31 comments

  • brandonpelfrey an hour ago

    Unless you explicitly need byte-matching decompilation, there are significantly faster ways to produce a decompilation/C which is functionally equivalent. I need to post about this. What's been working for me is that for every function, Agent A is tasked with writing some code which is semantically equivalent to the original assembly, but not necessarily exactly the same. Agent A also writes tests. Agent A submits the implementation of the function and tests to the harness for it to judge. The harness runs both the original function and the submitted function in a virtual machine/simulator/emulator (the tests define function inputs and starting state). The harness will only accept the implementation if 1) the read/write sequence to RAM is identical to the original function's, and 2) there must be complete line and branch coverage of the original function being decompiled.

    I've found this to be robust for decompiling games, while giving the agents enough freedom to write code that is readable and not waste a ton of time making sure e.g. instruction ordering, register assignments, etc. are all exactly the same. For me, having byte-matching decompilation is only one way to produce a decompilation I know is faithful to the original. This "high-level decompilation" process I just described is something agents can do much more quickly.

      j2kun an hour ago

      Functional equivalence here, of course, depends on the completeness of the test suite, where byte-identical compiled artifacts does not.

      (For example, your approach would not necessarily catch all the same overflow behaviors; the OP expressly claimed that "replicating all bugs" was also important, and many bugs are caused by certain overflow behaviors)

        SubiculumCode an hour ago

        Byte exact seems only of interest to preserve known bugs etc for cheats/shortcuts/etc.

          j2kun an hour ago

          That may be true, but I hate it when people repeat the false idea that functional equivalence requires only a test suite that has full branch/line coverage. Call me triggered :)

          That said, I would probably follow this same approach if I were to do this, but with extensive randomized testing as well.

            hedgehog 14 minutes ago

            You can do the process in stages. Do the first decompilation mechanically (no LLM), use a SMT solver to show it builds to an equivalent binary to the original, and then use LLM to clean up the code into something idiomatic with the benefit of a correct binary built with the new toolchain. This helps when you want to port across languages or toolchains, and helps protect against toolchain bugs.

      SubiculumCode an hour ago

      So you restricted it to implementing the same function (same inputs,outputs, dependencies as original?) and prevented the agents from making design decisions by keeping it's scope restricted?

        brandonpelfrey 30 minutes ago

        Yes. It can gain more context, but this has been enough. Note, there is also a notion of adversarial review layered on top in which it tries to poke holes in the test plan "you didn't handle this case of XYZ". It isn't actually perfect as a parallel thread said it may miss things like wrapping behaviors. In practice, it's very effective.

  • aetherspawn 23 minutes ago

    The reason this cost so much is because the AI has the ridiculous goal of getting identical assembly output.

    The agents would have had to mess around with compiler versions, optimisation options, and the phase of the moon as well.

    If you just went for functional equivalence, it would probably cost 10x or 100x less tokens.

    Another false economy was using Sonnet instead of a more intelligent model like Sol 6.1 (1), which would have cost more per token, but is 100x or so better at reverse engineering and coding and therefore can chew through the source code much quicker and make fewer mistakes, meaning less work needing to be scrapped.

    In my testing doing a similar task, I ran multiple sonnet for weeks and burnt through ~$1000 in tokens to get 20% completion and output that was pretty bad. After switching to Sol 6.1, it finished the whole task in around 2 days, cost around $50, and it did it with zero supervision and a single /goal.

    (1): struggle to use Opus for reverse engineering, too many safeguards. OAI has virtually none, and uses way less tokens so is more economical.

      Gigachad 17 minutes ago

      Identical output isn’t ridiculous. It’s pretty much a requirement to ensure the game actually is the same in every way. These decomp projects are pitched as a high performance alternative to emulation.

      No one is going to use it if it’s a kind of close but not really reimplementation.

      Testing functional equivalence is also pretty much impossible. How would you for example test the new one has exactly the same bugs which haven’t been discovered yet. Or doesn’t introduce new ones? This stuff matters for speed runners.

        aetherspawn 10 minutes ago

        It’s ridiculous because something as simple as the compiler picking different registers is going to make zero functional difference but give a false negative on assembly compare.

        Yet the C code can’t pick what registers to use, so the poor agent is probably shuffling the code around randomly for hours or days until it matches.

        That’s probably why the agent dropped down into inline assembly in the first place (the author complained about this), because I bet it’s thinking trace was that this is futile.

        Compilers themselves are not even deterministic and running them multiple times creates different assembly.

  • thway15269037 39 minutes ago

    I struggle to understand what legal leverage they used to threaten him to remove every detail about the game. Can someone post the game name and company name?

    So, if you reverse-engineer game X and post reverse-engineered code, what exactly do you infringe, how and in which jurisdiction? What changes if it is done via LLM?

    (I understand that LLM decompilation is absolutely out of hand right now and something surely will come to trample the fun. But what and when? I suppose american LLMs will have their system prompt updated to forbid any reversing help and report suspicious activity straight to legal hotline)

      xnx 32 minutes ago

      Call of Duty: Modern Warfare 2 (2009) (from a previous version of the page)

  • WheelsAtLarge 25 minutes ago

    Interesting, if all software can be decompiled and copied what is the future of software. Will all software be SaaS? A time where the majority of PCs will be terminals? Game consoles are almost there. It's only a small jump for all software to go that way.

      unsnap_biceps 2 minutes ago

      A future of all SaaS only works if you can't just tell a LLM what you want and get a custom implementation. I've always done a lot of personal projects, but my velocity has increased dramatically and I've replaced a number of projects that I used to pay for with custom ones that work well enough. I can't imagine that SaaS is going to be a viable model unless it involves a community that wants a unified experience, like a multiplayer game.

      Daishiman 16 minutes ago

      Most software organizations pay for is effectively a SaaS or something where software is a minor part of the artifact and support is where the real money is.

  • xnx 36 minutes ago

    A previous version of the page said the game was Call of Duty: Modern Warfare 2 (2009).

  • esafak 12 minutes ago

    Can anyone think of any lessons to draw from this for normal development, where we don't have oracles to serve as guardrails? I write specs but the agents still find ways to insert bugs between the lines. Oh well, job security.

  • vivzkestrel 12 minutes ago

    - i want to very very badly see a post of this using LM studio and one of the open source models

    - please someone do it

  • georgemcbay 38 minutes ago

    In case anyone is curious about the obvious question of which game they are talking about... based on months-old reddit posts (which seem like links to prior progress reports of the same project) the game in question appears to be Call of Duty: Modern Warfare 2 (the original 2009 version).

    https://www.reddit.com/r/ReverseEngineering/comments/1vxig19...

  • WillAdams an hour ago

    To save folks looking this up:

    >At current 2026 API rates, 500 billion AI tokens would cost roughly $100,000–$750,000 depending on the model, with most flagship models in the $150–$400 per million input tokens range

      Gigachad an hour ago

      This stuff is all done on highly subsidized subscription plans. I suspect Antropic is quite happy to sell these people $100k of compute for $4k because it boosts their growth numbers and they can tell investors once they stop subsidizing, this will grow to $100k. Despite the fact that most of this stuff simply wouldn't be done without the subsidization.

        chii 39 minutes ago

        the exact same arguments were said about uber's business at the start.

        Yet, it is now profitable.

        The bet is that people realize how valuable these services are, and despite complaining, they still would pay the higher price. This realization would not happen without this initial subsidy from investors.

        It isn't too different from drug dealer's first sample free...

          thway15269037 36 minutes ago

          Uber business model wasn't a subscription "for 10 bucks you can travel 900 lightyears a week"

          Gigachad 22 minutes ago

          There’s also examples where this didn’t work. Moviepass for example.

          Taxis were an established profitable business model and the uber subsidisation wasn’t anywhere near as much as AI subsidies.

            isubkhankulov 8 minutes ago

            Disagree with your second paragraph. Uber/lyft subsidized into deep negative margin territory around ~2015 or so. Anthropic (and OpenAI) are subsidizing but not losing money on these consumer plans.

      j2kun an hour ago

      I struggle to believe that someone would find it worth that much money to have a decompiled version of a game they also commit to keeping private.

        girvo an hour ago

        > they also commit to keeping private

        Reading between the lines:

        "The avid reader of my blog might have noticed that I had previously written two posts that have since been removed. Everyone else might now be wondering which game I am talking about. To both of you I can only say that corporate America was here to ruin our fun."

        Keeping it private likely wasn't the original plan...

      TomatoCo an hour ago

      Where are you getting 150-400 per million input?

      https://developers.openai.com/api/docs/pricing https://platform.claude.com/docs/en/about-claude/pricing

      OpenAI and Anthropic are both 10/mil in.

      https://openrouter.ai/z-ai/glm-5.3#providers https://openrouter.ai/moonshotai/kimi-k3#providers Other frontier models are like 1-3/mil in.

      Also, 500 billion is 500,000 millions. At the lower end of your 140/mil estimate that's 70 million dollars. Even at my 2/mil lookup for Chinese frontier models that's one million. Show your math for 100k-750k, please.

        WillAdams 11 minutes ago

        It was a search for "average cost of 500 billion ai tokens" which may or may not have been the correct phrasing, but seemed straight-forward enough that at first blush, accepting the AI-generated answer seemed reasonable.

      GaggiX 38 minutes ago

      The vast majority of these tokens are cache input tokens so even at API price the cost would be much lower.

        thway15269037 15 minutes ago

        Even with 95% cache hit, and on cheapest chinese model, it would still be in tens of thousands of dollars (I assume that of 500B tokens at least 10B would be in "output"). If we switch gears to Kimi K* then if would very quickly escalate in hundred thousands USD.