β€œV12 found a critical soundness bug that had been lurking in our ZK code for over a year. Human expert auditors missed it. Since then, we’ve made V12 a central part of a security strategy. Better and cheaper than most human experts.”

Yuvi Lightman Quantus

β€œV12 has been great at spotting issues and helping us pipeline them into our production process. For Bulk, the biggest value is the loop: find risk, verify it, turn it into a ticket, fix, retest. Excited to see this loop get better every day!”

Jun Bulk Trade

β€œWe write a lot of complex cryptographic code, and security is always top of mind. Having a tool like V12 in our belt has been a huge lift for our security posture. We get detailed code review on complete repositories in hours, giving a boost in confidence for our engineers, researchers, and partners.”

Aaron Feickert Alpen Labs

β€œV12 is fantastic as another set of review eyes for your high velocity team. When fixing legacy code, it points out all the other ways it was already broken for you.”

Dev Ojha ZCash

Get started with V12.

Open app