Client Engagement · Confidential

Cryptography — breaking flawed constructions

Finding and exploiting the gap between "uses cryptography" and "uses it correctly."

Client: Classified — under NDA
Engagement: Live engagement against a production-grade system (under NDA)
Hash collisionsWeak cipher schemesKey recoveryProtocol flaws

What we did

Exploited a hash-collision weakness to forge a value that a control accepted as authentic, and recovered plaintext/keys from cipher schemes that were mathematically or operationally broken. The work was analytical — identify the exact property that fails, then construct the input that abuses it.

Why it matters to a client

Cryptographic mistakes are common and quiet: a homemade token signer, a reused IV, a password reset that trusts a guessable value. This capability reviews how your app generates, signs, and verifies secrets — the failures that silently undo authentication and session security.

← Back to case studies