Ruikai Peng
Hey, I am Ruikai.
I am a 16 years-old working on the security of the lowest parts of computer systems.
(I've been doing this since 11.)
things about me:
- previous bugs I found
- Pwno, founder
- We build AIs for real-world memory security problems
at the innermost systems that billions used daily - We help secured:
Linux, FFmpeg, V8, Firefox, Chromium, WebKit, PostgreSQL, Redis, ...
- retr0.blog, storytell of how I exploit bugs from the lowest part of computers
Talks
- Youngest speaker at OAIC (Oct, 2025)
- I talked about how I designed a human-inspired taint engine via LLM reasoning, and how we used it found two overflows in Unitree Robodogs' BLE stack within 20 minutes
- Youngest speaker at Black Hat USA (Aug, 2025)
- I talked about we designed a dataflow engine inspired by Tree-of-Thoughts, and how we used it to do vulnerability discovery to PoCs generation (pruning, restriction generation and that kind of stuff)
- Youngest speaker at Zer0con (Apr, 2025)
- I talked about how I use a super fun but complex way to RCE LLama.cpp via a little heap-overflow in tensor processing.
- Youngest member of Tencent Talent Program
Media
- Mentioned by Lex Friedman
- Bugcrowd: Ruikai Peng, Spotlight
- Bloomberg: 16 y/o from CT, AI cyber startup
- questions / resume
Fun Facts
- I did my first router ROP at 12
- I can play neon by john mayer
- I played troy bolton in middle school