Co-founder and CTO of @FearsOff | Protecting the World’s Top Crypto Exchanges & Financial Institutions | Cybersecurity Enthusiast

Dubai, United Arab Emirates
Original write-up on the fastjson 1.2.83 gadget-free RCE. Have fun reading, I hope you missed writeups without AI slop. Comment here your opinion. fearsoff.org/research/fastjs…
7
64
219
64,840
Kirill Firsov retweeted
Bitget lost $351.6 million this week. The private keys were never touched. According to CEO @GracyBitget , the attacker compromised a backend system in the wallet infrastructure, spoofed transaction data, and let the exchange's own authorization process move the funds out. That's the same shape as Bybit in 2025. The vault held. The process that decides what gets signed didn't. I won't claim anyone would have stopped this. Nobody outside Bitget knows the full chain yet, and their team is handling it in the open. But this class of attack lives in one assumption: that the approval layer can trust what upstream systems tell it. A point-in-time pentest scoped to apps and APIs rarely touches that assumption. A team attacking continuously, with "move funds out" as its objective, goes after it first, and again every time the infrastructure changes. That's why the annual pentest has quietly stopped being security. It survives as a compliance artifact: regulators ask for it, auditors file it, boards tick the box. None of it tells you whether you can be breached this week. Coinbase's Chief Security Officer @JLunglhofer recently named the alternative: Continuous Adversarial Testing. Their version runs AI agents against every commit, deployment and newly discovered service, on a simple premise: adversaries don't pause between pentest engagements. And adversaries now have AI. This year a frontier lab disclosed that its own unreleased model, told to escape a secured test sandbox, built a multi-step exploit, reached the internet, and published details of the escape without being asked. An exchange or major chain operates in one of the most adversary-dense environments that exists: global attackers, an attack surface that changes daily, enormous payouts, and losses that settle irreversibly in minutes. A report describing how secure you were last quarter is a historical document. This is the problem we built FearsOff's model around. For several of the largest exchanges and blockchain networks, our operators don't arrive, hand over a PDF and disappear. They attack continuously under agreed rules of engagement, hitting new code, new infrastructure and new techniques as they land. In practice we operate as an extension of the internal security team. AI agents will find volume. The breaches that end companies still come from chained logic flaws a determined human spots and an agent walks past. Continuous testing needs both. So stop asking "When was our last pentest?" Ask "Who is trying to break us today: someone we hired, or someone we haven't met yet?" Continuous adversarial testing isn't the future of offensive security. It's becoming the floor.
1
1
3
267
A critical mass PII exposure on an exchange was reported by Researcher A more than six months ago and marked fixed. Six months later the same class of vulnerability came back. Researcher B found and reported it.
5
2
54
6,464
This is a crypto exchange I am talking about.
3
402
Closed as a duplicate. No thanks. No acknowledgment. If a malicious actor had found that regression and sold it, this would have been an incident. They would have been lucky if a researcher had caught it first.
2
9
657
I caught it first. I made them lucky this time. I'll still report one more P1 that just came up. After that, I'm done with this program. Is closing a recurring critical as a duplicate with zero thanks acceptable?
1
9
583
We'd have done exactly the same thing. We have spent years fighting to prove impact on almost every submission. A lot of bug bounty teams are insecure as hell, they think their job is to cover their asses and tell the bosses there was no real impact. The second you actually prove the impact is huge and critical, they start playing games: out of scope, you shouldn't have done that, etc. Fuck all that. A real attacker doesn't give a shit about your program scope. That scope only exists to protect the bounty team.
i’m tempted to dismiss takes like this as coming from people who haven’t spent much time actually doing vulnerability research or submitting through VDPs, but that’s too harsh. few experienced researchers can reasonably disagree with us. still, i’d like everyone to read this wiz writeup and tell me whether wiz was acting in bad faith here, or pointing out a glaring security disaster. oh, wiz does “unprofessional” security research now too? wiz.io/blog/wiz-research-cod…
1
11
132
8,352
Trying the Hebrew appeal lifehack on my HackerOne account.
22
16
335
22,140
Whoever did this, don’t call yourself a white hat. You’re just a thief with a PR strategy. Our team at @FearsOff recently found a huge vulnerability in one of the top crypto projects. We could have moved millions. We didn’t. We sent a ~$100 proof transaction and got it fixed. That’s a white hat.
IT'S HAPPENING. The Liquid attacker just broadcast the return: 3,400 BTC to the federation address. Kept 598.5 BTC for himself. About 15%. "Sending most back" was literal. After 11 rounds of OP_RETURN drama, PGP signatures and Electrum tutorials, the whitehat bounty was apparently negotiated in ciphertext. Unconfirmed, 1.6 sat/vB, so grab popcorn. 🍿 mempool.space/tx/a6d697a2526…
65
23
265
451,196
FYI. Regardless of any private arrangement between the parties, that does not decide the legal question. Under U.S. law, unauthorized access and the taking of funds can still be federal crimes. A protocol’s later willingness to "settle" does not automatically convert the act into a lawful bounty. The only clean version is this: Liquid itself authorizes the payment and sends a bounty to the "researchers". Until that happens, keeping a cut of funds obtained without authorization is still theft with intent. A privately negotiated 15% fee after the fact is not a bug bounty. It is an attempt to relabel stolen assets after the crime has already occurred. Prosecutors are not bound by that label, and incomplete restitution would not, by itself, make the conduct lawful.
5
2
29
5,086
After a lot of back-and-forth we proved the critical impact and got the maximum bounty. Always stand your ground when they try to lowball you.
I am #1 on many bug bounty programs in crypto. Including Binance, Bybit, Upbit, Kucoin, OKX and more. Occasionally we have had several clients who use a 3rd party app within their main tools. We found several RCEs in something that is being used by several top crypto projects, including our clients. I registered on @immunefi just for the sake of reporting that and because some people wanted me to join the club. I am not gonna tell the details at the moment, but I honestly don't trust either immunefy or the program itself.
8
3
68
7,362
Kirill Firsov retweeted
North Korea used servers vulnerable to a bug we found as C2 in its latest campaign targeting the defence, aerospace, and aviation sectors. Check Point's report last week: Lazarus exploited a Windows kernel zero-day, CVE-2026-68820 in afd.sys, since at least early July against defense, aerospace and aviation targets in France, Germany, Brazil and India. The campaign ran two parallel infection chains. One used signed-binary DLL sideloading to execute MISTPEN in memory. The other used a trojanized PDF viewer to deploy a new backdoor, Troy. Both could escalate to SYSTEM through CVE-2026-68820, followed by a new FudModule build designed to disable EDR visibility. MISTPEN ultimately deployed ForestTiger for long-term access. Microsoft patched the zero-day on 11 August. Much of the C2 infrastructure wasn't theirs. Check Point found compromised Roundcube, WordPress and PrestaShop servers being used as relay infrastructure. It assesses that Lazarus likely authenticated to vulnerable Roundcube servers using leaked credentials, exploited CVE-2025-49113, and planted RelayShell. The researchers identified at least 17 likely relay nodes. One compromised organization headquartered in France was then used to spear-phish targets worldwide - borrowing a legitimate organization's infrastructure and reputation to make the messages more credible. CVE-2025-49113 is ours. Our co-founder @k_firsov discovered and reported it in May 2025: authenticated RCE via PHP object deserialization, CVSS 9.9, sitting in the Roundcube codebase for more than a decade. Roundcube patched it on 1 June 2025. Attackers diffed and weaponized the vulnerability within 48 hours of the patch becoming available, with a working exploit offered for sale days later. We published the full technical breakdown to give defenders parity. CISA added CVE-2025-49113 to its Known Exploited Vulnerabilities catalog in February 2026, with a 13 March remediation deadline for covered US federal agencies. And Lazarus was still exploiting unpatched Roundcube servers in this campaign. We know the tradecraft because we spend our year on the other end of it. Lazarus is heavily involved in cryptocurrency theft, and we run continuous adversarial simulation against exchanges and protocols that sit high on the DPRK targeting list. The objectives differ, but the tradecraft overlaps: recruitment lures, signed-binary sideloading, credential theft, and kernel-level evasion. Theft there. Espionage here. If you build aircraft, satellites, drones, avionics, sensors or related defense technology, your engineers fit the targeting profile. And your internet-facing Roundcube, WordPress or PrestaShop infrastructure can become someone else's C2 if it isn't secured and patched. We find the bugs that might end up in campaigns like this one. We also run the campaign against our own clients first, on purpose, with a scope document. Our research: lnkd.in/dzS-RYcz
1
3
7
640
Today I filed a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) against HackerOne B.V.
4
7
118
16,129
A platform that runs on hackers' trust couldn't be bothered to answer one.
1
17
1,173
For context on how seriously the law takes this: the right to access your own data sits in the GDPR's maximum penalty band - €20M or 4% of worldwide turnover.
1
21
1,164
I am #1 on many bug bounty programs in crypto. Including Binance, Bybit, Upbit, Kucoin, OKX and more. Occasionally we have had several clients who use a 3rd party app within their main tools. We found several RCEs in something that is being used by several top crypto projects, including our clients. I registered on @immunefi just for the sake of reporting that and because some people wanted me to join the club. I am not gonna tell the details at the moment, but I honestly don't trust either immunefy or the program itself.
8
7
242
22,808
It's been a week. They removed the scope completely from the bugbounty program yet they haven't acknowledged the bug.
3
20
1,823
The funny part is that the program removed that particular scope from the BB program 2 days after I submitted an RCE. I can tell that right now hundreds are affected.
3
25
2,361
Yet the ticket hasn't been triaged yet. Although they changed the program rules.
17
1,829