The day job is offensive security at a major cryptocurrency exchange: application security, and lately the AI tooling that is starting to do parts of that work. Vuln discovery with AI is the easy part, finding the right things to look for is where it gets interesting.
The AI part is not a recent development. I was running a language-model chatbot in a Discord server in 2021, back when getting access to one still meant a research application. The homelab has been the proving ground ever since; right now it runs an agent that repairs my own infrastructure, so I can be wrong about agentic systems somewhere the stakes are a weekend rather than a company.
I’m starting to write about this in public. The essays will land here when they are worth reading.