AI Hedge Fund is a proof of concept for running a stock portfolio with language-model agents. Strategies are built from "models": LLM personas of Warren Buffett, Charlie Munger, Benjamin Graham, Peter Lynch and Stanley Druckenmiller that each read fundamentals and earnings and return a conviction score with a written thesis, plus systematic quant models such as post-earnings drift. A strategy blends their signals, a fund allocates capital across strategies, and a terminal app lets you backtest a fund against a benchmark or run it as a paper-trading fund that advances one market session at a time with fake money.
Virat Singh (virattt) started it in late 2024 and it has about 64,000 stars, helped by TikTok creators who featured it in AI-trading videos. The current 2.x version is a rebuild: install it with pipx as aihf, and every paper session is appended to a hash-chained ledger in your home folder so the track record cannot be quietly reset. It is MIT-licensed and the README is blunt: it is for education and research, it places no real trades, and it is not investment advice.
- Repository: github.com/virattt/ai-hedge-fund
- Licence: MIT (MIT License)
- Language: Python. Stars: 63.8K. Forks: 11.2K. Last push: Oct 2, 2026.
- Scan: safe, Oct 2, 2026, commit 78b779c
Who it is for
Developers and finance students curious how multi-agent LLM systems reason about stocks, and anyone who wants to test an investing idea on paper before trusting it.
Getting started
1. Install the CLI (or: uv tool install aihf)
pipx install aihf2. Launch the terminal app; it asks for a Financial Datasets key and one model key on first run
aihf3. Or run it from source
git clone https://github.com/virattt/ai-hedge-fund.git && cd ai-hedge-fund && poetry install && poetry run aihfYou need a Financial Datasets API key for prices and fundamentals and one model key (Anthropic, OpenAI, DeepSeek, Google, xAI or Kimi). Keys are saved in plain text to ~/.hedge-fund/.env. Every agent call costs tokens, so long backtests over many tickers add up.
Safety scan
We cloned virattt/ai-hedge-fund at commit 78b779c on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no pattern hits, no committed binaries and no install hooks across 115 files and about 17,500 lines of Python.
- The network hosts are the ones you configure: api.financialdatasets.ai for market data and the model providers (Anthropic, OpenAI, DeepSeek, Google, xAI, Kimi, TypeSafe). There is no brokerage integration; the brokers folder holds a simulator and a paper ledger only.
- poetry.lock pins 108 packages with 12 known advisories (1 critical, 4 high). The critical and one high are in black, the code formatter, a development tool. The LangChain path-traversal advisory concerns legacy prompt-loading functions this project does not call, and the urllib3 ones affect streaming and proxy edge cases.
- API keys are saved in plain text to ~/.hedge-fund/.env, which is fine on a personal machine but worth knowing on a shared one.
- No workflows, so no CI to review. Licence present; no security policy, Dependabot, CodeQL or contributing guide.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | None. |
| CI workflows | No GitHub Actions workflows. |
| Network hosts | 5 distinct hosts referenced from source; most often api.financialdatasets.ai, mba.tuck.dartmouth.edu, api.typesafe.ai, api.moonshot.ai. No URLs to bare IP addresses. |
| Known vulnerabilities | 12 advisories across 108 pinned packages: 1 critical, 4 high, 5 moderate, 2 low. poetry.lock: 108 packages, 12 advisories. |
| Project hygiene | Has licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Worst known vulnerabilities (12 of 12)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-v53h-f6m7-xcgm | critical | black@23.12.1 | |
| GHSA-3936-cmfr-pm3m | high | black@23.12.1 | |
| GHSA-qh6h-p6c9-ff54 | high | langchain-core@0.3.86 | LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions |
| GHSA-8988-9cw3-xx77 | high | urllib3@2.7.0 | urllib3: HTTPS proxy TLS configuration may be ignored or overridden |
| GHSA-vxq7-64xx-v4gw | high | urllib3@2.7.0 | urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory |
| GHSA-fj7x-q9j7-g6q6 | moderate | black@23.12.1 | Black vulnerable to Regular Expression Denial of Service (ReDoS) |
| GHSA-gr75-jv2w-4656 | moderate | langchain-anthropic@0.3.5 | LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders |
| GHSA-6w46-j5rx-g56g | moderate | pytest@7.4.4 | pytest has vulnerable tmpdir handling |
| GHSA-mf9w-mj56-hr94 | moderate | python-dotenv@1.0.0 | python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback |
| GHSA-gh4c-6fx4-qh6g | moderate | urllib3@2.7.0 | urllib3: Chunked Deflate streaming can enter an infinite loop |
| GHSA-2g6r-c272-w58r | low | langchain-core@0.3.86 | LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages |
| GHSA-r7w7-9xr2-qq2r | low | langchain-openai@0.3.35 | langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding |
By the numbers
| Stars | 63.8K |
|---|---|
| Forks | 11.2K |
| Contributors | 49 |
| Commits | 937 |
| Open issues | 55 |
| Open pull requests | 121 |
| Releases | 16 |
| Latest release | v2.5.0 |
| Licence | MIT |
| Main language | Python |
| Project age | 1 year |
| Last push | Oct 2, 2026 |
| Tracked files | 115 |
| Lines of code | 17.5K |
| Checkout size | 1 MB |
Lines by language: Python 16.7K, Markdown 604, YAML 92, TOML 60, JSON 48.
Questions
Is AI Hedge Fund free?
The code is MIT-licensed and free. Running it is not: market data comes from the Financial Datasets API and decisions from a paid model API, both billed by those providers. There is no hosted version and no subscription from the project itself.
Does AI Hedge Fund trade real money?
No. It has a simulated broker for backtests and a paper broker that tracks fake money against real market days. There is no connection to a brokerage, and the author states it is for educational purposes only and not for real trading or investment.
Can LLM agents beat the market?
Nothing in this project shows that. Persona agents produce plausible reasoning, but a backtest over a short window, on a few tickers, with a model that may have seen the period in its training data, proves little. Treat results as a way to study agent behaviour, not as a strategy.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
