13,044 Unsafe Blocks Shipped. Nobody Read Them.
Bun's AI rewrite is being called a capability milestone. The pattern points to something else: a production codebase where the audit trail lives inside a vendor subscription and the safety debt compounds faster than any team can pay it down.

TITLE: 13,044 Unsafe Blocks Shipped. Nobody Read Them.
The tests pass. Memory dropped from 6.7 GB to 609 MB. The binary shrank 20 percent. The headline is $165,000 and 11 days to rewrite a million-line runtime. If you stop there, this is the most impressive AI engineering story of 2026.
Don't stop there.
The rewrite leaves 13,044 unsafe Rust blocks versus 73 in comparable hand-written code. uv, a Rust project of 350,000 lines, contains 73 unsafe blocks. Bun's Rust port, at 681,000 lines, contains over 13,000. That's roughly 181 times more unsafe code per line than a well-regarded Rust project doing similar systems work.
This is not a number you clean up. It is a number you inherit.
What the Test Suite Does Not Tell You
The Rust rewrite passed 99.8% of the existing test suite. That number is significant, but let's be precise: it says the new implementation behaves like the old one at the runtime's public interface. It does not say that the new implementation is safe.
The unsafe keyword in Rust means "I am taking manual responsibility for memory invariants that the compiler cannot check." A project with 13,000 unsafe blocks is not meaningfully using Rust's memory safety model. The agents translated Zig's manual memory patterns into Rust, then reached for unsafe every time the borrow checker objected. A faithful port of manual memory management does not become memory-safe in transit. It becomes manual memory management wearing a Rust mask.
The memory safety argument is real but partial. One Bun engineer acknowledged: "When the Rust port merged to main, the state of the code was very, very bad. There were 13,000 instances of unsafe, no Miri tests at all, and, sure enough, it exposed UB in safe Rust."
Translation: Bun bought speed by outsourcing knowledge to Anthropic and deferring audit to "later." At 200 lines per hour, auditing all the code would take more than two years. Later does not come.

The Lock-in Nobody Named
The deeper issue is not the unsafe count. It is who holds the key to reducing it.
The Zig project banned LLM-authored contributions in late April 2026. Bun, acquired by Anthropic in December 2025, had been running its own Zig fork for months—unable to upstream AI-generated changes. A 4x compile-time speedup sat stranded in Bun's private fork, legally incompatible with upstream Zig. The language migration was forced, not chosen.
Anthropic stated at acquisition: "Bun will remain open source and MIT-licensed, and we will continue to invest in making it the runtime, bundler, package manager, and test runner of choice for JavaScript and TypeScript developers."
The MIT license is real. The practical reality is different.
Vendor lock-in is the verdict: Anthropic owns Bun. The only tool that can meaningfully maintain this codebase is Claude. If you want to contribute, you need access to Anthropic's models. This isn't open source in the traditional sense anymore.
The PR review was handled by claude[bot] and coderabbitai[bot]. No human read the full diff. For a runtime that hundreds of thousands of developers rely on, this is unsettling.
The team's stated plan for reducing the unsafe count: tell an agent "Make this function not unsafe." The agent traces dependencies and reworks them until the borrow checker passes.
Notice what that requires: every fix runs through Claude. You cannot fork this codebase and maintain it without the same toolchain. The code is MIT. The workflow is not.
This matters beyond Bun. Claude Code generates roughly $1 billion in run-rate revenue and ships as a Bun single-file executable. The runtime ceased to be a standalone product and became a critical dependency for Anthropic's primary revenue engine.
Pre-rewrite, Bun had roughly 200 open issues, with approximately 70% affecting Claude Code's runtime paths and 30% affecting monorepo and package management paths that Claude Code does not exercise. Post-rewrite, the total issue count could easily balloon to 500 or more, with the same prioritization skew. Claude Code paths get fixed immediately. Everything else waits.
If your refactor roadmap was on the shelf because a year-long timeline looked impossible, Claude just made it possible and unauditable. The job took 11 days and cost about $165,000 at API pricing. That cost baseline will land in every engineering org's deck by Q4. The 13,044 unsafe blocks will not be in the deck.
You now have a choice, not clarity.
What to Watch
First incident. Track not a test failure but a CVE traced to an unsafe block in a file no human has read. Undefined behavior does not announce itself as a failing test—it shows up as a CVE on the one libc nobody runs in CI, eighteen months out.
Contribution friction. Watch whether external PRs to the Rust codebase slow down or stop. A codebase you need a specific vendor's tool to reason about is not a community codebase, regardless of the license file.
The copycat cycle. This is the first publicly documented case of a production runtime switching languages at million-line scale using an AI coding agent as the primary author. Every project that copies the model also copies the debt structure. The cost is visible on day one. The audit gap is not.
- Zig creator calls Bun's Claude Rust rewrite 'unreviewed slop'
- Bun Rewrites 535K Lines of Zig to Rust in 11 Days Using Claude
- Bun Rust Rewrite Merged: The 13,000 Unsafe Block Problem
- Bun Has Been Converted to Rust. Now What?
- Bun 1.4: The Controversial AI-Driven Rewrite from Zig to Rust
- Bun's Rust Rewrite: Engineering Reality, Unsafe Blocks, and the AI-Speed Migration
- How Claude Verified a Million-Line Port: What Bun's Rust Rewrite Reveals
- Bun is joining Anthropic
- Anthropic acquires Bun as Claude Code reaches $1B milestone
- Claude Rewrites Bun's Million Lines of Code in 11 Days for $165,000
- The Pulse: What can we learn from Bun's rapid Rust rewrite with AI?
- How Claude Rewrote Bun in Rust in 11 Days
- Bun Rewrites 960K Lines of Zig to Rust Using Claude | AI Weekly
- Zig won’t accept AI-written code So the Bun team had Claude rewrite the whole thing in Rust. | by Native Developer | Jun, 2026 | Medium
- Bun is being rewritten in Rust, moving away from Zig | daily.dev
- Theo:Bun Rewrites 960,000 Lines From Zig to Rust in Six Days — 13,000 Unsafe Blocks Remain — BigGo Finance
- How 64 Claude Agents Rewrote Bun From Zig to Rust in 11 Days
- The Most High-Profile AI Rewrite in History: Claude Completed Bun in 11 Days – The Founder Spent a Month Before Daring to Reveal the Truth
- Bun Completes 11-Day AI-Driven Code Migration from Zig to Rust | KuCoin
- DraganSr: AI: Bun, Claude Code => Rust: 11 days, $165K
- Why Anthropic Had to Buy Bun. When your billion-dollar CLI depends on… | by Stéphane Derosiaux | Medium
- What Bun Can Tell Us About AI, Open Source and Anthropic – tecosystems
- Anthropic says Claude Code subscribers will need to pay extra for OpenClaw usage | TechCrunch
- Anthropic’s Bun Deal: Open Source Strategy Reshapes AI Tooling - AI CERTs News
- Anthropic Uses Open Source Bun To Power Claude Dev Agents - Open Source For You
- Bun rewrites in Rust, unsafe call count tells the real story | daily.dev
- Bun Founder Uses Claude to Port 960,000 Lines of Zig to Rust in Six Days, Community Erupts — BigGo Finance
- Bun's Experimental Rust Port Shows 13,000 Unsafe Calls, Dwarfing uv's 73 | Bun, uv, Fenado AI
- Bun's Migration from Zig to Rust as a Potential Case Study ...