What we did
Exploited a hash-collision weakness to forge a value that a control accepted as authentic, and recovered plaintext/keys from cipher schemes that were mathematically or operationally broken. The work was analytical — identify the exact property that fails, then construct the input that abuses it.
- Identifying weak or misused hashing and signature checks, then forging accepted values
- Attacking cipher misuse: predictable keys, reused nonces, and flawed modes
- Turning a mathematical weakness into a concrete authentication or confidentiality bypass
Why it matters to a client
Cryptographic mistakes are common and quiet: a homemade token signer, a reused IV, a password reset that trusts a guessable value. This capability reviews how your app generates, signs, and verifies secrets — the failures that silently undo authentication and session security.
← Back to case studies