Verifying all of nixpkgs would cost ~$400M, Theorem study estimates

ChrSzegedy · x · 2026-10-01

Theorem researchers published a back-of-envelope study on what it would cost to formally verify all software, using the nixpkgs bootstrap chain as a blueprint.

The team argues verification should happen at the binary level on real production systems (glibc, OpenSSL, curl), with human review scaling with behavioral complexity, not code volume. Global cybercrime damages are estimated at $500B/yr, dwarfing the cost.

Related event: Study Estimates Verifying All of nixpkgs Would Cost Hundreds of Millions(2 posts)→

Original post →

More from Research

Research channel →