Deep dives on real findings — how they were discovered, verified, and what they teach. The ones that got away get written up too.
Hardcoded Pimlico API key in wallet.polygon.technology's JS bundle. How reading AA error codes turned a "can't demo it" key leak into a proven 7-chain exploitation chain.
// read time ~9 min ->Triage accepted it as P3. Then someone else filed it first. The finding, the timeline, and what unauthenticated endpoint enumeration looks like on a real-money gaming platform.
// draft in progressAn exposed ADFS config that someone else reported 3 weeks earlier. Federation metadata, what it exposes, and why duplicate windows on enterprise programs are measured in days, not months.
// queued