News
ATHENE UP26@it-sa finalists: An interview with Fuzzware
Fuzzware is one of the five finalists for the ATHENE UP26@it-sa Award
On stage in Miami, the team hacked into the US power grid live and realised afterwards that critical infrastructure needs more robust security testing. Today, Fuzzware automatically tests the firmware of embedded systems for vulnerabilities, without the need for a physical device or source code. In this interview, the founders explain how a successful hack led to the creation of a company – and what the most difficult step in the process was.

Your start-up in one sentence?
Fuzzware automatically identifies security vulnerabilities in embedded software without the need for physical hardware – before insecure devices are shipped.
#FirmwareSecurity #Fuzzing #Rehosting
When did you first realise with absolute certainty: ‘This is exactly what’s missing from the market’?
When we successfully hacked the US power grid on stage in Miami, it became clear to us that critical infrastructure and other embedded systems finally need robust security testing – and that this must be carried out using high-tech solutions!
How big is your team, who’s in it, and how did you all meet?
There are currently nine of us. A few years ago, Simon Wörner and I co-founded the field of research on which our technology is based. We first met at hacking competitions such as the DEF CON Finals in Las Vegas, NASA’s Hack-a-Sat and Pwn2Own. Today, our team combines expertise in firmware security, product development and sales. What sets us apart is the combination of scientific depth and practical experience of carrying out attacks.
Whose life (or everyday work) do you make noticeably easier?
We support manufacturers and security teams in sectors such as the automotive industry, medical technology, the Internet of Things (IoT) and critical infrastructure. Fuzzware tests firmware without the need for the device itself or the source code, and delivers reproducible results that finally enable vulnerabilities to be identified and rectified. Ultimately, this benefits patients as well as anyone who relies on a cyber-secure car or the electricity grid.
Where do you think you’ll be in a year’s time, if everything goes well?
We are expanding the range of supported architectures and integrating Fuzzware more closely into development, CI/CD and compliance processes. Within a year, continuous firmware fuzzing is set to become an integral part of product development at several leading European manufacturers.
What’s your secret strength that the competition doesn’t have?
Our trump card is our automatic hardware modelling: it enables us to test complete firmware without the need for a physical device, source code or time-consuming manual configuration. This is the result of years of cutting-edge research and practical hacking experience at a very high level.
What have been the biggest successes and challenges so far?
This year, we won the ‘Master of Pwn’ world championship title at Pwn2Own, along with prize money of 215,000 US dollars, by successfully identifying and reporting a series of vulnerabilities in electric vehicle devices whilst on stage in Japan.
The biggest challenge for us is the transition from a research project to the industrial sector. We are proud to have successfully achieved milestones such as our first trade fair stand and our first negotiation call, with the help of our coaches.
What gave you the final nudge to click ‘Apply’ for the ATHENE Startup Award UP26@it-sa?
Our coach Philipp, who drew our attention to the ATHENE Startup Award UP26@it-sa as a brilliant opportunity. We’re really glad we listened to him and are now delighted to be through to the final. :-)
show all news
