hello, I'm keybleed.

aka token / null, "bleed"

Personal portfolio and blog: security write-ups on things I find interesting, and the projects I ship.

> available for work

About

Security researcher and engineer. By day I do crypto security for an unnamed company: reverse engineering apps, breaking the things that should not break, and writing up what I find. The rest of my time goes into building tools and shipping projects. This site is the home for both halves: technical write-ups when something is interesting enough to share, and the projects I publish.

PGP D697 4FF8 AFE3 21E6 8DD9 E75C F354 2DF3 B72F AAEF - full key at /pgp/ or contact.asc

Projects

Sites I run

Skills & certifications

Mobile

  • iOS & Android app pentesting
  • Frida & Objection instrumentation
  • SSL/TLS pinning bypass
  • Mach-O & DEX reversing

Offensive

  • Web & API pentesting
  • Bug bounty
  • LLM & agent red teaming
  • Prompt injection

Cryptography

  • Applied crypto analysis
  • TLS & PGP
  • Keychain & keystore extraction

Tooling

  • Go
  • Rust
  • Bash
  • Swift / Kotlin
  • IDA Pro

Services

Penetration testing iOS and Android apps, web, APIs. Fixed scope, real findings, a report your engineers can act on.
Reverse engineering Binaries, protocols, file formats. From a stripped Mach-O to a written spec.
Tooling Research and automation tools in Go and Rust, built to ship with the report.
Consulting Advisory, secure code review, or a second opinion on a bug nobody can pin down.

I take on a few engagements at a time; the indicator at the top of this page shows current availability.

Elsewhere

Have a project or an engagement? Signal is fastest; Telegram and email secondary. Sensitive mail goes to my PGP key. [email protected]

public profile stats synced Aug 21, 2026

Recent posts

Nothing published yet.