whaleyxbt / README.md
Snowy city banner used on whaley's GitHub profile
security engineer / researcher / web3 enthusiast

short summary

Security engineer and TypeScript/JavaScript developer. Building and pentesting web applications, hunting for bug bounty. Into web3 since 15.

web app security reviewrecon & enumerationbug bounty reportsNext.js / React interfacesscripts and internal toolsLinux servers setupweb3 arbitrage modules

tools / projects / bug reports

My real experience:

01getmoni.iocase-file / redacted report

Cloud storage access-control review: exposed bucket listing, unauthenticated upload surface, private project data exposure, and remediation guidance.

open github
02hololaunch.aicase-file / redacted report

Web3 presale auth chain: wallet identity spoofing, whitelist exposure, allocation data leakage, and server-side verification fixes.

open github
03takao.zonecase-file / redacted report

Frontend/admin exposure case: production bundle leaked admin logic and endpoints; client-side state could render management UI.

open github
04tgmrkt.iocase-file / redacted report

Session management review: long-lived static API tokens without expiration or context binding, creating persistent access risk.

open github
More reports

The full report collection lives in a dedicated GitHub repository.

open repository

what i can do

Practical work.

Security research

Web security review across API, frontend, backend and business logic: auth issues, broken access control, unsafe client-side flows, exposed data, business logic bugs and other bugs.

Full-stack

Full-stack and automation projects: browser automation, scraping/pentesting utilities, background workers, API integrations, network interception, Telegram alerts and market/scanner-style tools.

Linux operations

Linux setup and server hygiene: Arch/Debian/Ubuntu configs, firewall rules, SSH/service setup, Docker basics, Git workflows, shell automation and practical hardening.

~/stack/capabilities

$ cat stack.txt

security: nmap, Burp Suite, ffuf, gobuster, sqlmap, Wireshark, Metasploit, Bettercap

engineering: TypeScript, JavaScript, Bash, SQL, Docker, Git, Linux