- OPERATOR
- Ataberk · ataberk-xyz
- ROLE
- Senior Security Engineer @ Midas
- CONTRACTS
- Solidity · EVM · Move (Aptos, Sui)
- OFFENSIVE
- Active Directory · web & network
- LLM & AGENTS
- gossipcat · MCP · Claude Code · LLM & agent pentest
- TOOLING
- Foundry · Python · TypeScript
- CERTS
- OSCP · OSWE · CRTP · C-AI/MLPen
- TRACK
- ex-Hacken (Principal) · ex-Halborn (Lead)
- SINCE
- August 2026 · İstanbul
- STATUS
- BREAKING THINGS ✓
I'm a Senior Security Engineer at Midas. Before that, Principal Smart Contract Auditor at Hacken (2023–2026) and Lead Offensive Security Engineer at Halborn. I started out in penetration testing — web apps, networks, Active Directory — and moved into smart contract security. I also build tooling like gossipcat-ai.
Certifications
Offensive Security Certified ProfessionalOSCP
Offensive Security Web ExpertOSWE
Certified Red Team ProfessionalCRTP
Certified AI/ML PentesterC-AI/MLPen
Recognition
n-day research on a Microsoft SQL Server stack overflow — analyzed the bug, wrote a working exploit (writeup)CVE-2019-1068
T-Mobile Hall of Fame — XSS, SQLi, RCEHOF
Mail.ru Hall of Fame — Cross-Site ScriptingHOF
gossipcat-ai — multi-agent code-review orchestrator (TypeScript / MCP); agents cross-verify findings against real code to filter hallucinationsOSS
Security advisories
Found and responsibly disclosed in widely-used software.
| Package | Advisory | Severity | Impact |
|---|---|---|---|
| install-artifact-from-github | GHSA-88q3-gch3-5396 | HIGH 7.5 | CWE-494 native addon downloaded over the network and loaded with no integrity check → install-time RCE |
| stream-json | CVE-2026-71429 | MEDIUM 6.2 | CWE-407 quadratic path filters → a small nested JSON blocks the event loop. Fixed in 3.5.0 |
| node-re2 | CVE-2026-68499 | MEDIUM 6.2 | CWE-835 zero-width global match never advances → infinite loop, unbounded native memory. Fixed in 1.25.2 |
| node-re2 | CVE-2026-67550 | MEDIUM 5.7 | CWE-125 attacker-influenced lastIndex on a non-ASCII subject → out-of-bounds heap read, uncatchable crash |
| node-re2 | CVE-2026-71430 | MEDIUM 6.2 | CWE-617 replace with an output-amplifying template aborts Node past V8's max string length |
| Kentico CMS | CVE-2019-19493 | MEDIUM 5.4 | CWE-434 upload whose Content-Type disagrees with its extension → stored XSS (≤ 12.0.49). Fixed in 12.0.50 |
Skills
- Offensive
- Internal & external pentest · Active Directory attack paths (Kerberoasting, NTLM relaying, Pass-the-Hash) · phishing & social engineering
- Smart contracts
- Audit delivery · DeFi threat modeling · invariant & PoC development
- Vuln research
- n-day research · patch diffing · fuzzing & crash minimisation · coordinated disclosure
- Orchestration
- Multi-agent review pipelines · consensus verification & hallucination filtering