← back to portfolio

Writeups

Deep dives on real findings — how they were discovered, verified, and what they teach. The ones that got away get written up too.

$ ls ./published --count=3
P1 · DUPED ERC-4337 2026-07 · Polygon Technology / HackerOne

Proving Unrestricted Write Access to an ERC-4337 Bundler — Without Spending a Rupee of Gas

Hardcoded Pimlico API key in wallet.polygon.technology's JS bundle. How reading AA error codes turned a "can't demo it" key leak into a proven 7-chain exploitation chain.

// read time ~9 min ->
DUPED IDOR 2026-07 · Baazi Games / CoinPoker · Com Olho

CoinPicker — Tournament Winner Data Exposure on CoinPoker

Triage accepted it as P3. Then someone else filed it first. The finding, the timeline, and what unauthenticated endpoint enumeration looks like on a real-money gaming platform.

// draft in progress
DUPED AD / Config 2026-07 · TMF Group / Com Olho

ADFS Configuration Leak on a Global HR Platform

An exposed ADFS config that someone else reported 3 weeks earlier. Federation metadata, what it exposes, and why duplicate windows on enterprise programs are measured in days, not months.

// queued