Skip to content

Security1 publisher2 min readPublished

DARPA picks AIxCC winner Xint to research AI audits of military messaging apps

DARPA selected Xint, one of three winners of its $29.5 million AIxCC contest, to research AI-driven security analysis of Department of War messaging apps. The work aims its automated find, triage and patch pipeline at messaging code and binaries the military actually runs.

The Watch · Security desk

Illustration accompanying DARPA picks AIxCC winner Xint to research AI audits of military messaging apps

What happened

  • Xint's brief covers source code, both code written in-house by messaging apps such as Signal and code from open source projects.
  • Compiled binaries go through a Xint service launched in September 2026 that assesses supply chain risk in agents, appliances, network daemons and on-premises software.
  • Xint CTO Andrew Wesie said an Android review would cover the messaging app, the Linux kernel and every Android component in between, reverse engineering binaries where needed.
  • DARPA pays for part, but not all, of the technology's development, and Xint keeps it to sell to commercial customers.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Vendors whose SDKs and libraries ship inside Department of War messaging apps become part of the audit, since Wesie names embedded third-party code as a source of location and identity leaks.
  • decision A defense customer that requires source code to stay in-house must, for now, give up Xint's newest-model analysis or relax that rule until the on-premises version ships.
  • capability Binary analysis lets reviewers inspect appliances and network daemons delivered without source, code a source-only review cannot reach.
  • precedent Because Xint was picked on its AIxCC result, whatever this research finds in fielded military apps will be a direct check on how contest performance carries into production code.

Wesie, who co-founded Xint, set out the threat model. "Messaging and communications applications are unique in that an attacker needs read-only access to compromise the entire point of the app," he said [6]. For a messaging app, then, an information leak is the whole compromise. An attacker who can read message content or a location fix does not need code execution.

He located much of the risk in code the app developer did not write. "Third-party SDKs and libraries embedded in these apps can create hidden data risks, where even seemingly minor leaks may expose a user's location or other personally identifiable information during sensitive communications," Wesie said [7]. DARPA's aim is to keep Department of War messaging secure against external, and especially foreign, eavesdropping [15].

As Wesie described it to SecurityWeek, the tool investigates each bug it finds, triages it by how reachable it is to an attacker, and generates patches for the ones an attacker could use [9]. He called Xint "really just a harness and a workflow around frontier elements" [12]. That dependence on outside models limits where it can run. Some enterprises want everything inside their own data center so no source code leaves it. That version is still a work in progress, Wesie said, because "we cannot automatically use the latest LLM models and keep everything within a customer's data center" [11].

DARPA's selection is for research [1]. Xint earned it in a competition that ran for two years [3]. Whether reachability triage and machine-written patches hold up on apps already in service is what this work would show. The report does not include a contract value, a duration, a list of apps in scope, any findings, or where the analysis of government source code will run.

Commercially, Xint sells the service as SaaS: developers run code through it before release, then scan on a schedule to catch bugs introduced later [13]. It already has paying customers [14]. "Our relationship with and funding from DARPA is allowing us to continue developing additional capabilities," Wesie said [16].

What to watch

  • Whether DARPA or Xint publishes vulnerabilities or patches from the messaging-app work, including any in Signal or in bundled SDKs.
  • Whether Xint ships its on-premises version, and which models it can run inside a customer data center.
  • Whether the contract value and duration are disclosed, or whether the other AIxCC winners receive similar selections.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories