Co-founder and CTO of @FearsOff | Protecting the World’s Top Crypto Exchanges & Financial Institutions | Cybersecurity Enthusiast

Joined April 2011
28 Photos and videos
Pinned Tweet
Our latest research is out! If you missed a good write-up for nice vulnerabilities, I brought you one! Enjoy the reading! @FearsOff @Cloudflare
10
106
498
137,897
Fable 5 gets disabled and suddenly everyone forgot that tomorrow Anthropic is also starting to charge extra for claude -p and agent sdk. Headless usage moves off subscription limits onto a separate $20/$100/$200 monthly credit at API rates. Convenient timing.
1
7
260
Kirill Firsov retweeted
Kudos to the teams of @Bitrefill and @FearsOff for handling this incident with the utmost professionalism and transparency. ‘What doesn’t kill you makes you stronger’, especially in cybersecurity.
March 1st incident report On March 1, 2026, Bitrefill was the target of a cyberattack. Based on indicators observed during the investigation - including the modus operandi, the malware used, on-chain tracing and reused IP email addresses (!) - we find many similarities between this attack and past cyberattacks by the DPRK Lazarus / Bluenoroff group against other companies in the crypto industries. The initial access originated through a compromised employee laptop, from which a legacy credential was exfiltrated. That credential provided access to a snapshot containing production secrets. From there, the attackers were able to escalate their access to our broader infrastructure, including parts of our database and certain cryptocurrency wallets. We first detected the incident after noticing suspicious purchasing patterns with certain suppliers. We realized that our gift card stock and supply lines were being exploited. At the same time we found some of our hot wallets being drained and funds transferred to attacker-controlled wallets. The moment we identified the breach, we took all of our systems offline as part of our containment response. Bitrefill operates a global e-commerce business with dozens of suppliers, thousands of products, and multiple payment methods across many countries. Safely switching all these things off and bringing them back online is not trivial. Since the incident, our team has been working closely with top industry security researchers, incident response specialists, on-chain analysts and law enforcement to understand what happened and how we can prevent it from happening again. A sincere thank you to @zeroshadow_io, @SEAL_Org, @RecoverisTeam and @fearsoff for their rapid response and support throughout this ordeal. What about your data Based on our investigation and our logs we don’t have reason to think that customer data was the target of this breach. There is no evidence that they extracted our entire database, only that the attackers ran a limited number of queries consistent with probing to understand what there was to steal, including cryptocurrency and Bitrefill gift card inventory. Bitrefill was designed to store very little personal data. We are a store, not a crypto service provider. We don’t require mandatory KYC. When a customer chooses to verify their account - e.g. to access higher purchasing tiers or certain products - that data is kept exclusively with our external KYC provider, with no backups in our system. Still, based on database logs, we know that a subset of purchase records was accessed and we want to be transparent about that. Around 18,500 purchase records were accessed by the attackers. Those records contained limited customer information, such as email addresses, crypto payment address, and metadata including IP address. For approximately 1,000 purchases, specific products required customers to provide a name. That information is encrypted in our database. However, since the attackers may have gotten access to the encryption keys, we are treating this data as potentially accessed. Customers in this category have already been notified directly by email. At this time, based on the information currently available, we do not believe customers need to take specific action. As a precaution, we recommend remaining cautious of any unexpected communications related to Bitrefill or crypto. If this assessment changes, we will of course immediately inform those affected. What we are doing We have already significantly improved our cybersecurity practices, but vow to continue to draw learnings from this experience to make sure user and company balances and data remain maximally safe. Specifically we’re: -Continuing thorough cybersecurity reviews and pentests with multiple external experts and implementing recommendations; -Further tightening internal access controls; -Further improving logging and monitoring for faster detection and more effective response; and -Continuing to refine and test our incident response procedures and automated shutdown procedures. The bottom line Getting hit by a sophisticated attack sucks (a lot). We’ve been in business for over 10 years and it’s the first time we’ve been hit this hard. But we survived. Bitrefill was designed to limit the impact if something like this ever happened. Bitrefill remains well funded, has been profitable for several years and will absorb these losses from our operational capital. Almost everything is back to normal: payments, stock, accounts. Sales volumes are also back to normal, and we are eternally thankful to our customers for your continued confidence in us. We will continue to do our best to continue deserving your trust. Thank you!
3
6
1,224
So much drama today, people losing their minds over this "new" feature from Anthropic, calling it the death of pentesting and bug bounties. Even stocks tanked for companies that have nothing to do with it. Why? Because most investors in this space don't know shit about security or what Claude AI actually dropped. We have been running vulnerability scans with various AI models, including Opus 4.6 for months already. This release is basically just a handy button to run what used to be a chain of prompts doing the exact same thing. Investors: Buy back in. Bug hunters and pentesters: relax and level up with it. Anthropic’s social media team: Bravo! This clickbait worked out!
Feb 20
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…
41
48
372
42,235
You don't need them for pentesting companies either. Most hackers don't have any certs, so why would some corporate bureaucracy tell me I'm not qualified to work with them just because I lack some XXX certificate? OK, let's wait until you get hacked and see how well that bureaucracy holds up then.
| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄| You don't need certs to be successful in bug bounty |___________| \ (•◡•) / \ / --- | |
4
2
75
6,950
CVSS such a joke sometimes. 9.9 for a vuln that needs low-priv access?
Critical n8n RCE (CVE-2026-1470) lets attackers bypass sandbox defenses via malicious expressions. CVSS 9.9. Check versions 1.123.17 & 2.x now. #n8n #CyberSecurity #RCE #CVE20261470 #DevOps #InfoSec #Automation #Vulnerability securityonline.info/sandbox-…
1
22
3,573
Our latest research is out! If you missed a good write-up for nice vulnerabilities, I brought you one! Enjoy the reading! @FearsOff @Cloudflare
10
106
498
137,897
This write‑up tells the story of how traffic aimed at that certificate path could reach origins behind Cloudflare even when the rest of the application was blocked by customer rules. Enjoy the reading here fearsoff.org/research/cloudf…
54
231
50,101
28 Dec 2025
The Ubisoft hack is another reminder of how broken many corporate bug bounty programs are. Endless out-of-scope assets, ignored dev servers, and blind spots everywhere. Hackers do not follow scope rules - they go where attention is lowest. That is exactly why #MongoBleed worked so well. Treat whitehat researchers fairly, and you will not be dealing with incidents during the holidays.
6
21
124
26,225
26 Dec 2025
The funniest part of the @TrustWallet hack. People from a dark forum DDoSed the malicious site soon after the hack started. It actually worked. Uno reverse card on hackers😂 Millions possibly saved for @cz_binance
39
76
774
99,024
26 Dec 2025
The #TrustWallet hack appears to have been planned weeks in advance. The malicious domain was registered on December 8, 2025. Based on the domain’s IP address and hosting infrastructure, the attackers may be linked to Russia, though attribution cannot be confirmed. @FearsOff @cz_binance @TrustWallet
18
22
177
25,882
20 Dec 2025
Many believe that if you steal funds from a platform and they offer a 10% bounty to get the rest back - with a promise of no legal pursuit - you are in the clear. Sorry to burst the bubble, that's not how it works. The US government (and others) can and will pursue criminal charges independently. They don't need the platform's cooperation or complaint to launch a full investigation and prosecution. Once you cross into theft, there's no safe "deal" that erases the crime. Bottom line: Don't steal if you want to have a good sleep.
20 Dec 2025
Onchain message from the victim to the attacker
1
1
11
2,335
12 Dec 2025
There is a simple way to find a GitHub profile just by knowing an email. I have never seen this mentioned publicly. Curious who already knows this - or who wants to know. Leave a comment. #bugbounty #github #OSINT We at @FearsOff know many secrets! Follow for more!
10
5
52
8,973
12 Dec 2025
A little morning research. New React/Next.js CVE-2025-55183 Source code leakage PoC Bypasses Cloudflare! @FearsOff #react #bypass #cloudflare
15
80
528
56,897
12 Dec 2025
2
30
6,986
12 Dec 2025
Also bypassing Vercel WAF @cramforce @rauchg
1
11
4,676
12 Dec 2025
Scan all js for Action IDs
2
10
6,277
Done! Vercel WAF bypass. #vercel #bugbounty
31
52
942
121,151
Kirill Firsov retweeted
Crypto’s noisy, but the signal is clear: Security starts with an offense-first mindset. Join us as Marwan (@FearsOff - #1 ranked offensive-security firm) breaks down - black/white/gray hats, offense vs defense, CEX vs on-chain vulnerabilities, and how AI is changing the battlefield. We wrap with concrete tips you can use today. @mar1hachem
5
5
12
9,908