knight-security
--:-- UTC
independent practice · est. 2021 crypto · fintech · payments coordinated disclosure · iso/iec 29147
$whoamiknight-security

Knight Security

Independent security research for the institutions that move money — cryptocurrency exchanges, wallets, payment platforms and the fintech infrastructure behind them. Five years of manual, methodical, evidence-first testing.

web · api · mobile · cloud · auth deliverable: poc + repro + cvss
scroll

In practice since 2021 — a statement of record.

5 Years in practice
200+ Platforms assessed
2,500+ Vulnerabilities reported
400+ Critical severity
No client logos. No testimonials. Coordinated disclosure means staying quiet — the work speaks in the report. Across 30+ jurisdictions. † Aggregate, self-reported across coordinated-disclosure
engagements since 2021. Details under nda.
01  / Manifesto what this is

Every application believes its own rules. I look for the places where that belief breaks — the quiet gaps between what a system promises and what it actually does.

Independent, methodical, and allergic to noise. Every finding goes through responsible disclosure: written up properly, reported to the people who can fix it, and to no one else.

02  / Capabilities six lines of work
02.1  / Finding classes what turns up most
Critical Account-takeover chains — OTP brute-force, auth bypass, session manipulation CWE-287
Critical Broken access control on withdrawals, transfers & balance CWE-639
High SSRF into internal services & cloud metadata CWE-918
High Payment-logic flaws — invoice forgery, amount & signature bypass CWE-840
High SQL / NoSQL injection with confirmed data extraction CWE-89 / 943
High Hardcoded API keys & signing secrets in client / mobile CWE-798
Medium Exposed admin panels & debug endpoints in production CWE-489
Medium Source-code disclosure via source maps & open buckets CWE-540
Critical High Medium Colour encodes severity — nothing else.
03  / Method iso/iec 29147 · 90-day window

How an engagement runs.

authorization first, always

Every finding ships with
  • A working proof of concept
  • Numbered reproduction steps
  • CVSS 3.1 vector & score
  • Coordinated disclosure & re-test
01

Scope & rules of engagement

Written authorization, explicit boundaries and a fixed timeline — agreed before a single packet is sent.

deliverable — signed scope & rules of engagement
02

Recon & manual testing

Methodical review of the attack surface. Scanners are a floor, not the work — they assist, they do not decide.

deliverable — surface map & candidate weaknesses
03

Exploit & chain

Candidate issues are proven end to end. What gets reported is a working proof of concept, never a theoretical flag.

deliverable — reproducible poc + cvss 3.1 rating
04

Report & coordinated disclosure

Findings go directly to the affected organization on a standard 90-day window, then get re-tested after the fix. User data is never retained or shared.

deliverable — full report, remediation guidance, re-test
04  / Evidence what a report looks like
Exhibit A — anonymized finding file ks-24-0418 · redacted for disclosure
High CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H — 8.1

Broken access control on the withdrawal endpoint enables cross-account fund movement.

proof of concept request · redacted
POST /api/v3/withdraw HTTP/2
Host: wallet.exchange.tld
Authorization: Bearer eyJhbGciOiJIUzI1NiIs…
Content-Type: application/json

{
  "account_id": "a71f…d19",
  "asset": "USDT",
  "amount": "48250.00",
  "destination": "0x9f…c4"
}

// account_id above belongs to a victim — not the caller
→ 200 OK · server never verifies account ownership

Reproduction

  1. Authenticate as a standard, fully-verified account.
  2. Capture a legitimate POST /api/v3/withdraw request.
  3. Substitute another user's account_id, keep your own bearer token.
  4. The transfer is authorized — funds move cross-account. No server-side ownership check.

Disclosure timeline

Day 0Reported to vendor security
Day 2Triaged & acknowledged
Day 61Patched & re-tested
Day 90Coordinated window closes
05  / Engagement three ways this works
E-01

Bug bounty & VDP

Public and private programs on the platforms below. Reports go through platform triage, on program terms — no side channels, no extortion, ever.

  • Scope: whatever the program declares
  • Payment: program bounty terms
  • Turnaround: continuous
E-02

Private assessment

A scoped, time-boxed engagement against your own infrastructure. Written authorization first; a full report with reproducible findings and a re-test at the end.

  • Scope: agreed in writing, in advance
  • Deliverable: report + poc + cvss + re-test
  • Turnaround: quoted per scope
E-03

Retained review

Ongoing coverage for teams that ship fast: recurring passes over new releases, plus a direct line for a second opinion before something goes live.

  • Scope: rolling, revisited each cycle
  • Deliverable: cycle reports + advisory line
  • Turnaround: agreed cadence
Rules of engagement non-negotiable
R1

Authorization before testing. No target is touched without written permission or a published program scope.

R2

No data exfiltration. Proof of impact is demonstrated with the minimum data necessary, then destroyed. Nothing is retained or shared.

R3

No disruption. No denial of service, no destructive payloads, no testing against production data belonging to real users where avoidable.

R4

Coordinated disclosure only. ISO/IEC 29147, 90-day standard window, extended on request while a fix is genuinely in flight.

R5

No brokers, no leverage. Findings are never sold, auctioned, or used as pressure. One report, one recipient: the people who can fix it.

R6

Encrypted by default. Reports over PGP on request; fingerprint verified out of band before anything sensitive moves.

06  / Platforms public profiles

The work lives where the programs live. Reports, when disclosed, speak for themselves.

07  / Contact scope first, always

Your move.

knightsec.research@proton.me
Telegram@knight_security X@knightsechac LinkedInknightsecurity

reports under nda · 90-day coordinated window
pgp key fingerprint on request · no intermediaries

security.txt
Email Telegram