Exposed Spring Boot Actuator gave full access to MMBot infrastructure, logger modification, and trading strategy leak. $180M TVL at risk.
API security vulnerability on a perpetuals trading platform. Reward increased to $400 with a bonus after the initial report.
Responsible disclosure on self-custodial payments infrastructure — global digital-dollar transfers with no custodial intermediary.
Two live exchange API keys found leaked in public wallet-app repositories, plus a quote markup parameter that accepted out-of-range values — a $626 quote reduced to $6.21.
Futures backend trusted client-supplied entry and exit prices — arbitrary PnL and platform volume minted from a single account. Social-reward and fee-deduction bypasses found in the same API.
Admin API reachable by any registered account: platform metrics, high-value card transactions, and mass-notification endpoints had no server-side role check.
Unauthenticated private key export on all user wallet pockets. Full attack chain proven: scan pockets, export keys, sweep funds.
Firebase Admin SDK custom token leaked via unauthenticated API — full account takeover, email flooding, and persistent access.
Production source map exposure on console.aiven.io — 2,642 files, 21MB, leaking OAuth secrets and internal API routes.
Production source map and Sentry exposure on cloud console infrastructure.
CORS misconfiguration and undocumented endpoint exposure on an agentic platform.
Agentic Engineering grant, funded for open-source agent infrastructure work.