Trail of Bits

Trail of Bits is a security research and consulting firm performing software, blockchain/smart-contract, and AI/ML security reviews, publishing findings openly, and maintaining 100+ open-source tools including Slither, Echidna, and Manticore.

Visit official website

Published Updated

CategoryVulnerability Management
AccessSee vendor
PricingContact sales
APISee vendor
Overview

What is Trail of Bits?

Trail of Bits is a security research and consulting firm founded in 2012 and headquartered in New York City. It performs software assurance reviews, blockchain and smart-contract audits, cryptography consulting, and AI/ML security evaluations, and publishes much of its research and tooling openly rather than keeping it proprietary. The company maintains more than 100 open-source security tools, including Slither and Echidna for smart-contract analysis and Manticore for symbolic execution.

Read the full overview

Sources checked 27 September 2026: official website, GitHub, blog.

Why teams use it

Key capabilities

  • Security audits: Software, blockchain/smart-contract, and cryptography reviews.
  • AI/ML security: Evaluation of machine-learning systems and pipelines.
  • Open-source tools: Slither, Echidna, Manticore and other tools usable independently of a paid engagement.
Core areas

Core areas are blockchain/smart-contract security, software assurance, cryptography, and publish-first security research.

Positioning

Shortlist Trail of Bits for scoped security audits (especially blockchain/smart-contract and cryptography work) or when you want to adopt its open-source analysis tools directly. Engagements are quoted individually - there is no public price list.

Why it matters

Because many of its tools are free and open source, teams can evaluate Trail of Bits' methodology on their own code before committing to a paid audit engagement.

Deployment & technical details

Technical details

Access
See vendor
Source model
Other license
Founded
2012
Headquarters
New York, USA
Pricing model
Contact sales
API
Not specified
Check with the publisher

Official resources

Before you shortlist

What to verify for your environment

Start from the users, systems and operating responsibilities the tool needs to support.

  • Confirm current features, licensing and support terms with the publisher.
  • Validate deployment, data location, access control, backup and recovery requirements.
  • Test integrations, export paths and a representative operational workflow before committing.
Community experience

Reviews of Trail of Bits

No published reviews yet.

Loading review form…