Cody having espresso on the terrace of a café
Cody at dinner in a candle-lit restaurant
Cody standing in front of a helicopter

Cody Zacharias

Application and offensive security

Tampa, Florida

About

I find vulnerabilities in real software and help teams fix them.

Ten years in security: bug bounty, application security testing, client penetration tests and incident response, and open-source tools used widely by other researchers. I use AI to make vulnerability research faster.

Experience

2024 to present

Owner and Security Consultant, Xen LLC

Security research, consulting and software products

  • Performed penetration tests for clients under NDA, covering web applications and APIs, iOS apps and Solana smart contracts, both independently and in partnership with other security teams.
  • Led contractors and delegated work on larger engagements.
  • Assisted clients with incident response: patched vulnerabilities quickly after incidents, audited for related classes of issues, and helped identify threat actors and prepare reports for law enforcement.
  • Mentored beginners in cybersecurity, from fundamentals to bug bounty hunting, and taught individuals operational security practices for protecting accounts and digital assets from common attacks.
  • Built AI-assisted vulnerability analysis tooling, including for smart contract security.
  • Built and shipped software products, including LaserSell.
June to Sept 2024

Security Engineer, Hyperproof

Contract position

  • Owned application security testing for the company's SaaS platform, deciding what to test and where to focus without direction.
  • Performed daily manual penetration testing with Burp Suite and reviewed code and issue tracker activity to find vulnerabilities.
  • Filed detailed bug reports and worked with engineers until findings were resolved.
  • Reviewed external penetration test reports and acted as the point of contact for a third-party assessment, whose results were cross-checked against internal testing.
  • Contributed to internal security documentation.
Jan 2023 to Mar 2024

Owner, SupplyShark

Supply chain security tooling for GitHub organizations

  • Built Python software that scans code hosted on GitHub for supply chain security issues.
  • Used the tool to find vulnerabilities, reported through bug bounty programs to Coinbase, Snapchat, MetaMask and several crypto companies.
  • Built a SaaS platform with Next.js and Supabase so users could run the tool against their own GitHub organization.
  • Ran outbound outreach to validate demand, which taught me firsthand how hard security tooling is to sell.
Sept 2018 to Jan 2023

Product Security Analyst, HackerOne

Vulnerability triage and validation for customer bug bounty programs

  • Validated incoming vulnerability reports, scored severity with CVSS and wrote impact assessments that customer security teams used to prioritize fixes.
  • Led triage for several live hacking events: served as the main point of contact for the customer, delegated work across the triage team and kept the team current on procedures throughout.
  • Learned new customer programs ahead of the team, then trained other analysts on how to triage them.
  • Built internal tools that streamlined triage for specific programs and contributed to a shared tool that saved the team time.
  • Advised customer security engineers on remediation and kept communication between researchers and customers clear.
  • Trained new hires and gave internal presentations.
2016 to 2018

Independent security researcher, Self-directed

  • Focused on bug bounty hunting and exploit research, and built open-source security tools for penetration testers, including Twint and subjack.

Research and open source

Twint

2017

Open-source Twitter intelligence and scraping tool written in Python. Over 16,000 stars on GitHub, featured in YouTube tutorials, and cited as a data collection source in academic papers.

NetworkChuck — Twitter OSiNT (Ethical Hacking)

Null Byte — Mine Twitter for Targeted Information Using Twint

Tyler Germain — Twitter's $100/Month API vs This Free Method

Cited inExtracting & Analyzing Twitter Data · Sentiment analysis study · Twitter users' behavior study

OpenEMR vulnerabilities

2018

Part of the Project Insecurity team that manually reviewed OpenEMR 5.0.1.3 and reported authentication, SQL injection, file upload and code execution flaws. Patched by the vendor in a subsequent release. I published an authenticated RCE proof of concept as Exploit-DB 45161.

Proof of concept against a local test install

OpenMRS XXE vulnerability

2018

Discovered and reported an XML external entity (XXE) vulnerability in the HTML Form Entry module of OpenMRS, an open-source medical record system. Patched upstream.

Live chat widget information disclosure

2018

Co-authored a public advisory showing that widely used live chat widgets exposed support staff details such as names, IDs and email addresses.

Bug bounty

I’ve reported vulnerabilities resolved by Shopify, Snapchat, Coinbase, MetaMask, Hedera Hashgraph, Illuvium, Adobe, dYdX, Squads, OpenOcean, LastPass, VICE, OKX, and more.

Ranked among the top 10 researchers at AT&T for Q3 2017.

Languages

PythonGoShellTypeScript / JavaScript

Skills

Offensive security

  • Web application and API penetration testing
  • Proof-of-concept exploit development
  • Manual code review
  • iOS application security testing
  • Android application security testing (basic)
  • Smart contract security review (Solana)
  • AI-assisted smart contract reverse engineering
  • Subdomain takeover and attack-surface discovery
  • Supply chain security analysis

Intelligence and defense

  • OSINT and threat actor investigation
  • Operational security for individuals and teams
  • Threat modeling
  • Incident response support and post-incident audits

Certifications

Offensive Security Certified Professional

OSCP

Issued Feb 2018 · Credential ID OS-101-041803

Contact

Get in touch about consulting engagements, security assessments, research collaborations, or other opportunities. I reply within a couple of days.

cody[at]codyzacharias.com