Founder / Pragma Research

Bernhard Mueller.

I build tools for understanding complex systems. My work spans offensive security, mathematical models of physics and brains that learn from experience.

Research / Physics, mathematics and AI

Physics. Mathematics.
Machine intelligence.

A shared question runs through this work: how can local systems build a coherent account of a world?

Physics / OPH / 2025 onward

Reverse engineering reality.

OPH studies bounded, self-reading patches with local state, ports, records and feedback. Patches compare shared records and repair disagreement. The research develops finite constructions and conditional routes toward quantum probability, spacetime, gravity and gauge structure.

The papers state the assumptions behind those routes. Establishing a physical account of nature requires measurements as well as mathematical consistency.

Mathematics / Formal verification

Arguments you can inspect.

The OPH research repository develops machine-checked Lean proofs alongside executable models. Work includes finite agreement and refinement, event algebras, geometry and algebraic structure.

Formal verification establishes consequences of explicit hypotheses. The proofs, computational checks and physical interpretations can be examined separately.

AI / Cadence

A brain that learns.

Cadence turns the idea of cooperating local models into software. Flat, ordinary state-coupled and recursive observer layouts all settle through the same repair and qualification process; admitted experience changes their retained relations. Recursive observers add access to other populations' activity and exact prediction errors.

Code, bounded learning experiments and the research paper support an engineering program for embodied intelligence.

Books, papers and research resources

Career and selected work

Follow the questions.

From vulnerability research and mobile standards to symbolic execution, AI agents and the structure of learning.

2005–2013 / SEC Consult

Finding the seams.

Vulnerability research across enterprise software, embedded systems and mobile platforms.

2009 / Whitepaper / Pwnie Best Research

From 0 to 0Day on Symbian.

Applied low-level vulnerability analysis to Symbian smartphones, including Nokia multimedia codecs reachable through MMS. The research covered seven vulnerable codec DLLs and devices including the E61, E71 and N96.

2008 / Whitepaper

Improved DNS Spoofing Using Node Re-Delegation.

Research into DNS cache poisoning following the coordinated multi-vendor disclosure, using node re-delegation to improve the reliability of an attack.

2008 / With Peter Panholzer

FireWire-Hack in Windows Vista.

A demonstration of the FireWire direct-memory-access attack against Windows Vista, with a proof of concept that disables password authentication in the login routine.

Disclosure ↗
Vulnerability advisory archive / 2005–2013
Published advisories and vulnerability research.
DateResearch
Nov 2005Macromedia Flash Player: ActionDefineFunction memory corruption (SA-20051107-1).
Nov 2005toendaCMS: credential and session theft, directory traversal and arbitrary file upload (SA-20051107-0).
Apr 2006Opera Browser: CSS attribute integer wrap and buffer overflow (SA-20060413-0).
May 2006Symantec Enterprise Firewall: internal IP disclosure of NATted machines (SA-20060512-0).
Oct 2006PHP exec/system/popen: file descriptor bug demonstrated by overwriting an Apache log.
Mar 2007MySQL: information_schema denial of service through a null-pointer dereference, with S. Streichbier (SA-20070309-0).
Oct 2007Perdition IMAP Proxy: format string vulnerability (CVE-2007-5740; SA-20071031-0).
Nov 2007SonicWALL SSL-VPN: multiple ActiveX control vulnerabilities (SA-20071101-0).
Dec 2007SonicWALL Global VPN Client: format string through a crafted configuration file (SA-20071204-0).
Dec 2008Fujitsu-Siemens WebTransactions: remote command injection (SA-20081219-0).
Dec 2008Microsoft SQL Server: sp_replwritetovarbin memory overwrite (CVE-2008-5416; MS09-004). CERT/CC note.
Mar 2009IBM Director CIM Server: remote denial of service (SA-20090305-1).
Mar 2009IBM Director CIM Server: local privilege escalation (SA-20090305-2).
May 2009Nortel Contact Center Manager: authentication bypass (SA-20090525-0).
May 2009SonicWALL Global VPN Client: local privilege escalation through installation-directory permissions (SA-20090525-3).
Jul 2009Symbian S60 / Nokia firmware: media-codec memory corruption through MMS (SA-20090707-0).
Oct 2012ModSecurity: multipart parsing bypass (SA-20121017-0). Full Disclosure.
Nov 2012Applicure dotDefender WAF: format string vulnerability.
Dec 2012IBM System Director Agent: DLL injection through wmicimsv, with a Metasploit module; co-credited with Juan Vazquez and Kingcope.
Jul 2013Sybase EAServer: directory traversal, XML entity injection and OS command execution, with Gerhard Wagner (SA-20130719-0).

2014–2018 / Vantage Point Security & OWASP

Making mobile security teachable.

Security research became shared standards, testing methods and tools for reversing mobile applications.

Creator and lead author

OWASP MASVS.

The Mobile Application Security Verification Standard defines requirements used to assess the security of mobile applications.

2016 / HITB GSEC, Singapore

Hacking Soft Tokens.

Research on mobile two-factor and one-time-password tokens, from reverse engineering to kernel sandboxes and full-system emulation. Presented as Attacking Software Tokens.

Vantage Point vulnerability advisories / 2014–2015

2017–2020 / ConsenSys Diligence

Reasoning about code.

As a security engineer, I worked on smart-contract auditing and tools that explore program behavior through symbolic execution.

Creator / Open-source analysis

Mythril.

A security analysis tool for EVM bytecode using symbolic execution, SMT solving and taint analysis. Created by Bernhard Mueller and transferred to ConsenSys.

2018 / HITB Amsterdam / Pwnie nomination

Smashing Ethereum Smart Contracts for Fun and ACTUAL Profit.

Paper and talk introducing Mythril's approach and the LASER symbolic execution engine.

August 2019 / DEF CON 27 / With Daniel Luca

The Ether Wars.

A talk on Ethereum exploits, counter-exploits and honeypots, with a demonstration of Scrooge McEtherface. The tool uses symbolic execution and the Z3 solver to investigate exploitable contracts.

Research tools

Testing the edges.

  • SolFuzz: hybrid grey-box fuzzing and symbolic analysis.
  • DeFi Hacking Playground: a local environment for flash-loan and DeFi experiments.
  • Rektosaurus: testing NFT metadata injection on marketplaces.
  • Storm: blockchain-node stress testing and fuzzing.

2023 onward / AI & autonomous agents

Tools that investigate.

Work on autonomous agents and an AI Research Lead role at Sherlock brought security analysis and machine learning together.

Creator / Research paper, October 2025

Hound.

A language-agnostic code security auditor that builds relation-first knowledge graphs during an investigation. An exploring agent works with senior-model guidance. The paper is Hound: Relation-First Knowledge Graphs for Complex-System Reasoning in Security Audits.

Creator / Evaluation framework

ScaBench.

A framework for evaluating AI smart-contract audit agents against real-world vulnerability datasets. Hound and ScaBench were transferred to scabench-org.

Source ↗

Autonomous-agent experiments

MiniAGI and Darwin GPT.

MiniAGI explored a small autonomous agent built around the OpenAI API. Darwin GPT explored an agent that can spawn copies of itself.

AI-assisted security

Legion.

A Web3 bug-bounty assistant that tracks bounties and uses autonomous agents to investigate code.

Source ↗

Reinforcement learning

Mancala Deep-Q.

Deep Q-learning experiments with Mancala, including an OpenAI Gym environment, agent self-play and a PyGame interface.

Source ↗

Music / TransformerXL

Rage of the Machine.

A polyphonic, multi-instrument music transformer trained on 3,604 metal, grunge and punk MIDI songs, augmented through pitch transposition. The project used a custom tokenizer and 200 hours on four Nvidia T4 GPUs.

Read the project story ↗

Embodied learning / Cadence

Cadence extends this interest in machine intelligence to a persistent learner built from cooperating predictive patches. Explore the research or read the Cadence preprint.

2025 onward / Learning projects

Make the mechanism visible.

Interactive explanations and reading paths for the mathematics and security of computational systems.

Interactive tutorial

STARK Lab.

A step-by-step exploration of STARK proofs, from execution traces and constraints to FRI.

Read about STARK Lab ↗

Curated learning path

Awesome ZK Proofs.

Reading paths through SNARKs, STARKs and Bulletproofs, with the mathematics and implementation ideas behind them.

Explore the project ↗

Curated learning path

Awesome AI Security.

Resources on adversarial attacks, prompt injection and the use of AI in security testing.

Explore the project ↗

Articles and essays

Writing archive.

Research explanations, technical walkthroughs, malware analysis and occasional satire.

Floating Pragma Blog
Smart Contract Security
Web3 Analysis
AI Security Auditing
Zero-Knowledge Proofs
AI & Music
Satire & Misc
Physics

Keep in touch

Compare notes.
Build something.

For research conversations, robotics collaborations or an introduction to Pragma Research, get in touch.