Thomas Dullien: The Reverse Engineer Behind BinDiff
In reverse engineering there's a tool so standard that its name became a verb. When a vendor ships a security patch and says nothing about what it fixed, researchers "bindiff" it: feed the old binary and the new one into BinDiff, and the silently patched bug lights up.
The man who built it is a German mathematician named Thomas Dullien, better known by a hacker handle borrowed from a children's cartoon about Vikings. As Halvar Flake he trained American government analysts, sold his company to Google, helped turn a quirk of computer memory into a working exploit and gave a Black Hat keynote on why we aren't building a defendable internet.
Then he walked away from security entirely. Where he turned up in 2026 says a lot about where security is going.
Thomas Dullien at a Glance
- Dullien grew up in Germany taking apart other people's compiled programs as a teenager; friends nicknamed him Halvar, after the Viking chief from the village of Flake in the cartoon Vicky the Viking.
- Trained as a mathematician, he won the Horst Görtz Prize in 2006, then Germany's largest privately funded research prize in the natural sciences, for work on graph-based code similarity.
- That work became BinDiff, sold by the company he founded in Bochum in 2004, first called SABRE Security and later zynamics, where he was CEO and head of research.
- In July 2007 U.S. customs refused him entry on his way to teach at Black Hat, found his printed training materials and put him on the next flight back to Germany.
- Google bought zynamics in March 2011, when Dullien had just turned 30; Google later made BinDiff free in 2016 and open source in 2023.
- In 2015 he and Mark Seaborn published the Project Zero exploit that turned the Rowhammer memory flaw into kernel privileges; he later worked on Project Zero and left Google at the end of 2018.
- In 2019 he started optimyze.cloud, a Swiss continuous-profiling company with no security angle at all, which Elastic acquired in 2021; he left Elastic in January 2024 for an extended break.
- In August 2026 he joined OpenAI to work on what he called "better cyber" and efficiency.
The Life of Thomas Dullien
A Viking Named Halvar
Thomas Dullien's handle came first. As a teenager in Germany his friends started calling him Halvar, after the burly village chief in Vicky the Viking, a cartoon beloved of German children, and the village's name, Flake, completed it. By then he was already disassembling other people's compiled software to see how it worked.
He studied mathematics at Ruhr University Bochum, and the mathematics mattered. His idea was to treat a program as a graph and compare two programs by their structure rather than their bytes, which meant you could line up two versions of the same software even after the compiler had rearranged everything. In 2006 the work won him the Horst Görtz Prize, at the time the biggest privately financed research prize in the natural sciences in Germany.
BinDiff
Dullien founded a company in Bochum in 2004 to sell the idea. SABRE Security, later renamed zynamics, shipped BinDiff and its sibling BinNavi, and its founder spent the Black Hat season teaching reverse engineering to students who, as ZDNet put it, were "mostly working on US National Security in some form."
BinDiff solved a problem every vulnerability researcher had: vendors often patched bugs quietly. Compare the binary before and after the patch, and the fix, and therefore the bug, falls out. The industry started saying "bindiff it," and a verb was born.
Sent Home at the Border
In July 2007, on his way to Black Hat in Las Vegas, Dullien got off a nine-hour flight from Germany and spent four and a half hours being interviewed by U.S. immigration officials. Customs had found printed training materials in his suitcase, and the problem, he said, appeared to be his use of the visa-waiver program to present Black Hat training as a private citizen rather than a company representative.
They put him on the next nine-hour flight home. "I have trained people from the DoD, DoE, DHS and most other [government] agencies that come to mind," he told ZDNet, which noted that he'd presented at Black Hat for seven straight years and at Microsoft's internal Blue Hat conference. He wrote up the whole ordeal on his blog.
Google Buys the Toolmaker
On March 1, 2011 Dullien posted a blog entry titled simply "Wow ...": the company "that produces your favourite security researchers' favourite tools has been acquired by Google." He admitted to being surprised: zynamics wasn't web-centric and was far from Google's core business, and he'd spent years on sales and on finding resources for his team instead of on technical work. "I wanted the chance to focus on technical issues again," he wrote.
He'd just turned 30. Google eventually cut BinDiff's price to nothing, announcing in March 2016 that the tool was free, and in September 2023 released it as open source, so the verb now belongs to everyone.
Hammering on Memory
The technical focus paid off in 2015. Rowhammer was a known quirk of DRAM: hit one row of memory cells often enough and bits in neighboring rows flip.
Most of the industry filed it under reliability.
Dullien and Google's Mark Seaborn filed it under exploitation.
Their March 2015 Project Zero post, "Exploiting the DRAM rowhammer bug to gain kernel privileges," showed bit flips in page-table entries handing an unprivileged process full control of a Linux machine, with no software bug involved at all. Seaborn credited Dullien with "double-sided hammering," with measuring how many machines were affected and with filling in the exploit details. Hardware vendors have been issuing mitigations ever since.
Dullien later worked on Project Zero itself, Google's elite bug-hunting team, and in 2017 gave a Black Hat keynote, "Why We Are Not Building a Defendable Internet." Its thesis has aged well: offensive problems are technical, but most defensive problems are political and organizational, and the talk walked through the economics and incentives that keep it that way. In 2018 he was writing about "weird machines," the theory that a bug turns a program into an unintended computer that an exploit then programs.
Leaving Security
He left Google on December 31, 2018 and in February 2019 started optimyze.cloud, a Swiss startup he hoped would align "my ecological, economic, and technical interests." It had nothing to do with security.
Its product was a lightweight profiler for fleets of Linux machines that showed, without changing a line of code, which lines were burning the CPU. Andreessen Horowitz led a seed round in April 2020, and in October 2021 Elastic bought the company.
The deal came with a private cost he later wrote about publicly: the day it closed, his mother fell into a coma, and she died on New Year's Day 2022. On January 31, 2024 he posted "The end of my Elastic/optimyze journey", announcing an extended break to "focus on rest, family, health, writing, a bit of startup mentoring/investing, and some research."
Back in the Game
The research turned out to be about AI. By 2025 he was demonstrating how to optimize PyTorch with an AI coding agent and contributing to Raptor, an open-source framework that uses agentic workflows to find bugs and generate patches. In March 2026 his blog offered "slightly safer vibecoding by adopting old hacker habits," and in August 2026 he went on a podcast to argue that vulnerability research "is not cooked."
That same month he joined OpenAI. "I have a personal update: Next monday, I will be starting at OpenAI," he posted on August 4, describing the job as "better cyber" with some "efficiency work" mixed in.
He started on August 10. Two weeks later his blog noted that he'd "recently joined a company that skews younger-than-me."
Thomas Dullien: Not Cooked Yet
Dullien's career traces the arc of modern security itself: from lone reverse engineers trading tricks, through toolmakers and acquisitions, to a world where the most consequential code is written by machines and the people who used to break software are hired to keep the machines honest.
He walked away from security once and came back anyway, which suggests the field is harder to leave than it looks.
BinDiff is free, the verb is permanent, and the Viking now works at OpenAI.
QUOTE:
"Amateurs hack systems, professionals hack people."