DestroyerX

Ahmed.

Security researcher and bug bounty hunter, known online as DestroyerX. I find vulnerabilities that come from missing authentication, broken access control, and secrets left in production code.

When I find something worth writing about, it goes here.

100+
Reports
20+
Programs

I've reported vulnerabilities to over 20 companies, including:

AutodeskABBIBMAnthropicWhoX VPNGetYourGuideAboitizpowerCourseraEquifaxand others.

Focus

API & access control

  • Missing authentication
  • IDOR
  • Broken access control
  • GraphQL

Secrets & exposure

  • JavaScript analysis
  • Source maps
  • Hardcoded credentials
  • Cloud storage

Approach

01

Recon across subdomains, endpoints, and JavaScript bundles.

02

Test authorization: strip tokens, swap IDs, probe cross-tenant access.

03

Analyze production JS for hardcoded keys, cloud credentials, and internal endpoints.

04

Prove real impact with a working proof of concept before writing anything up.