xDeadSignalx

White hat. Your side.

I attack websites, web apps, APIs and web3 projects the way a real adversary would, then show you exactly what I found and how to close it.

White fedora
Results

What the work has been worth

Real numbers from client engagements. The details stay between me and the owner.

$13,000
at risk in one app from the most critical bug I've found
27
threats found, reported and confirmed closed on retest
100%
of findings delivered with steps to reproduce and a fix
Example run · details redacted
About

I'm xDeadSignalx.

I do ethical hacking and penetration testing for anyone who runs something on the web: a SaaS, a store, an API, a crypto project, a landing page with a login behind it. Most of them go live without anyone trying to break in first. I try first, so the next person who tries isn't a stranger.

You get a plain report ranked by severity, with steps to reproduce and a fix for each finding, and I check again after you patch.

Services

What I actually test

Named by technique, not buzzword. If it's on the OWASP lists or in a real breach write-up, it's in scope.

01

Web application attacks

Cross-site scripting (stored, reflected, DOM), SQL and NoSQL injection, command injection, server-side template injection, path traversal, unsafe file uploads, insecure deserialization.

02

Auth and access control

IDOR and broken object-level authorization, privilege escalation, JWT and session flaws, OAuth and SSO misconfiguration, password reset and MFA bypass, missing rate limits on login.

03

APIs

REST and GraphQL: mass assignment, excessive data exposure, SSRF, introspection left on, endpoints missing authorization checks, abuse of batch and bulk operations.

04

Data and PII exposure

Personal data leaking through responses, public storage buckets, exposed .env and .git, secrets in client bundles, verbose errors and logs, backups left online.

05

Crypto and web3

Smart contract review (reentrancy, access control, oracle and price manipulation, unchecked external calls), dApp front-ends and wallet-connect flows, signature and approval phishing surfaces, key and RPC handling, bridge and token integrations.

06

Business logic and infrastructure

Race conditions, payment and coupon manipulation, CSRF, open redirects, clickjacking, CORS and security-header misconfiguration, subdomain takeover, outdated dependencies with known CVEs.

07

Retest and license

After fixes ship I re-run every finding. When they hold, you can add a license for $100/year, paid in crypto: a record anyone can look up here and a badge for your footer.

Process

How a job runs

01

Scope

We agree on what's in bounds: domains, apps, APIs, contracts.

02

Test

I work through the target without touching real users or taking anything down.

03

Report

Each issue with severity, steps to reproduce, and how to fix it.

04

Retest

Once you've patched, I verify every fix holds.

05

License

Optional, $100/year in crypto: a license ID and badge, verifiable here.

Anonymous

No names. No emails.

You stay anonymous, and so do I. Everything runs through DMs, and everything is paid in crypto.

Licenses

Licensed by xDeadSignalx

Licenses are optional. A licensed site gets a record here and a badge for its footer, and anyone can look up the domain before trusting the badge.

Licensed by xDeadSignalx badge
$100/year

Paid in crypto, so you and I both stay private.

  • Verifiable. Search any domain or license ID and see whether it's real.
  • Dated and scoped. The record says what was tested, when, and how long it's valid.
  • Earned, not bought. Only issued after the fixes hold on retest.
Ground rules

Ethical means ethical

Contact

Want your site checked?

Send the link and a line about what it does. No name, no email, just a DM. Payment is in crypto.