Engineers in Japan built an AI pentester that topped HackerOne VDP (Q3 2026) Layer8 Co., Ltd.'s AI penetration testing agent Trident, run under the HackerOne research account l8_trident, ranked first worldwide on HackerOne's VDP leaderboard for Q3 2026 (July 1–September 30), with 568 reports triaged across 50 programs, including 65 critical and 104 high-severity findings. The agent autonomously discovers vulnerabilities in web applications and validates exploitability, and a team of three Japanese engineers — with one engineer spending about an hour a day reviewing and submitting results — has developed it since May 2025 without venture capital funding. In one case study, Trident chained an authentication bypass with SQL injection to gain unauthorized access to an internal dealer parts ordering system. Introduction Layer8 Co., Ltd. announces that its research account, l8 trident https://hackerone.com/l8 trident?type=user , powered by its AI penetration testing agent Trident, ranked first worldwide on HackerOne’s VDP leaderboard for Q3 2026 July 1–September 30 . Trident autonomously discovers vulnerabilities in web applications and validates the conditions required to exploit them and their impact. Since starting development in May 2025, our team of three software and security engineers in Japan has worked extensively to improve its performance and safety without venture capital funding. We have now validated its effectiveness on real systems through HackerOne VDPs. Of the three Japanese engineers developing Trident, one handled the HackerOne operation. Their daily work consisted of about an hour reviewing and submitting Trident’s results. Every other step was automated. Results on HackerOne A vulnerability disclosure program VDP authorizes external researchers to test for vulnerabilities under the policies set by a company or organization. Vulnerability reports must demonstrate the conditions required for exploitation and the resulting business impact. Findings with no exploitable impact are not accepted for triage. From July 1 to September 30, 2026, a total of 568 reports across 50 programs were triaged. | severity | Reports | |---|---| | Critical | 65 | | High | 104 | | Medium | 378 | | Low | 21 | | Total | 568 | Attack case study The following example describes an attack we carried out, with identifying details omitted. The target was a dealer parts ordering system intended for internal use. Trident chained authentication bypass and SQL injection to attack the application without a legitimate account. Trident first discovered that the server created a session by trusting information sent by the browser, without verifying the identity provider’s IdP’s authentication result. A fabricated username, however, was rejected by a subsequent check against registered users. That check inserted the username stored in the session directly into a SQL query on the next page, without sanitizing it. SQL injection could therefore alter the query conditions and bypass the registered-user check. The remaining check compared the submitted site code with the code assigned to the registered user. When the codes did not match, the error message exposed the correct code. Resubmitting the request with that code allowed unauthorized access to the business application. The vulnerabilities had two consequences: - Risk of data disclosure and tampering - SQL injection allows an attacker to extract confidential information and modify data. Tampering with order data could also disrupt parts procurement. - Unauthorized access to the business application - Authentication bypass allows an external attacker to access user and order management screens. We promptly submitted reports for these vulnerabilities. Workflow Trident is built around an AI agent that performs penetration testing autonomously, from mapping the application and discovering vulnerabilities to validating exploits and recording reproduction steps, evidence and impact. The results accumulate in a vulnerability register. One in-house security engineer reviews and submits the reports. This division of responsibilities has enabled our small team to conduct testing at scale without false positives. Architecture and design decisions Trident uses a multi-agent architecture in which 24 agents work together on reconnaissance, vulnerability analysis, exploitation, verification and other tasks. We faced two main design challenges in making an AI penetration testing agent operate autonomously: 1. How to handle the different requirements of reconnaissance, vulnerability discovery, exploitation and verification. 2. How to prevent out-of-scope access and excessive requests without human supervision. The two most important design decisions are described below. Why we chose a multi-agent architecture We built Trident as a multi-agent system for the following reasons: - Per-phase tuning is easier: Models, system prompts, toolsets and guardrails can be optimized independently for each phase. Reconnaissance and exploitation require very different capabilities and guardrails, so this flexibility matters. - Phase-specific false-positive checkers can be added: Automated filters can be optimized for each phase. - State management can be separated: Some phases benefit from their own state management or forgetting behavior. The trade-off is that managing multiple agents and shared state adds complexity. Even so, we concluded that the benefits outweigh the cost. Guardrails for autonomous execution Because we chose full automation without a human in the loop, guardrails are essential for safe operation without human supervision. Trident implements guardrails in two layers: - Prompt-level guardrails: Each agent’s system prompt explicitly states the allowed scope and prohibited actions. - System-level guardrails: All traffic passes through an intercepting proxy L7 Egress Gateway , which blocks requests to out-of-scope hosts, enforces request-rate limits and rejects unknown protocols. If we rely only on prompt-level guardrails, safety breaks as soon as the LLM ignores or misunderstands an instruction. Full automation requires system-level guardrails that enforce constraints independently of the LLM’s behavior. Requests and responses passing through the intercepting proxy are also recorded and automatically sent to scanners for inspection. Why existing benchmarks were not enough To keep tuning individual phases, one of the advantages of a multi-agent architecture, we need benchmarks that can measure performance differences at the phase level. PortSwigger Academy Lab and XBOW Benchmark are commonly used to evaluate AI penetration testing agents. They are useful for measuring the strength of complete attack chains, but we encountered the following challenges in Trident’s development: 1. As model capabilities improve, existing benchmarks are starting to saturate at the upper end. 2. They make it hard to measure fine-grained tuning differences, such as initial reconnaissance with a web browser or safety checks for exploitation. 3. They make it hard to detect regressions where only a specific phase gets worse after switching models. We therefore developed our own benchmarks for phase-level performance improvement and cost optimization, and use them for continuous evaluation. Conclusion Our work on HackerOne VDPs validated Trident’s effectiveness on real systems, with fully automated vulnerability discovery and exploit validation. We ranked first worldwide in Q3 2026 with one person spending about an hour a day reviewing and submitting reports. We will continue our research and development toward automating more advanced attack chains and supporting a broader range of targets.