V

3.5K posts

V

V

@kxrd36

security researcher

انضم Nisan 2015
1K يتبع9.9K المتابعون
V
V@kxrd36·
i found chain halting bug on a network carrying $120M in stablecoins and $1.85B in market value. anyway, good morning! @HackenProof #HackenProof
V tweet media
English
30
16
402
11.4K
V
V@kxrd36·
@aviggiano @HackenProof If someone can halt a chain from that tweet alone then tweet isnt the problem + the vulnerability itself was cleared for disclosure. I still didnt anything operational. Thank you btw (:
English
0
0
1
335
V
V@kxrd36·
@Chimajax @HackenProof Yess just with the obvious limits, ill write it up soon
English
0
0
2
227
All day Astronomy
All day Astronomy@forallcurious·
🚨: According to Philosophy, the highest form of peace is to have zero desire to be understood, admired, pitied or even known.
All day Astronomy tweet mediaAll day Astronomy tweet media
English
555
11.8K
82.6K
1.5M
V
V@kxrd36·
This is exactly how you push whitehats to switch sides.
f4lc0n@al_f4lc0n

I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…

English
0
0
18
1.7K
V
V@kxrd36·
another p0.
GIF
English
0
0
4
673
V
V@kxrd36·
signed MNDA today.
English
0
0
5
988
V
V@kxrd36·
i used to compete with actual geniuses but now im up against vibecoders with mac minis and agentic tools. i reported three vulnerabilities and every single one was a duplicate. i think i might need to take a step back from security research and focus on something else.
English
0
0
7
1.1K
V
V@kxrd36·
@KRGDIT kudos!
Español
0
0
0
203
DIT
DIT@KRGDIT·
Major DDoS Attack Averted (Feb 15–16, 2026) We have successfully mitigated a highly coordinated DDoS campaign targeting the Runaki portal on 15–16 Feb 2026, with around 10 consecutive attack waves peaking at ~180 Gbps each, generated from thousands of globally distributed IPs and millions of automated requests. DIT activated its incident response immediately, applying layered defenses (real-time detection and filtering, rate limiting and geo-controls where applicable), coordinating upstream blocking with the ISP, and routing the service behind cloud DDoS protection (including a public IP change) to sustain availability throughout the incident.
English
18
32
268
20.4K
V
V@kxrd36·
announcing a new infrastructure category soon.
English
0
0
6
968
All day Astronomy
All day Astronomy@forallcurious·
🚨: A man was discovered with 90% of his brain mass missing, and yet he was living a perfectly normal life.
All day Astronomy tweet media
English
3.8K
1.3K
25.6K
10.3M
V
V@kxrd36·
@chiefofautism this is exactly what u did
V tweet media
English
0
0
1
166
chiefofautism
chiefofautism@chiefofautism·
CLAUDE CODE but for HACKING its called shannon, you point it at website and it just... tries to break in... fully autonomous with no human needed i pointed it at a test app and it stole the entire user database, created admin accounts, and bypassed login, all by itself, in 90 minutes
GIF
English
571
1.6K
16.7K
4.8M
V
V@kxrd36·
@zhyvr thank you kaka zhyar gyan! ❤️
English
0
0
1
129
V
V@kxrd36·
honored to be on this month’s board and congrats to the other researchers.
HackenProof@HackenProof

❄️January payouts to hackers totaled $594,280 Huge thanks to every hacker with a valid find — you’re absolute legends. Keep hunting! 🏆 Top Bug Bounty Payouts: JRHL — $112,000 chaitealatte — $100,000 @kxrd36— $100,000 nk11 — $75,000 @VulsightSec — $50,000 @0xvivekd — $20,000 ..And speaking of remarkable community wins in December’25, researcher Jinxorder has now crossed $1,100,000 in a single reward on HackenProof — a milestone backed by consistent performance across programs. 🙌 More targets, more bugs, more wins — see you in the next month.

English
2
0
27
2.6K
Windscribe
Windscribe@windscribecom·
THIS IS NOT A DRILL: The Dutch authorities, without a warrant, just seized one of our VPN servers saying they'll give it back after they "fully analyze it". Windscribe uses RAM disk servers so the only thing the authorities will find is a stock Ubuntu install. The bigger worry is the unredacted Epstein files we had on there...
Windscribe tweet media
English
1K
3.8K
27.8K
3.5M