10 comments

  • brandonpelfrey 47 minutes ago
    Unless you explicitly need byte-matching decompilation, there are significantly faster ways to produce a decompilation/C which is functionally equivalent. I need to post about this. What's been working for me is that for every function, Agent A is tasked with writing some code which is semantically equivalent to the original assembly, but not necessarily exactly the same. Agent A also writes tests. Agent A submits the implementation of the function and tests to the harness for it to judge. The harness runs both the original function and the submitted function in a virtual machine/simulator/emulator (the tests define function inputs and starting state). The harness will only accept the implementation if 1) the read/write sequence to RAM is identical to the original function's, and 2) there must be complete line and branch coverage of the original function being decompiled.

    I've found this to be robust for decompiling games, while giving the agents enough freedom to write code that is readable and not waste a ton of time making sure e.g. instruction ordering, register assignments, etc. are all exactly the same. For me, having byte-matching decompilation is only one way to produce a decompilation I know is faithful to the original. This "high-level decompilation" process I just described is something agents can do much more quickly.

    • j2kun 45 minutes ago
      Functional equivalence here, of course, depends on the completeness of the test suite, where byte-identical compiled artifacts does not.

      (For example, your approach would not necessarily catch all the same overflow behaviors; the OP expressly claimed that "replicating all bugs" was also important, and many bugs are caused by certain overflow behaviors)

      • SubiculumCode 43 minutes ago
        Byte exact seems only of interest to preserve known bugs etc for cheats/shortcuts/etc.
        • j2kun 39 minutes ago
          That may be true, but I hate it when people repeat the false idea that functional equivalence requires only a test suite that has full branch/line coverage. Call me triggered :)

          That said, I would probably follow this same approach if I were to do this, but with extensive randomized testing as well.

          • hedgehog 0 minutes ago
            You can do the process in stages. Do the first decompilation mechanically (no LLM), use a SMT solver to show it builds to equivalent code to the original, and then use LLM to clean up the code into something idiomatic with the benefit of a correct binary built with the new toolchain.
    • SubiculumCode 44 minutes ago
      So you restricted it to implementing the same function (same inputs,outputs, dependencies as original?) and prevented the agents from making design decisions by keeping it's scope restricted?
      • brandonpelfrey 16 minutes ago
        Yes. It can gain more context, but this has been enough. Note, there is also a notion of adversarial review layered on top in which it tries to poke holes in the test plan "you didn't handle this case of XYZ". It isn't actually perfect as a parallel thread said it may miss things like wrapping behaviors. In practice, it's very effective.
  • aetherspawn 8 minutes ago
    The reason this cost so much is because the AI has the ridiculous goal of getting identical assembly output.

    The agents would have had to mess around with compiler versions, optimisation options, and the phase of the moon as well.

    If you just went for functional equivalence, it would probably cost 10x or 100x less tokens.

    Another false economy was using Sonnet instead of a more intelligent model like Sol 6.1 (1), which would have cost more per token, but is 100x or so better at reverse engineering and coding and therefore can chew through the source code much quicker and make fewer mistakes, meaning less work needing to be scrapped.

    In my testing doing a similar task, I ran multiple sonnet for weeks and burnt through ~$1000 in tokens to get 20% completion and output that was pretty bad. After switching to Sol 6.1, it finished the whole task in around 2 days, cost around $50, and it did it with zero supervision and a single /goal.

    (1): struggle to use Opus for reverse engineering, too many safeguards. OAI has virtually none, and uses way less tokens so is more economical.

    • Gigachad 2 minutes ago
      Identical output isn’t ridiculous. It’s pretty much a requirement to ensure the game actually is the same in every way. These decomp projects are pitched as a high performance alternative to emulation.

      No one is going to use it if it’s a kind of close but not really reimplementation.

      Testing functional equivalence is also pretty much impossible. How would you for example test the new one has exactly the same bugs which haven’t been discovered yet. Or doesn’t introduce new ones? This stuff matters for speed runners.

  • thway15269037 25 minutes ago
    I struggle to understand what legal leverage they used to threaten him to remove every detail about the game. Can someone post the game name and company name?

    So, if you reverse-engineer game X and post reverse-engineered code, what exactly do you infringe, how and in which jurisdiction? What changes if it is done via LLM?

    (I understand that LLM decompilation is absolutely out of hand right now and something surely will come to trample the fun. But what and when? I suppose american LLMs will have their system prompt updated to forbid any reversing help and report suspicious activity straight to legal hotline)

    • xnx 18 minutes ago
      Call of Duty: Modern Warfare 2 (2009) (from a previous version of the page)
  • WheelsAtLarge 10 minutes ago
    Interesting, if all software can be decompiled and copied what is the future of software. Will all software be SaaS? A time where the majority of PCs will be terminals? Game consoles are almost there. It's only a small jump for all software to go that way.
    • Daishiman 2 minutes ago
      Most software organizations pay for is effectively a SaaS or something where software is a minor part of the artifact and support is where the real money is.
  • xnx 21 minutes ago
    A previous version of the page said the game was Call of Duty: Modern Warfare 2 (2009).
  • georgemcbay 23 minutes ago
    In case anyone is curious about the obvious question of which game they are talking about... based on months-old reddit posts (which seem like links to prior progress reports of the same project) the game in question appears to be Call of Duty: Modern Warfare 2 (the original 2009 version).

    https://www.reddit.com/r/ReverseEngineering/comments/1vxig19...

  • FounderDenken 9 minutes ago
    [flagged]
  • carplaybits 1 hour ago
    [flagged]
  • WillAdams 51 minutes ago
    To save folks looking this up:

    >At current 2026 API rates, 500 billion AI tokens would cost roughly $100,000–$750,000 depending on the model, with most flagship models in the $150–$400 per million input tokens range

    • Gigachad 43 minutes ago
      This stuff is all done on highly subsidized subscription plans. I suspect Antropic is quite happy to sell these people $100k of compute for $4k because it boosts their growth numbers and they can tell investors once they stop subsidizing, this will grow to $100k. Despite the fact that most of this stuff simply wouldn't be done without the subsidization.
      • chii 25 minutes ago
        the exact same arguments were said about uber's business at the start.

        Yet, it is now profitable.

        The bet is that people realize how valuable these services are, and despite complaining, they still would pay the higher price. This realization would not happen without this initial subsidy from investors.

        It isn't too different from drug dealer's first sample free...

        • thway15269037 21 minutes ago
          Uber business model wasn't a subscription "for 10 bucks you can travel 900 lightyears a week"
        • Gigachad 7 minutes ago
          There’s also examples where this didn’t work. Moviepass for example.

          Taxis were an established profitable business model and the uber subsidisation wasn’t anywhere near as much as AI subsidies.

    • j2kun 42 minutes ago
      I struggle to believe that someone would find it worth that much money to have a decompiled version of a game they also commit to keeping private.
      • girvo 36 minutes ago
        > they also commit to keeping private

        Reading between the lines:

        "The avid reader of my blog might have noticed that I had previously written two posts that have since been removed. Everyone else might now be wondering which game I am talking about. To both of you I can only say that corporate America was here to ruin our fun."

        Keeping it private likely wasn't the original plan...

    • TomatoCo 41 minutes ago
      Where are you getting 150-400 per million input?

      https://developers.openai.com/api/docs/pricing https://platform.claude.com/docs/en/about-claude/pricing

      OpenAI and Mythos are both 10/mil in.

      https://openrouter.ai/z-ai/glm-5.3#providers https://openrouter.ai/moonshotai/kimi-k3#providers Other frontier models are like 1-3/mil in.

      Also, 500 billion is 500,000 millions. At the lower end of your 140/mil estimate that's 70 million dollars. Even at my 2/mil lookup for Chinese frontier models that's one million. Show your math for 100k-750k, please.

    • GaggiX 23 minutes ago
      The vast majority of these tokens are cache input tokens so even at API price the cost would be much lower.
      • thway15269037 1 minute ago
        Even with 95% cache hit, and on cheapest chinese model, it would still be in tens of thousands of dollars (I assume that of 500B tokens at least 10B would be in "output"). If we switch gears to Kimi K* then if would very quickly escalate in hundred thousands USD.