Verification tools check the source program, not the binary the compiler produces, so code that is proven correct can still carry a back-door when a known compiler bug miscompiles it. In joint research with Cristian Cadar and Luís Pina at Imperial College London, I explored this attack vector: how it works, how to deploy it against the open-source programs Lighttpd and Vsftpd and how it could extend to cryptographic back-doors.