Ask an agent how a feature works in an app you cannot read the source of, and in 2026 you can get a real answer. That is the promise behind REA, short for Reverse Engineer Anything, the open-source project from morluto that now shows 33.4k GitHub stars, 4.1k forks and 32 releases. Its latest release, v6.1.0, shipped on October 9, 2026.
We already covered what REA's setup changes on your machine. This post asks a different question: what do its published case studies actually prove? Stars measure interest. Case studies measure results, and they are more modest, and more useful, than the headline.
TL;DR: what the evidence shows
| Question | Short answer |
|---|---|
| What can an agent recover? | Formulas, call chains, IPC channels and data formats, with the addresses and bytes behind each claim |
| What is the strongest proof so far? | DX-Ball: a recovered C function matched the original x86 code on 3,205 test cases and 63 compiled bytes |
| Does it need source code? | No. It reads binaries, Electron bundles, websites, APKs and .NET assemblies |
| Is it fully automatic? | No. Every case study names manual reading, pinned versions or reviewed relocations |
| Does it send my app to a server? | REA analyzes locally; your agent receives the tool output, so your model provider's data policy applies |
| Who should try it? | People who want to learn how a feature works, audit their own old code, or rebuild a behavior from evidence |
What is the idea, in plain terms?
Reverse engineering used to mean a person in a disassembler, reading assembly for days. REA connects an agent to that disassembler (Hopper, Ghidra or IDA for native code) and to static analyzers for JavaScript and .NET. The agent asks the tools questions, collects findings, and reports them with the evidence attached.
The README's example prompt is the whole pitch: "Understand how search works in the Notes app, show me the evidence, and build a similar feature for my project." The agent does the tracing. You get an explanation, the code locations, and a list of what is still unknown.
If you are new to how agents talk to tools like this, our MCP explainer covers the plumbing. You do not need it to follow the rest of this post.
Blueprint with a traced route showing how reverse engineering maps an unknown app's internals
Case study 1: DX-Ball and a sound-pan formula
The question: how does the 1990s game DX-Ball turn a brick's horizontal position into a left or right sound pan? The case study reports these steps.
- The decompiler view of the function at
0x406400showed only a call to__ftol()with no visible input. The instructions revealed the missing argument at[EBP+8], loaded withFILD. - The caller at
0x411f40computes20 + 30 × tile_x, the brick's screen coordinate. - Reading bytes from memory gave three constants: 1.5625, 500.0 and an initial pan scale of 1.0.
The recovered rule: convert the screen coordinate to a double, multiply by 1.5625, subtract 500.0, multiply by the stored pan scale, and truncate. At a scale of 1, the study reports the result is −500 at the left edge, 0 at the center and 500 at the right edge.
This is the part that matters for trust. The author did not just read the code and announce a formula. They ran 3,205 cases through both the original x86 function and the new C version, covering every position from 0 to 640 at pan scales 0, 0.5, 1, 20 and −1. Under a pinned VC4.0 toolchain, the function's compiled bytes also matched the original: 63 bytes, after applying reviewed relocations. The wider project reports 55 maintained C functions and 45,380 comparisons against the original.
What it does not prove. The study states that the next step, wiring the pan value into the game's sound backend, is still pending. The playable game is incomplete, the work is tied to DX-Ball 1.07 with a pinned hash, and the compiler replay "depends on reviewed relocations and checked constants," so it is not fully automatic.
A bug card connected to a patch, representing a recovered function checked against the original with tests
Case study 2: how Notion copies to your clipboard
The second study moves from a 1990s binary to a modern Electron app. The question: how does Notion Desktop 7.6.1 copy text and HTML to the system clipboard?
The path has four stages. The preload script exposes clipboard.write to the page. A wrapper calls ipcRenderer.invoke on a channel. An ipcMain.handle receiver in the main process picks it up. After a sender check, Electron's clipboard.write puts text and HTML on the clipboard. The packaged code uses one channel name on both sides, notion:clipboard:write.
Two findings are worth knowing, even if you never touch Notion:
- The sender check is real. The main-process handler checks which page sent the request, and only Notion's own web contents reach the clipboard write. That is the right pattern for any Electron app.
- Copies carry hidden block data. The HTML includes a comment,
<!-- notionvc: <copy-id> -->, that points to block data Notion stores locally under a custom MIME type,text/_notion-blocks-v3-production. On paste, matching IDs restore the block data. If the saved entry is stale, paste falls back to text and HTML only.
What it does not prove. REA 4.1.0 analyzed the tab preload and found the exposed API and the invoke call. The author then read the wrapper implementations by hand to link the channel to the receiver. The clipboard-format findings come from web assets cached on July 13, 2026, checked with saved probes and test harnesses, not from a captured live desktop session.
Case study 3: a PC-98 bullet ring
The third study, TH04, goes back to 16-bit DOS code from a PC-98 game. REA's Ghidra provider supports 16-bit DOS analysis. The author recovered the fixed and aimed angle calculations behind a bullet-ring pattern, rebuilt them in C++, and compared the result with the historical compiler's output. The reconstruction lives in a separate repository.
This is the same shape as DX-Ball: recover a small calculation, rebuild it, then check it against the original rather than trusting the explanation.
What do these three have in common?
Read them side by side and a pattern shows up. It is a better guide to using REA than the star count.
| Pattern | DX-Ball | Notion | TH04 |
|---|---|---|---|
| Narrow question | One pan calculation | One clipboard path | One bullet ring |
| Evidence attached | Addresses, constants, 3,205 tests | Channel names, handler code, saved probes | Instructions, compiler comparison |
| Manual step admitted | Reviewed relocations | Hand-read wrappers | Compiler matching |
| Pinned target | DX-Ball 1.07 with hash | Notion Desktop 7.6.1 | Original PC-98 binary |
Every study asks a small, answerable question. None says "rebuild the whole app." That is the honest scope today: an agent is a fast, tireless assistant for tracing one behavior, and the proof comes from tests you can rerun.
Why this matters if you build with agents
Agents already port and rebuild software from partial specs. We covered one example when Claude Fable 5 helped port Command & Conquer Generals to macOS and iPad, and another when a developer recreated an iPhone animation on Android. Those tasks began with readable source or a recorded demo. REA pushes the same loop one step further down: the input is a compiled program.
Three practical uses stand out:
- Understanding your own legacy code. If your team lost the source for an old tool, an agent can recover the behavior and write tests around it.
- Learning how a feature works. Tracing a clipboard bridge or an IPC channel teaches more than reading a blog post about it.
- Security review of apps you ship or depend on. The same trace that explains a feature can show what an Electron app exposes to its pages.
The legal side is real. REA's disclaimer says it provides tools for lawful research and that you must obtain any required authorization. Recovering a formula to learn from is not the same as cloning a product, and the clean-room question comes up quickly. For a related fight over copying versus building, see our PhotoCraft coverage.
Try it on something small
REA says to start with npx rea-agents setup, review the proposed changes, and restart your agent. Then pick a question like the case studies do, not a whole app. Here are prompts in that style:
Using REA, inspect this Electron app directory and tell me which IPC channels
the renderer can call, which handler receives each one, and whether the handler
checks the sender. Show the file and line for each claim and list what you
could not confirm.
Find the function that computes the damage number in this binary. Show the
instructions, the constants you read, and write a C version. Then write a test
that runs both and compares the outputs on at least 1,000 inputs.
The second prompt copies the DX-Ball method: recover, rebuild, then test against the original. Ask for the unknowns every time. A report that says "could not confirm" is more trustworthy than one that sounds certain.
If you want hands-on practice directing agents through multi-step work like this, our workshops cover agent workflows from setup to review.
Where the hype outruns the evidence
A few honest limits before you read "reverse engineer anything" literally:
- Targets are pinned. Each study names exact versions and hashes. A new app release can change addresses and break the trace.
- Pseudocode can mislead. In DX-Ball the first decompiler view hid the input to the function. The instructions revealed it. An agent that trusts pseudocode alone can be confidently wrong.
- Native analysis needs a disassembler. You need Hopper, Ghidra or IDA installed and configured. Hopper may show a first-run dialog on macOS.
- The tool moves fast. The README itself warns that REA "changes quickly" with frequent bug fixes, so keep it updated.
- A recovered formula is not a product. DX-Ball still lacks physics, power-ups and sound integration. Recovering one function is a long way from a rebuilt game.
Also be careful with permissions. REA's setup edits agent configuration, and its runtime capture runs targets with your user permissions. The companion post walks through what to review. For commands you will use while testing, see our Claude Code command reference.
What this means for what you build
If you build software, assume that behavior shipped in a binary or an Electron bundle is more readable than it used to be. That is not a reason to panic. It is a reason to keep secrets out of client code, check senders on IPC handlers like Notion does, and treat obfuscation as a speed bump.
If you learn or teach software, this is a new kind of exercise: give students a small binary, ask them to explain one function, and require tests as the proof.
Frequently asked questions
What is REA and why did it get so many stars? REA (Reverse Engineer Anything, npm package rea-agents) lets a coding agent inspect binaries, Electron apps, websites and APKs and report findings with evidence. It shows 33.4k stars and 4.1k forks as of October 9, 2026.
Can an AI agent reverse engineer any app on its own? No. The Notion case study needed hand-reading to connect a channel to its receiver, and every study uses a pinned target. The agent speeds up the search; a person judges the result.
What did the DX-Ball case study prove? A recovered C function matched the original x86 code on 3,205 cases, and its compiled bytes matched for all 63 bytes under a pinned VC4.0 toolchain, after reviewed relocations.
Do I need Ghidra or Hopper? For deep native analysis, yes: Hopper, Ghidra or IDA. Static JavaScript and .NET inspection do not need one.
Is it legal? It depends on your jurisdiction, the software's license and your purpose. REA's disclaimer puts the responsibility for authorization on you.
Related reading
- REA MCP server: what agent reverse engineering changes in your setup
- What is MCP? The Model Context Protocol guide
- Claude Fable 5 ports Command & Conquer Generals to macOS and iPad
- Recreate the iPhone Duo Fold animation on Android
- PhotoCraft: open-source Rust Photoshop clone and the clean-room question
- Claude Code commands: complete reference
- Official: REA on GitHub · DX-Ball case study · Notion case study
Star counts, versions and case-study details are accurate as of October 9, 2026. REA releases frequently, so check the repository for current behavior.
