Compiler engineers like fuzz testing. You'll find a bunch of infra for it in llvm. That should mean the easy targets have already been hit, though I wouldn't be too confident of that stance.
[1] https://www.cs.tufts.edu/~nr/cs257/archive/john-regehr/findi...
One example of a higher order reasoning about this is [1] (includes metrics).
[1] "As TVL rises, so does the probability of being hacked" https://www.bittrap.com/resources/defis-growing-pains:-as-tv...