co-founder and ceo @verialabs (yc f25) | hack things @smiley_ctf

Joined September 2025
4 Photos and videos
Pinned Tweet
We spun out of the #1 hacking team in the US and built AI that finds what even the best hackers miss. During one engagement, it found 6 different ways to take over any user's account on a popular webapp. Completely autonomously. Then suggested fixes for every single one. Today we're announcing @verialabs' $3.2M seed, backed by @ycombinator, @gokulr, @paulg, and @woloski (co-founder of Auth0), and many other great investors. DM me if you want to know what we'd find in your app.
25
19
241
55,612
stuxf retweeted
Another 5-figure win for an Immunefi SR. Congrats to @verialabs and @Cayden_Liao.
6
11
200
8,384
how is this happening again
Multiple security vulnerabilities affecting React Server Components and Next.js have been disclosed. We strongly recommend updating your applications immediately. Cloudflare WAF managed rules already mitigate the disclosed denial-of-service vulnerabilities, and we are investigating additional coverage for several other CVEs. developers.cloudflare.com/ch…
2
324
stuxf retweeted
🏆#EPFL #LakeCTF 2026 — it's a wrap! 🚀 Another year, another amazing battle of brains of creativity!🧠💻 Congratulations to this year's winning team pls carry :3! And thank you to every participant for making this edition such a success.👏 🥇 pls carry :3 🥈 .;.;. 🥉 FluxFingers
10
45
3,265
stuxf retweeted
Part 2 of @verialabs Securing Open Source series: We found 2 bugs that could be chained together in Kraken Wallet: Chaining both, a malicious dApp could impersonate a trusted one and disguise transactions as messages, silently draining user funds. Blog: verialabs.com/blog/securing-…
1
6
630
stuxf retweeted
We wrote up everything we do to secure our open source projects at Astral
10
40
361
23,278
stuxf retweeted
recently onboarded to @verialabs (F25) to help with our security Highly recommend working with them! Super professional, clean UI, and well worth the investment The product lives within our CI/CD, and it's a super easy github integration 🥂
3
3
19
1,997
stuxf retweeted
Mar 24
Starting a series where we write up interesting vulns our agent at @verialabs finds: First up, 1-click RCE in Goose, Block's coding agent with 33k stars: verialabs.com/blog/securing-… Goose was vulnerable to CSWSH, allowing an attacker-controlled website to run arbitrary commands.
2
7
20
2,130
Mar 23
We at @verialabs built an autonomous CTF agent in a weekend and won 1st place at @BSidesSF 2026, solving all 52/52 challenges. It races multiple AI models (Claude, GPT-5.4) in parallel, each in isolated Docker sandboxes with full CTF tooling. A coordinator LLM reads solver traces and sends targeted guidance to stuck agents. As AI gets better at finding and exploiting vulnerabilities, we think it's important to understand exactly how good it is and where it fails. github.com/verialabs/ctf-age…
8
53
316
34,852
stuxf retweeted
We just qualified 2 teams for DiceCTF Finals, with one of our teams getting 2nd place overall! Congrats @BunkyoWesterns on winning and we'll see everyone in NYC! insert line about llms ruining ctfs here
2
7
31
5,412
Went to @ycombinator startup school last year, ended up having dinner w/ visiting partner @aroraharshita33 decided to apply for the fall batch and got in after :) if you're at all interested in startups, highly recommend applying, free sf trip and a life changing two days
Startup School is back! Hear from Jensen Huang, @sama, @alexandr_wang, @JeffDean, and more. Join a hand-selected group of top CS students, researchers, and engineers for two days of talks, sessions with YC partners, and hands-on robotics demos, right here in San Francisco.
5
8
43
15,379
We spun out of the #1 hacking team in the US and built AI that finds what even the best hackers miss. During one engagement, it found 6 different ways to take over any user's account on a popular webapp. Completely autonomously. Then suggested fixes for every single one. Today we're announcing @verialabs' $3.2M seed, backed by @ycombinator, @gokulr, @paulg, and @woloski (co-founder of Auth0), and many other great investors. DM me if you want to know what we'd find in your app.
25
19
241
55,612
stuxf retweeted
We hacked a Times Square billboard! jk! @brexHQ put us up there for YC F25. Back to actually finding security vulnerabilities.
2
3
22
2,720
stuxf retweeted
🧵 Broke Eigen Network's zkVM Found a missing check in its FRI implementation that lets attackers forge arbitrary proofs.
1
3
9
1,260
stuxf retweeted
31 Dec 2025
We're officially top 3 in the world on CTFtime for 2025, up from 13th last year! yay This year, we also: - hosted the first ever smileyCTF, with 1,000 teams playing - went to in-person CTFs in Switzerland, Las Vegas, NYC * 2 - qualified for SECCON and LakeCTF 2026 finals
2
8
39
5,245
14 Oct 2025
shoutout to @greybaker who has been absolutely fantastic to work with and has given us a lot of amazing advice about the security industry
We're excited to announce nine YC alums joining us as new Visiting Partners! Welcome @matthewriley, @aroraharshita33, @greybaker, @golda, @raphaelschaad, @ChristinaG325, @FrancoisChauba1, @vivianmshen, and @dazzeloid! ycombinator.com/blog/ycs-new…
5
785