Client Engagement · Confidential

Cryptography: breaking flawed constructions

Finding and exploiting the gap between "uses cryptography" and "uses it correctly."

Client: Classified, under NDA
Engagement: Live engagement against a production-grade system (under NDA)
Hash collisionsWeak cipher schemesKey recoveryProtocol flaws

What we did

Exploited a hash-collision weakness to forge a value that a control accepted as authentic, and recovered plaintext/keys from cipher schemes that were mathematically or operationally broken. The work was analytical, identify the exact property that fails, then construct the input that abuses it.

Why it matters to a client

Cryptographic mistakes are common and quiet: a homemade token signer, a reused IV, a password reset that trusts a guessable value. This capability reviews how your app generates, signs, and verifies secrets, the failures that silently undo authentication and session security.

← Back to case studies