Introducing Patch the Planet

What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with open-source maintainers, and unleash frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnership with OpenAI and its Daybreak initiative, we can report that the impact is hundreds of discovered bugs, 64 pull requests, and 51 issues filed across 19 projects in the first week of Patch the Planet.

The first week covered 19 projects across cryptography, networking, language infrastructure, and software supply chain: cURL, NATS, pyca, Sigstore, aiohttp, the Go project, freenginx, Python and python.org, urllib3, PyPI, SimpleX, Valkey, and RustCrypto. Over 30 projects have joined the initiative so far.

We’re reporting public findings on GitHub including 64 PRs, 11 of which are already closed with a fix. This public tally undercounts the work, since several projects take reports through private channels like HackerOne, GitHub security advisories, mailing lists, and private forks.

Notable findings include 24 Linux kernel local privilege escalation PoCs, a 23-year-old OpenBSD flaw, Chrome V8 vulnerabilities fixed within days, and a Firefox WebAssembly CVE patched before Pwn2Own Berlin.

HackerOne and Calif support triage and coordinated disclosure. GPT-5.5-Cyber built a full-scale fuzzing lab in under a day — work that would have taken human fuzzing experts two or three weeks manually.