The Temporary Democratization of Software Reverse Engineering

By David Buchanan (aka retr0id), 3rd October 2026

I'm very good at reverse engineering. I finished 8th place in the 2022 Flare-On RE CTF, out of thousands of participants. It took me a bit over 2 days to complete all the challenges (and that was after I'd decided to "take it easy" and not be hyper-competitive that year).

I never set out to get good at reverse engineering exactly, I just wanted to understand how the things around me worked, and to change their behaviours. Learning how to reverse engineer was a side-effect of following that curiosity.

Once I discovered CTFs (which was over 10 years ago at this point), I found the competitive aspect highly motivating. I loved climbing CTF scoreboards, and being the first to solve a challenge was truly intoxicating.

But in 2026 everyone is good at software reverse engineering, and associated puzzle-solving. Everyone who can afford the LLM tokens at least. The top ranks in Flare-On 2026 are all occupied by LLM-wielding humans, or fancier orchestration setups, all of whom finished the whole CTF in just a few hours.

I think this quote from a participant sums it up fairly well:

I had never participated in #FlareOn, not for lack of interest but due to the massive time commitment it represented. This year, I decided to pit [LLM-based product] against it and was able to solve all challenges in <2h.

Even though LLMs were already getting decent around this time last year, the scoreboard for Flare-On 2025 was comparatively very normal, with well-known CTF players in the top spots.

I have a lot of conflicting feelings about all this!

  • It's jarring to see something I was uniquely good at become so commoditized, although I'm at peace with it by now (the writing has long been on the wall).

  • I'm not directly bothered that CTFs are "dead", since I'd already stopped playing competitively before LLMs got good. However, I'm sad that future generations will not be able to enjoy CTFs in quite the same way. I see communities of human-only solvers forming, which is encouraging. Even though it can only be enforced through an honour system, I bet it can retain some of the atmosphere of the "good old days" of CTFing.

  • I'm happy that more people have the opportunity to understand and modify the devices and software they use.

  • I don't like that they have to pay (money or GPU-hours) to do so, even if the opportunity cost of dedicating years of your life to learning RE was never free. Sure, local models exist, but nobody's doing frontier-quality inference on their school-issued chromebook any time soon.

  • I don't like that LLMs allow people to skip the "understanding" part entirely, making it harder to demonstrate understanding, for people who still care. The non-understanders can produce more output (because they are not bottlenecked by the process of understanding), reducing the signal-to-noise ratio when it comes to finding interesting projects to look at or read about.

  • I like that it takes less human effort to demonstrate that "security through obscurity" is (and has always been) a bad idea.

  • I enjoy using LLMs for reverse engineering! Part of my enjoyment of RE came from knowing I was good at it, but I only got good because I enjoyed finding out how things worked. I still enjoy finding out how things work, and I can still be the first to do something.

The Future

We're living through a sort of "golden age" of reverse engineering capability right now, but I fear it will not last. Even when vendors aren't deliberately trying to deter reverse engineering, software complexity is going up (see also: Jevons paradox). LLM-powered anti-RE and product security measures will likely also be formidable, and the whole thing will devolve into a battle of who has the deepest pockets for inference.

Worst of all, more product logic will be pushed onto the server-side, reducing the RE-able surface. You will own nothing and you will be kinda pissed off about it.