How long does Vorthix take to find a vulnerability?
The pymonocypher heap buffer overflow (GHSA-8f95-v3jq-cj86) was confirmed in 1 hour 50 minutes from initial analysis. The libexpat incomplete fix bypass (CVE-2026-56412) was found in iteration 42 of a 50-iteration session. Initial findings on a standard single-target Focused engagement appear within 24–48 hours. The exact time depends on target complexity, codebase size, and attack surface density.
Vorthix does not stop at the first vulnerability. It continues until the iteration budget is exhausted. On the libexpat engagement, the same session that found CVE-2026-56412 also analyzed multiple other entry points and code paths — a full picture of the attack surface, not a single finding. See the full research index or the incomplete fix detection methodology behind that finding.