Remix.run Logo
▲ 500B Tokens Later: Letting AI Agents Decompile a First-Person Shooter(momo5502.com)
73 points by davikr 4 hours ago | 56 comments
▲brandonpelfrey 4 hours ago | parent | next [-]

Unless you explicitly need byte-matching decompilation, there are significantly faster ways to produce a decompilation/C which is functionally equivalent. I need to post about this. What's been working for me is that for every function, Agent A is tasked with writing some code which is semantically equivalent to the original assembly, but not necessarily exactly the same. Agent A also writes tests. Agent A submits the implementation of the function and tests to the harness for it to judge. The harness runs both the original function and the submitted function in a virtual machine/simulator/emulator (the tests define function inputs and starting state). The harness will only accept the implementation if 1) the read/write sequence to RAM is identical to the original function's, and 2) there must be complete line and branch coverage of the original function being decompiled.

I've found this to be robust for decompiling games, while giving the agents enough freedom to write code that is readable and not waste a ton of time making sure e.g. instruction ordering, register assignments, etc. are all exactly the same. For me, having byte-matching decompilation is only one way to produce a decompilation I know is faithful to the original. This "high-level decompilation" process I just described is something agents can do much more quickly.

▲j2kun 4 hours ago | parent | next [-]

Functional equivalence here, of course, depends on the completeness of the test suite, where byte-identical compiled artifacts does not.

(For example, your approach would not necessarily catch all the same overflow behaviors; the OP expressly claimed that "replicating all bugs" was also important, and many bugs are caused by certain overflow behaviors)

▲nine_k 2 hours ago | parent | next [-]

> catch all the same overflow behaviors

So you're looking not just for functional but also dysfunctional equivalence %)

▲8note an hour ago | parent [-]

no, thats still functional here. the bugs have to be the same, such that speed runs could still run correctly

▲SubiculumCode 4 hours ago | parent | prev [-]

Byte exact seems only of interest to preserve known bugs etc for cheats/shortcuts/etc.

▲j2kun 4 hours ago | parent | next [-]

That may be true, but I hate it when people repeat the false idea that functional equivalence requires only a test suite that has full branch/line coverage. Call me triggered :)

That said, I would probably follow this same approach if I were to do this, but with extensive randomized testing as well.

▲hedgehog 3 hours ago | parent [-]

You can do the process in stages. Do the first decompilation mechanically (no LLM), use a SMT solver to show it builds to an equivalent binary to the original, and then use LLM to clean up the code into something idiomatic with the benefit of a correct binary built with the new toolchain. This helps when you want to port across languages or toolchains, and helps protect against toolchain bugs.

▲kg an hour ago | parent | prev [-]

For anything with recorded replays or multiplayer you need to preserve known and unknown bugs for compatibility reasons, not just for cheating.

▲SubiculumCode 4 hours ago | parent | prev [-]

So you restricted it to implementing the same function (same inputs,outputs, dependencies as original?) and prevented the agents from making design decisions by keeping it's scope restricted?

▲brandonpelfrey 3 hours ago | parent [-]

Yes. It can gain more context, but this has been enough. Note, there is also a notion of adversarial review layered on top in which it tries to poke holes in the test plan "you didn't handle this case of XYZ". It isn't actually perfect as a parallel thread said it may miss things like wrapping behaviors. In practice, it's very effective.

▲nvme0n1p1 3 hours ago | parent | prev | next [-]

> The avid reader of my blog might have noticed that I had previously written two posts that have since been removed. Everyone else might now be wondering which game I am talking about. To both of you I can only say that corporate America was here to ruin our fun.

Call of Duty: Modern Warfare 2 (2009)

https://web.archive.org/web/20260925153118/https://momo5502....

https://web.archive.org/web/20260925153131/https://momo5502....

Come at me, corporate America.

▲ares623 an hour ago | parent [-]

Friendly reminder that corporate America came at Aaron Swartz.

▲aetherspawn 3 hours ago | parent | prev | next [-]

The reason this cost so much is because the AI has the ridiculous goal of getting identical assembly output.

The agents would have had to mess around with compiler versions, optimisation options, and the phase of the moon as well.

If you just went for functional equivalence, it would probably cost 10x or 100x less tokens.

Another false economy was using Sonnet instead of a more intelligent model like Sol 6.1 (1), which would have cost more per token, but is 100x or so better at reverse engineering and coding and therefore can chew through the source code much quicker and make fewer mistakes, meaning less work needing to be scrapped.

In my testing doing a similar task, I ran multiple sonnet for weeks and burnt through ~$1000 in tokens to get 20% completion and output that was pretty bad. After switching to Sol 6.1, it finished the whole task in around 2 days, cost around $50, and it did it with zero supervision and a single /goal.

(1): struggle to use Opus for reverse engineering, too many safeguards. OAI has virtually none, and uses way less tokens so is more economical.

▲Gigachad 3 hours ago | parent [-]

Identical output isn’t ridiculous. It’s pretty much a requirement to ensure the game actually is the same in every way. These decomp projects are pitched as a high performance alternative to emulation.

No one is going to use it if it’s a kind of close but not really reimplementation.

Testing functional equivalence is also pretty much impossible. How would you for example test the new one has exactly the same bugs which haven’t been discovered yet. Or doesn’t introduce new ones? This stuff matters for speed runners.

▲aetherspawn 3 hours ago | parent [-]

It’s ridiculous because something as simple as the compiler picking different registers is going to make zero functional difference but give a false negative on assembly compare.

Yet the C code can’t pick what registers to use, so the poor agent is probably shuffling the code around randomly for hours or days until it matches.

That’s probably why the agent dropped down into inline assembly in the first place (the author complained about this), because I bet it’s thinking trace was that this is futile.

Compilers themselves are not even deterministic and running them multiple times creates different assembly.

▲edg5000 3 hours ago | parent | prev | next [-]

I sense the approach overcomplicates things. I wonder how long this would have taken in a single session. Maybe this is actually a textbook example of something where subagents make sense, but when I first started LLMs I was often overcomplicating the workflow with all kinds of orchestration. Now I just use one agent, it better allows controlling the output even if the agent works slightly longer. Most time is spent by me writing prompts and reviewing work anyway (for me at least).

▲hansvm 2 hours ago | parent [-]

The best models have O(1k tokens per second). A billion tokens, sequentially, takes 1-2 weeks. 500B takes 500x that ... not fast. The problem might not have required 500B tokens, but if it needed anything within a couple orders of magnitude then something like the given approach (or anything else yielding equivalent results in exchange for parallelism) was mandatory.

▲speedstyle 2 hours ago | parent [-]

Yeah, I don't think the problem needed billions of tokens

▲hansvm an hour ago | parent [-]

That's plausibly true. I've definitely seen absurd token costs abused and wasted. I've also seen simple problems require absurd token counts regardless of prompt quality. Which factors made this problem require 1000x fewer tokens than they used?

▲WheelsAtLarge 3 hours ago | parent | prev | next [-]

Interesting, if all software can be decompiled and copied what is the future of software. Will all software be SaaS? A time where the majority of PCs will be terminals? Game consoles are almost there. It's only a small jump for all software to go that way.

Edit: Here's a possibility.

The future of software is agent only software. We ask for a result, agent asks questions from us, agent uses the specialized software, user gets result. We subscribe to an AI assistant and specialized agents. We are almost there,at least the start. The future of PC's as we know them are numbered. OSs,CLI,compilers and whatever will melt into AI assistants. Say goodbye to writing software for people.

▲vagab0nd 2 hours ago | parent | next [-]

Non-SaaS, close sourced software is already dead, no? I think pretty soon we'll all be using bespoke software written by the AIs. I already use throwaway software designed for each job because it's so cheap to do so.

▲edg5000 2 hours ago | parent | prev | next [-]

I wonder about this too. Although, cracking was always possible. So what changed is that people can now modify, improve proprietary software with zero technical knowledge. I can now tell Astra or Fable (maybe not Fable because of safeguards?) to add a feature to Adobe Photoshop and it might actually succeed even when prompting purely on a functional level (e.g. the functionality I want out of the program). It would take days, but I think it would succeed. Call it PhotoBench?

▲unsnap_biceps 3 hours ago | parent | prev | next [-]

A future of all SaaS only works if you can't just tell a LLM what you want and get a custom implementation. I've always done a lot of personal projects, but my velocity has increased dramatically and I've replaced a number of projects that I used to pay for with custom ones that work well enough. I can't imagine that SaaS is going to be a viable model unless it involves a community that wants a unified experience, like a multiplayer game.

▲bitwize 3 hours ago | parent [-]

Even then, interact with a SaaS enough and you may be able to "distill" a spec out of it that's sufficient enough for an LLM to replicate it closely enough. If you feed the LLM screenshots or video of people using it, it will be able to recreate it even more accurately.

▲georgemcbay an hour ago | parent [-]

> If you feed the LLM screenshots or video of people using it, it will be able to recreate it even more accurately.

You could just have the LLM agent use the software itself and then duplicate the functionality it finds, don't even need the screenshots or video.

Unless the software is doing something extremely novel, the LLM can just do this all itself after you point it toward a url for the software with instructions to clone what it finds there.

It'll be interesting to see if SaaS companies and/or providers of internet services like Cloudflare try to stop this sort of agentic cloning of SaaS products.

Like, obviously they would kinda want to if/when this sort of thing becomes commonplace, but how do you do it while allowing your software to be agent-friendly for non-cloning uses, and who is going to want to tell their customers they can't use agents with their SaaS for fear of their software being cloned? Kind of a bad situation with either option.

▲Daishiman 3 hours ago | parent | prev [-]

Most software organizations pay for is effectively a SaaS or something where software is a minor part of the artifact and support is where the real money is.

▲thway15269037 3 hours ago | parent | prev | next [-]

I struggle to understand what legal leverage they used to threaten him to remove every detail about the game. Can someone post the game name and company name?

So, if you reverse-engineer game X and post reverse-engineered code, what exactly do you infringe, how and in which jurisdiction? What changes if it is done via LLM?

(I understand that LLM decompilation is absolutely out of hand right now and something surely will come to trample the fun. But what and when? I suppose american LLMs will have their system prompt updated to forbid any reversing help and report suspicious activity straight to legal hotline)

▲xnx 3 hours ago | parent | next [-]

Call of Duty: Modern Warfare 2 (2009) (from a previous version of the page)

▲rasz 2 hours ago | parent | prev | next [-]

>what legal leverage

PIF owns EA, when they invite you to a meeting you might start to worry about foil lined room and carpentry tools lying around

▲bitwize 3 hours ago | parent | prev [-]

> So, if you reverse-engineer game X and post reverse-engineered code, what exactly do you infringe, how and in which jurisdiction? What changes if it is done via LLM?

In 1986 there was a federal court case, Whelan Associates Inc. v. Jaslow Dental Laboratory, in which it was ruled that the "structure, sequence, and organization" of a computer program was protected by copyright, and thus independently produced software could be found infringing if it copied these elements, even if the code were not copied (or mechanically translated) verbatim. This led to a six-year period in which computer software enjoyed generous copyright protection, such that "clones" of copyrighted software were effectively infringing. It wouldn't be until the early nineties that other court rulings would tighten the rules again, notably Computer Associates International, Inc. v. Altai Inc.. The 3-step "abstraction-filtration-comparison" test has been used by most courts since 1992 to determine whether nonliteral parts of program code are eligible for copyright protection, and whether another, independently written program is infringing.

HOWEVER, the Whelan standard was never actually overturned or stricken from U.S. law due to legislation or litigation! And companies have sued and won under the Whelan standard! Most notably, Oracle in their copyright and patent case against Google regarding Java APIs in Android. Google ultimately prevailed, but only because the Supreme Court ruled that Google's use of the APIs was fair use; they did not overturn the Federal Circuit's finding that the "structure, sequence, and organization" of the Java declaration code was ineligible for copyright! And I doubt that the Supreme Court would similarly smile on a reverse-engineered complete video game!

I believe that these reverse-engineered projects infringe copyright, under the Whelan standard and perhaps under the stricter Altai standard as well. You do not get a free pass because the original code was in C and yours is in Rust; or because you created a slightly different version of each function in the original code.

▲thway15269037 2 hours ago | parent | next [-]

That implies US jurisdiction plus that was made at the time where "hey, let's actually reverse-engineer and copy our competitor" was very expensive and time-consuming, so slapping one company would discourage everyone else to sink money in it. Currently it seems the latter is becoming either automatic (still somewhat expensive) or even free.

▲bitwize 2 hours ago | parent [-]

Committing copyright infringement against software vendors was automatic and free before, when it involved merely copying files, maybe after cracking the copy protect. It was still illegal. What makes you think this time would be any different? The fact that an LLM did it? Whatever an LLM produces humans assume responsibility for.

▲thway15269037 an hour ago | parent [-]

When you copy a file, it's trivially simple to prove it's a copy and not an original work.

How can one prove that X is a copy when none of the source code match original? Clean room re-implementations are not illegal after all, if we go that way (yeah, yeah, I know about clean room argument).

While I personally do not think it would be different, but a lot of LLM folks are, and even some companies (rushing to blatantly clone and de-compile stuff). Kinda strange feeling sitting and looking around in the midst of it, y'know.

▲nullpoint420 2 hours ago | parent | prev [-]

Yet AI companies distilling copyrighted books and repositories is somehow okay?

And let's say there's a future where an AI model could zero-shot the game itself. What then?

▲xnx 3 hours ago | parent | prev | next [-]

A previous version of the page said the game was Call of Duty: Modern Warfare 2 (2009).

▲georgemcbay 3 hours ago | parent | prev | next [-]

In case anyone is curious about the obvious question of which game they are talking about... based on months-old reddit posts (which seem like links to prior progress reports of the same project) the game in question appears to be Call of Duty: Modern Warfare 2 (the original 2009 version).

https://www.reddit.com/r/ReverseEngineering/comments/1vxig19...

▲esafak 3 hours ago | parent | prev | next [-]

Can anyone think of any lessons to draw from this for normal development, where we don't have oracles to serve as guardrails? I write specs but the agents still find ways to insert bugs between the lines. Oh well, job security.

▲ashdnazg 6 minutes ago | parent [-]

It's not really comparable. When decompiling you only care about a one time result. Code quality doesn't matter much. Stability doesn't matter much. Only whether the result is accurate. Once you have the matching decompiled code, all tools used until that point will be usually thrown away.

Normal development isn't so lucky, you do care about code quality. So you have to review the code the agents write and handle the testing yourself. The agents will not do what you want, they'll do what they think you want, and you're the only person who knows what you think.

▲vivzkestrel 3 hours ago | parent | prev | next [-]

- i want to very very badly see a post of this using LM studio and one of the open source models

- please someone do it

▲WillAdams 4 hours ago | parent | prev [-]

To save folks looking this up:

>At current 2026 API rates, 500 billion AI tokens would cost roughly $100,000–$750,000 depending on the model, with most flagship models in the $150–$400 per million input tokens range

▲Gigachad 4 hours ago | parent | next [-]

This stuff is all done on highly subsidized subscription plans. I suspect Antropic is quite happy to sell these people $100k of compute for $4k because it boosts their growth numbers and they can tell investors once they stop subsidizing, this will grow to $100k. Despite the fact that most of this stuff simply wouldn't be done without the subsidization.

▲chii 3 hours ago | parent [-]

the exact same arguments were said about uber's business at the start.

Yet, it is now profitable.

The bet is that people realize how valuable these services are, and despite complaining, they still would pay the higher price. This realization would not happen without this initial subsidy from investors.

It isn't too different from drug dealer's first sample free...

▲thway15269037 3 hours ago | parent | next [-]

Uber business model wasn't a subscription "for 10 bucks you can travel 900 lightyears a week"

▲nmfisher an hour ago | parent | prev | next [-]

Last I checked, Uber underperformed the S&P index since its IPO. Even Softbank didn't make a great return on its investment. The growth story was definitely oversold.

Also, Uber was peak ZIRP + COVID, money was cheap and growth was easy. I think the mountain to climb is a lot steeper now.

▲Gigachad 3 hours ago | parent | prev [-]

There’s also examples where this didn’t work. Moviepass for example.

Taxis were an established profitable business model and the uber subsidisation wasn’t anywhere near as much as AI subsidies.

▲0x457 39 minutes ago | parent | next [-]

Moviepass failed because they thought it's going to be like Gym membership - people buy and don't go, but guess what? People love going to movie theaters. On its own its not bad, see AMC Stubs, but AMC owns the theater, they sell you popcorn and soda. OpenAI an Anthropic is closer to AMC than Moviepass.

▲isubkhankulov 3 hours ago | parent | prev [-]

Disagree with your second paragraph. Uber/lyft subsidized into deep negative margin territory around ~2015 or so. Anthropic (and OpenAI) are subsidizing but not losing money on these consumer plans.

▲edg5000 2 hours ago | parent [-]

> subsidizing but not losing money

????

▲Gigachad an hour ago | parent [-]

It's profitable if you don't count the expenses.

▲oblio 22 minutes ago | parent [-]

I think you're joking but that's Amodei & co are claiming with a straight face.

▲j2kun 4 hours ago | parent | prev | next [-]

I struggle to believe that someone would find it worth that much money to have a decompiled version of a game they also commit to keeping private.

▲girvo 4 hours ago | parent [-]

> they also commit to keeping private

Reading between the lines:

"The avid reader of my blog might have noticed that I had previously written two posts that have since been removed. Everyone else might now be wondering which game I am talking about. To both of you I can only say that corporate America was here to ruin our fun."

Keeping it private likely wasn't the original plan...

▲TomatoCo 4 hours ago | parent | prev | next [-]

Where are you getting 150-400 per million input?

https://developers.openai.com/api/docs/pricing https://platform.claude.com/docs/en/about-claude/pricing

OpenAI and Anthropic are both 10/mil in.

https://openrouter.ai/z-ai/glm-5.3#providers https://openrouter.ai/moonshotai/kimi-k3#providers Other frontier models are like 1-3/mil in.

Also, 500 billion is 500,000 millions. At the lower end of your 140/mil estimate that's 70 million dollars. Even at my 2/mil lookup for Chinese frontier models that's one million. Show your math for 100k-750k, please.

▲WillAdams 3 hours ago | parent [-]

It was a search for "average cost of 500 billion ai tokens" which may or may not have been the correct phrasing, but seemed straight-forward enough that at first blush, accepting the AI-generated answer seemed reasonable.

▲GaggiX 3 hours ago | parent | prev [-]

The vast majority of these tokens are cache input tokens so even at API price the cost would be much lower.

▲thway15269037 3 hours ago | parent [-]

Even with 95% cache hit, and on cheapest chinese model, it would still be in tens of thousands of dollars (I assume that of 500B tokens at least 10B would be in "output"). If we switch gears to Kimi K* then if would very quickly escalate in hundred thousands USD.