Skip to content
winfunc

Mission

The pre‑AGI security company.

Software is about to be written, shipped, and attacked by machines faster than any security team can read it. Stition exists so that defenders get there first. winfunc is step 0.

Company
Stition, Inc.
Founded
2024 · Delaware
Backed by
Y Combinator · S24
Step 0
winfunc
Prologue

Every exploit ends the same way. Execution reaches a function it was never meant to reach. In capture-the-flag games, that function is called win(). This is the story of two engineers from Kerala who decided attackers should never reach it again.

01SourceBefore 2024Thrissur, Kerala

The hacker

It started with taking software apart.

Mufeed VH grew up in Thrissur, Kerala, taking software apart to see where it would break. He was still a teenager when his reports started landing in the bug bounty programs of Google, Mastercard, and Okta.

Competition sharpened it. He won gold in cyber security at the IndiaSkills Nationals, bronze for India at the BRICS Skills Olympiad, and represented the country at WorldSkills. Between contests he ran Lyminal, a research consultancy that took on the software problems other people had given up on, and patched or reviewed more than 300 CVEs in open-source code.

One lesson never changed. Scanners report patterns. Hackers report paths.

Record · Mufeed VHCo-founder, CEO
IndiaSkills
Gold medal Cyber security
BRICS Skills
Bronze medal, representing India
WorldSkills
Represented India in cyber security
Bug bounties
Google, Mastercard, Okta, Dell, Ford, Adobe, EFF, Telefónica
Open source
300+ CVEs patched and reviewed
Lyminal
Research consultancy for hard software problems, 2020–2023
02Hop 1Before 2024Kerala → distributed systems

The engineer

Vivek built the things that are not allowed to fail.

Vivek R came to security from the other side. His first systems project was a shell written from scratch. In 2020 he spent Google Summer of Code inside GStreamer, the multimedia framework under products from Google and Apple, building an object-tracking element for the Pitivi editor.

Then he went where mistakes cost real money. At Chorus One he built fault-tolerant infrastructure for proof-of-stake validators holding more than two billion dollars in stake. He did protocol research for IoT startups and helped Fortune 100 companies plan their infrastructure. He reads papers with the three-pass method and writes Rust by preference.

Mufeed knew how systems break. Vivek knew how they are held together. The agent would need both.

Record · Vivek RCo-founder, CTO
$ ./vsh          # first systems project: a shell
$ gst-launch-1.0 v4l2src ! cvtracker ! autovideosink
# GSoC 2020 · GStreamer object tracking for Pitivi
Chorus One
Fault-tolerant validator infrastructure, $2B+ in stake
Research
IoT protocol optimization for startups
Advisory
Infrastructure strategy for Fortune 100 companies
Off hours
Rust, papers, live-coded music, FPV drones
03Hop 2Dec 9, 2022mufeedvh.com

The warning

Nine days after ChatGPT, a threat model.

ChatGPT launched on November 30, 2022. Nine days later Mufeed published Security in the age of LLMs, an essay on what happens to threat models once a language model sits between a user and a system.

It described prompt injection before most people had a name for it. It predicted jailbreaks that end in code execution, with the exploit written in plain English. And it carried the idea the company was built on: if a model can read code and reason about it, it can do the work of a security researcher. So can the attacker's model.

Essay · Security in the age of LLMs2022-12-09 · 12 min

“…with the exploit being just plain english.”

Written the week language models went mainstream: prompt injection, jailbreaks that end in code execution, and agents that act in the physical world, treated as ordinary security problems.

Read the essay
04Hop 3Feb 2024Delaware

Stition

A company named for the window we are in.

In February 2024 they incorporated Stition, Inc. and gave it a single line of purpose: the pre-AGI security company.

The argument is simple to state and hard to act on. Between now and AGI there is a window in which AI makes attacking software cheap long before it makes defending software cheap. Every codebase written in that window will be read by models, and some of those models will be pointed at it by attackers. Defense has to become AI-native while the window is still open.

Stition would close it in steps. Step 0 was a hacker made of software.

github.com/stitionaiOrganization

stition

the pre-agi security company. step 0: @winfunc.

05Hop 4Mar 2024github.com/stitionai/devika

Devika

A joke on X that became 19,000 stars.

On March 12, 2024, Cognition showed Devin, an autonomous software engineer. Mufeed posted a joke about Devin having an Indian cousin called Devika. Then he built her, in about twenty hours of coding across three days, and put her on GitHub.

Devika planned, researched, and wrote code from a single instruction. She passed 19,000 stars, drew dozens of contributors, and made national news as India's answer to Devin. She also proved something uncomfortable. Agents could now write software at speed, and nothing in the loop was checking whether that software was safe.

stitionai/devikaOpen source
Stars19.6k
Built in20 hours
Over3 days

Devika is the first open-source implementation of an Agentic Software Engineer.

Economic TimesHindustan TimesNDTVAnalytics India Magazine
06Hop 5Aug 8, 2024Y Combinator · S24

Asterisk

An AI hacker, launched on Y Combinator.

That summer Stition joined Y Combinator's S24 batch and shipped its first product. Asterisk was an AI hacker that found vulnerabilities, exploited them in a sandbox, patched them, and reported only what it could prove.

It was built to work the way a human auditor works. Index the codebase into a call graph that any language could fill, even Arc, the Lisp dialect behind the original Hacker News. Learn what the software is for. Model the threats that matter to that kind of software. Hunt, exploit, patch in the codebase's own style, and write the report.

Within months its reports had reached Google, Supabase, Sentry, Cal.com, Gumroad, Bun, and Hoppscotch.

Launch YC · Asterisk: AI-automated security teamAug 2024

Find, exploit, and patch security vulnerabilities across your digital assets, with no user intervention and a report with zero false positives.

  1. Indexing
  2. Context
  3. Threat model
  4. Scanning
  5. Exploitation
  6. Patching
  7. Reporting
07Hop 62025github.com/winfunc

In the open

We built our tools in public, and the bugs followed.

In 2025 the team kept shipping in the open. Claudia, a desktop app for Claude Code that later became opcode, passed 22,000 stars. Blockoli and stackwalk taught agents to index huge codebases and walk their call stacks in any language. Every tool made the agent better at reading code the way an attacker does.

The findings got sharper. An authentication bypass in Anthropic's FastMCP. SQL injection in Supabase. A zero-click account takeover in Gumroad. A permission-model bypass in Node.js. Authorization, tenancy, and business logic: the classes of bug that pattern scanners were never built to see.

08Hop 72025asterisk.so → winfunc.com

The rename

Asterisk became winfunc.

Asterisk was a good name for a footnote. It was also the name of a famous open-source phone system, and the product had stopped being a footnote.

So we named it after the function every exploit is written to reach. In binary exploitation challenges, the flag sits behind a function called win(). Hijack control flow, land in win(), and the game is over.

winfunc is that function, pointed the other way: the place our agent reaches first, so an attacker never does.

Rename2025

asterisk

winfunc

// the function every exploit is written to reach
void win() {
    system("cat flag.txt");
}
09Hop 82026Chromium · NGINX · Ray · React

State of the art

State of the art is a ledger, not a claim.

In 2026 the agent went after the hardest code there is. It found a type confusion in Chromium's V8 and heap overflows in NGINX, in code fuzzed for decades and read by millions of engineers. Running only open models on our harness, it found six NGINX vulnerabilities, five of them credited in F5's advisories. It found unauthenticated remote code execution in Ray, cross-tenant takeovers in SaaS platforms, and CVEs in React, Node.js, and Mattermost.

We publish every finding we are allowed to, with the trace, the proof, and the patch. We built N-Day-Bench, a monthly benchmark that tests frontier models on real vulnerabilities disclosed after their training cutoff, so anyone can check how good the models, and we, really are.

10win()NowSan Francisco · Kerala

The mission

Make every codebase unexploitable before AGI makes exploitation free.

Here is the problem we arrived at. Code is now written faster than it can be secured. Scanners bury teams in patterns. Pentests take a snapshot and leave. An attacker with a model needs one path, and the models are getting better at finding all of them.

The answer is a defender that thinks like the attacker: one that reads the whole codebase, proves the exploit, and ships the fix before the code merges. That is winfunc.

It is step 0. The steps after it follow the same line, from securing the code AI writes to securing the agents that write it.

  1. 01

    Start with the application.

    Security questions only make sense in context. The agents read the code, the architecture, and the trust boundaries before they conclude anything.

  2. 02

    Prove it, or say so.

    A finding carries its trace and its proof. When something cannot be proven, the report says exactly where the evidence stops.

  3. 03

    Engineers make the call.

    Every fix arrives as a pull request. Your team reviews, tests, and merges it. The agents never merge to protected branches.

  4. 04

    Do the work in public.

    We publish our disclosures, our benchmark, and our tools, so anyone can check the work instead of taking our word for it.

Game over, for the attacker

Let our agent reach win() in your codebase first.

Bring us the repository you worry about most. You get the trace, the proof, and the fix, before anyone else finds the path.

A voxel chessboard with a bone rook and a red knight, the traced path between them lit green