hello, I'm keybleed.

aka token / null, "bleed"

Personal portfolio and blog: security write-ups on things I find interesting, and the projects I ship.

> available for work

About

Security researcher and engineer. I spend my days breaking mobile apps and the cryptography that holds them together. I enjoy mobile security, cryptography, reverse engineering.

Projects

Sites I run

Skills & certifications

Mobile

  • iOS & Android app pentesting
  • Frida & Objection instrumentation
  • SSL/TLS pinning bypass
  • Mach-O & DEX reversing

Offensive

  • Web & API pentesting
  • Bug bounty
  • LLM & agent red teaming
  • Prompt injection

Cryptography

  • Applied crypto analysis
  • TLS & PGP
  • Keychain & keystore extraction

Tooling

  • Go
  • Rust
  • Bash
  • Swift / Kotlin
  • IDA Pro

Services

Penetration testing iOS and Android apps, web, APIs. Fixed scope, real findings, a report your engineers can act on.
Reverse engineering Binaries, protocols, file formats. From a stripped Mach-O to a written spec.
Tooling Research and automation tools in Go and Rust, built to ship with the report.
Consulting Advisory, secure code review, or a second opinion on a bug nobody can pin down.

I take on a few engagements at a time; the indicator at the top of this page shows current availability.

Elsewhere

Have a project or an engagement? Signal is fastest; Telegram and email secondary. My PGP key is on the about page. contact@hack.ec

public profile stats synced Aug 21, 2026

Recent posts

Nothing published yet.