API Security Research
01Tracing trust breaks through request and response flows.
02 / Field Notes
I'm a 17-year-old independent bug hunter and security researcher. I spend my time reading requests, tracing trust boundaries, and looking for the moment an application believes the wrong thing.
I hunt on HackerOne and build my own tools when a workflow needs more precision. API hunting and source-code hunting are my favorite places to work: one shows me what an application says, the other shows me what it assumes.
When I'm not testing, I'm writing detailed reports, studying how systems fail, and turning small signals into evidence that developers can act on.
Just a hacker who doesn't understand anything without hacking.
Toolkit / Curiosity
The tools change. The questions stay sharp.
Tracing trust breaks through request and response flows.
Following assumptions from code to the security boundary.
Testing the places where identity, access, and state meet.
Turning small signals into a clear attack-surface map.
Building focused tools for repeatable, careful research.
Making technical findings useful for the people fixing them.
Field journal — vol. II
Security research is rarely about the obvious path. I examine how applications authenticate users, enforce authorization, and handle state — then turn reproducible behavior into clear, actionable findings.
Entries: 05
Status: curated
Clearance: public